Real-Time Mobile-Network Intelligence for Detecting Recent SIM Changes and Reducing Account-Takeover Risk

SIM Swap Detection API

Last Update: 10/2026

What is SIM Swap fraud? 

A SIM swap is a process in which a mobile number is associated with a different SIM. 

SIM changes occur legitimately every day. 

A subscriber may: 

  • lose a SIM;

  • damage a SIM;

  • move from a physical SIM to an eSIM;

  • request a replacement; port or modify a mobile service;

  • activate a new subscription; use certain multi-SIM services;

  • or otherwise require the operator to change the SIM association.


The CAMARA SIM Swap specification describes a SIM swap in terms of the mobile number being associated with a new SIM/IMSI and notes that legitimate operator processes may cause such changes. 

SIM swap fraud occurs when an attacker fraudulently causes a victim's telephone number to become associated with a SIM controlled by the attacker. 

Once the attacker gains control of the mobile number, calls and SMS messages intended for the victim may reach the attacker's SIM. 

This is particularly important where a bank, cryptocurrency platform, email provider, social network or other digital service relies on SMS One-Time Passwords or possession of a phone number as part of account authentication. 

A successful fraudulent SIM swap may enable the attacker to receive: 

  • password-reset OTPs; 

  • login verification codes; 

  • transaction-approval messages; 

  • account-recovery codes; or 

  • other communications intended for the legitimate customer. 



The CAMARA SIM Swap specification identifies account-takeover fraud and interception of SMS authentication messages as major reasons for exposing SIM-change information programmatically. 

What is the SIM Swap API? 

The SIM Swap API is a Network API that allows an authorised application to obtain information about recent SIM pairing changes associated with a mobile number. 

Instead of attempting to infer a SIM change from device behaviour, SMS delivery or third-party databases, the application queries information derived from the mobile operator responsible for the subscription. 

The released CAMARA SIM Swap API supports two principal questions: 

 

  1. When did the most recent SIM swap occur?

  2. Has a SIM swap occurred during a specified recent period? 

 

The CAMARA product description summarises these capabilities as returning either the timestamp of the most recent change or a yes/no answer for a defined period. 

The current public stable CAMARA release listed by the project is SIM Swap v2.1.0, together with SIM Swap Subscriptions v0.3.0. 

The development specification also documents an optional /retrieve-age-band capability that can return a standardised recency band instead of the exact date where supported. Because this appears in the work-in-progress specification rather than the currently listed v2.1.0 release, implementations should verify provider support rather than assuming it is universally available. 

 

How does the SIM Swap API work? 

 

The application first identifies the relevant mobile subscription. 

 

Depending on the authentication model, the phone number may be provided explicitly or may be determined from the access token. 

 

The application then calls one of the supported operations. 

 

SIM Swap check 

 

The /check operation asks whether a SIM swap occurred during a specified period. 

 

For example, a bank could ask whether a SIM change occurred within the previous 24, 48 or 72 hours. 

 

The API receives a maxAge value in hours. 

 

The released specification supports a configurable period within the allowed range and returns a Boolean SIM-swap result. 

 

This allows the application to make a risk decision without requiring the exact SIM-change timestamp. 

 

A conceptual request is: 

 

Phone number + period → operator SIM history → swapped true/false 

 

A true result does not mean fraud has occurred. 

 

It means the operator detected a SIM-pairing change during the requested period. 

 

Retrieve SIM Swap date 

 

The /retrieve-date operation returns the timestamp of the latest SIM change where the provider is permitted and able to expose it. 

 

This gives a fraud engine more flexibility because the application can define its own risk thresholds. 

 

For example: 

 

SIM changed 20 minutes ago → very recent signal 

SIM changed 3 days ago → recent signal 

SIM changed 18 months ago → generally less relevant for an immediate takeover event 

 

The precise interpretation remains the responsibility of the enterprise. 

 

Where privacy or data-retention restrictions prevent the operator from returning an older exact timestamp, the specification provides mechanisms for indicating that the monitored period does not extend indefinitely.

 

SIM Swap Subscriptions 

 

CAMARA also defines SIM Swap Subscriptions. 

 

Instead of an enterprise repeatedly querying a phone number, the application can create a subscription and receive notifications when a SIM change occurs. 

 

This can support proactive fraud monitoring. 

 

For example, a financial institution could register an eligible mobile number and receive an event indicating that the SIM changed. 

 

Its fraud-management system could then apply temporary controls, increase monitoring or require stronger authentication for sensitive activity. 

 

SIM Swap Subscriptions are a separate CAMARA API and their availability depends on the API provider. 

 

Why is SIM Swap Detection important for Mobile Operators & Enterprises?

 


Traditional SMS-based authentication assumes that the party receiving the message controls the customer's mobile number.


SIM swap fraud can weaken that assumption.


If a criminal takes control of the number, an OTP can be delivered successfully while still reaching the wrong person.


From the application's perspective, the SMS provider may report a completely normal delivery.


SIM Swap Detection adds a network-derived signal that can identify an important change before the organisation relies on that mobile number.


This makes it especially relevant for:

 

  • account recovery;

  • password resets;

  • high-value payments;

  • cryptocurrency withdrawals;

  • profile changes;

  • new-device enrolment;

  • beneficiary creation;

  • contact-detail changes; and

  • other account-takeover-sensitive actions.


CAMARA specifically identifies banking fraud prevention and password-reset protection among the primary use cases.


Key Benefits / Features of SIM Swap Detection

 

  • Operator-derived SIM-change information
  • Check whether a swap occurred within a chosen period
  • Near-real-time risk signal
  • Retrieve latest SIM-swap timestamp
  • Support for fraud-decision engines
  • Account-takeover protection
  • Password-reset protection
  • Additional protection for SMS OTP
  • Support for transaction validation
  • Standardised CAMARA interface
  • Can be combined with Number Verification
  • Can be combined with Device Swap
  • Can be combined with KYC Match
  • Can be used without exposing sensitive SIM identifiers to the enterprise
  • GSMA Open Gateway ecosystem exposure
  • Event-driven monitoring through SIM Swap Subscriptions 

     

Examples of SIM Swap Detection Use Cases


Banking transaction validation

 

A customer initiates a high-value transfer.  Before approving it, the bank queries SIM Swap.  If no recent swap is reported, the signal can support the existing authentication decision.  If the SIM changed very recently, the bank may:

 

  • request a passkey;

  • require biometric confirmation;

  • contact the customer through a trusted channel;

  • delay the transaction;

  • require manual review; or

  • apply another step-up control.


The SIM Swap API does not dictate which action the bank must take. It provides the network signal to the bank's risk engine.

 

Password reset


A user requests a password reset and the service plans to send an SMS OTP. Before accepting SMS possession as sufficient evidence, the application queries SIM Swap. A recent change may indicate that SMS OTP should not be accepted as the only recovery factor.


CAMARA explicitly cites password-reset fraud prevention as a use case.


Cryptocurrency withdrawal


A crypto exchange receives a request to withdraw digital assets after a password reset.
A recent SIM change, new device and unusual IP location together may significantly increase the account's risk profile. SIM Swap provides one of those signals.


New beneficiary creation


A banking application can check SIM Swap before allowing a customer to add a new payment beneficiary.
The application may impose additional checks if a SIM change occurred shortly before the request.


Customer-support authentication


Call centres are frequently targeted by social-engineering attacks. Before allowing a high-risk account change, the support system may use SIM Swap information as part of its verification process.


The development specification specifically notes that SIM Swap information may also support non-automated sensitive actions such as call-centre verification.


Continuous monitoring


Where SIM Swap Subscriptions are available, an organisation can receive a notification when a subscribed mobile line undergoes a SIM change. This can allow the organisation to apply additional monitoring before the customer initiates another action.

 

SIM Swap Detection vs. SIM Swap Fraud


These terms should not be treated as identical.


SIM Swap describes the SIM association changing.


SIM Swap Detection determines whether such a change occurred.


SIM Swap Fraud is a malicious event in which an attacker obtains control of the victim's number through an unauthorised SIM change.


The API detects the change. It does not independently determine the attacker's intent.


SIM Swap vs. Device Swap


SIM Swap and Device Swap measure different events.


SIM Swap concerns a change in the SIM associated with a mobile subscription or number.


Device Swap concerns a change in the device associated with the subscription.


A customer can move an existing SIM to another handset without replacing the SIM; or replace the SIM while continuing to use the same handset. Therefore, the two APIs provide complementary signals.


SIM Swap vs. Number Verification


Number Verification confirms whether a supplied phone number corresponds to the authenticated mobile subscription. SIM Swap determines whether the SIM associated with a number recently changed. A fraud-prevention system may use both.


For example:


Number Verification confirms that the current subscription corresponds to the account number.
SIM Swap shows that the SIM was replaced one hour ago.


The application treats the successful Number Verification result as valid possession but recognises that possession changed very recently. Additional authentication is requested. This is why SIM Swap can be especially valuable alongside Number Verification rather than as a replacement for it.

 

Common questions about SIM Swap Detection

  1. Does a SIM Swap result prove fraud? No. Legitimate customers replace SIMs for many reasons. The result should be treated as a risk signal.
  2. What does /check do? It determines whether a SIM swap occurred within a specified previous period.
  3. What does /retrieve-date do? It returns the timestamp of the latest SIM swap where the operator can expose the information.
  4. Can the operator always return the exact date? Not necessarily. Retention, privacy rules or provider policy may limit how much history is available.
  5. Can SIM Swap detect a stolen phone? Not directly. A stolen handset with the original SIM may involve no SIM change. Device intelligence and other fraud controls are required.
  6. Does SIM Swap replace SMS OTP? No. It can strengthen an SMS OTP process by identifying a recent change before an OTP is trusted.
  7. Does an eSIM change count? The relevant concept is the operator's SIM/subscription association. Implementations and operator processes may include physical SIM and eSIM lifecycle changes, subject to the provider's definition and systems.
  8. Can applications subscribe to SIM-change events? Yes, where SIM Swap Subscriptions are supported by the API provider.
  9. Is SIM Swap available on every network? No. Availability varies by operator, country and API provider.
  10. Should an account automatically be blocked after a recent swap? The API does not prescribe that response. A recent change should normally be assessed with other risk information and the organisation's fraud policy.


Related Terms


SIM Swap; SIM Swap Fraud; SIM Swap Detection; SIM Swap API; SIM Swap Subscriptions; SIM; eSIM; IMSI; MSISDN; Account Takeover; SMS OTP; One-Time Password; Number Verification; Device Swap; Mobile Identity; Fraud Prevention; Risk Engine; Step-Up Authentication; Password Reset; Account Recovery; CAMARA; GSMA Open Gateway; OAuth 2.0; OpenID Connect; Mobile Network Operator.

 

Sources 

 

CAMARA SIM Swap Overview

CAMARA SIM Swap GitHub Repository

CAMARA SIM Swap OpenAPI Specification

CAMARA SIM Swap Releases

GSMA Open Gateway SIM Swap Documentation

GSMA Open Gateway API Descriptions



Last Updated: October 2026