← All examples Full example — Forensic Report + Formal Statement

SIM Swap / Phone Fraud

Fictitious case. Attacker social-engineered mobile carrier to port victim’s number to a new SIM, bypassed SMS-based 2FA on crypto exchange, and drained wallet of £8,700 in Bitcoin. Carrier logs and blockchain tracing documented.

1
Forensic Investigation Report
7 pages • Carrier analysis + 2FA bypass + Blockchain tracing
2
Formal Statement
5 pages • Ready for police + carrier complaint
Document 1 — Forensic Investigation Report
🔎
Forensic Report — SIM Swap Attack
TraceProof_Forensic_Report.pdf • 7 pages • Classification TLP:RED
Risk 82/100
TP-2026-9012 Method: SIM swap + 2FA bypass Amount: £8,700 Carrier: EE (BT Group) Crypto drained via Coinbase

Social engineering of EE customer service — SIM port — Coinbase account takeover

8 June 2026 — 02:14 AM
Attacker calls EE customer service, provides victim’s personal details (obtained from data breach). Requests SIM replacement citing “lost phone”. Agent processes request after security questions answered correctly.
8 June 2026 — 02:18 AM
Victim’s phone loses signal. New SIM activated on attacker’s device. Attacker now receives all SMS messages intended for victim.
8 June 2026 — 02:22 AM
Attacker initiates password reset on victim’s Coinbase account. SMS 2FA code received on ported number. Password changed. Email notification sent but victim asleep.
8 June 2026 — 02:25 AM
Attacker withdraws 0.127 BTC (£8,700) from Coinbase to external wallet (bc1qx7k...9m3p). Transaction confirmed in next block.
8 June 2026 — 07:30 AM
Victim wakes up, notices no phone signal. Contacts EE who confirm SIM swap. Coinbase account already drained. Victim reports to Action Fraud.
▶ ON-CHAIN TRACE — BTC
Coinbase withdrawal: bc1qx7k...9m3p 0.127 BTC (£8,700)
Hop 1: bc1qn4r...2f8t Split: 0.08 BTC + 0.047 BTC
Hop 2a: bc1qk9m...4w2e KuCoin deposit (identified)
Hop 2b: bc1qt5v...8j1r Unspent (dormant wallet)
⚠ Partial recovery possible via KuCoin compliance request
Document 2 — Formal Statement (extract)
Formal Statement — SIM Swap Fraud
TraceProof_Statement.pdf • 5 pages

I, REDACTED, report that on 8 June 2026 my mobile phone number was fraudulently ported by an unknown attacker who social-engineered my carrier (EE). The attacker used control of my number to bypass two-factor authentication on my Coinbase account and withdraw £8,700 in Bitcoin. I hold EE partially liable for inadequate security verification procedures.

Have you been a victim of a similar scam?

Start your free report: within minutes you will receive a forensic investigation report and a formal statement ready to submit to the authorities.

Start your report →

No obligation. You only pay if you decide to download the documents.