Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Europol Dismantles SIM Farm Network Powering 49 Million Fake Accounts Worldwide

0
Medium
Phishingrce
Published: Sun Oct 19 2025 (10/19/2025, 06:13:00 UTC)
Source: The Hacker News

Description

Europol dismantled a sophisticated cybercrime-as-a-service platform operating a SIM farm that powered over 49 million fake online accounts globally. The platform enabled criminals to conduct phishing, smishing, investment fraud, extortion, migrant smuggling, and distribution of child sexual abuse material by providing temporary phone numbers and verification codes from over 80 countries. Operation SIMCARTEL resulted in arrests, seizures of SIM box devices, servers, and freezing of criminal assets. The service was used to obscure identities, facilitating a wide range of telecommunications-related cybercrimes and financial fraud. The criminal infrastructure was highly technical and impacted thousands of victims, especially in Austria and Latvia, with multimillion-euro losses. The platform also monetized SIM cards for passive income, further incentivizing abuse. European law enforcement agencies from Austria, Estonia, Finland, and Latvia collaborated with Europol and Eurojust to disrupt this network. Defenders should focus on monitoring SIM farm-related activities, improving verification processes, and enhancing awareness of social engineering tactics leveraging fake accounts.

AI-Powered Analysis

AILast updated: 10/20/2025, 01:32:00 UTC

Technical Analysis

Europol's Operation SIMCARTEL targeted and dismantled a large-scale cybercrime-as-a-service (CaaS) platform that operated a SIM farm infrastructure facilitating the creation of over 49 million fake online accounts worldwide. This platform provided customers with access to telephone numbers registered in more than 80 countries, enabling them to bypass identity verification mechanisms on social media, communication platforms, and financial services. The SIM farm consisted of approximately 1,200 SIM box devices containing 40,000 active SIM cards, which were used to receive SMS verification codes and conduct SIM swapping attacks. The service was marketed as a provider of fast, temporary phone numbers and allowed SIM card owners to monetize their cards by routing SMS messages through specialized software. Criminals used these fake accounts to execute a broad spectrum of crimes including phishing, smishing, investment fraud, extortion, migrant smuggling, and distribution of child sexual abuse material (CSAM). The platform's infrastructure was technically sophisticated, enabling anonymity and complicating attribution. Law enforcement actions included 26 searches, seven arrests (five Latvian nationals), seizure of servers and SIM devices, and freezing of over €697,000 in bank and cryptocurrency assets. The operation involved cooperation between Europol, Eurojust, and authorities from Austria, Estonia, Finland, and Latvia. The criminal network was linked to over 1,700 cyber fraud cases in Austria and 1,500 in Latvia, with losses exceeding €4.9 million. The disruption of this platform significantly impedes the ability of cybercriminals to create and use fake identities for fraudulent activities and highlights the ongoing threat posed by SIM farm operations in enabling large-scale telecommunications fraud.

Potential Impact

European organizations face significant risks from this threat due to the widespread use of fake accounts enabled by the SIM farm infrastructure. Financial institutions and online service providers are particularly vulnerable to fraud schemes such as phishing, smishing, and investment scams that leverage these fake identities to deceive victims and steal funds. The creation of millions of fake accounts undermines trust in digital identity verification processes, complicating customer onboarding and increasing the risk of account takeover. Critical sectors including banking, telecommunications, and social media platforms may experience increased fraud losses and reputational damage. The involvement of multiple European countries in the operation and the high number of cases in Austria and Latvia indicate a regional concentration of impact. Additionally, the platform facilitated serious crimes like extortion, migrant smuggling, and distribution of CSAM, posing broader societal and legal challenges. The disruption of this infrastructure reduces the operational capabilities of cybercriminals but also signals the persistence of SIM farm threats that require ongoing vigilance. Organizations must anticipate continued attempts to exploit telecommunications systems for fraudulent purposes, potentially affecting cross-border transactions and communications within Europe.

Mitigation Recommendations

European organizations should implement multi-layered verification processes that do not rely solely on SMS-based authentication, such as adopting app-based authenticators or hardware tokens to reduce reliance on vulnerable SIM cards. Telecom providers must enhance detection of SIM farm activities by monitoring unusual SIM card usage patterns, such as high-volume SMS routing through SIM boxes, and collaborate with law enforcement to report suspicious activities. Financial institutions and online platforms should deploy advanced behavioral analytics and machine learning models to identify and block transactions or account activities associated with fake or suspicious accounts. Awareness campaigns targeting customers about social engineering tactics, including smishing and impersonation scams, can reduce victim susceptibility. Organizations should also enforce stricter Know Your Customer (KYC) and Anti-Money Laundering (AML) controls to detect and prevent fraudulent account creation. Sharing threat intelligence related to SIM farm operations and associated fraud campaigns across European cybersecurity communities will improve collective defense. Finally, regulators should consider mandating stronger identity verification standards and encouraging telecom operators to implement SIM swap protection mechanisms.

Need more detailed analysis?Get Pro

Technical Details

Article Source
{"url":"https://thehackernews.com/2025/10/europol-dismantles-sim-farm-network.html","fetched":true,"fetchedAt":"2025-10-20T01:31:43.934Z","wordCount":1117}

Threat ID: 68f591024f503908ae7cd144

Added to database: 10/20/2025, 1:31:46 AM

Last enriched: 10/20/2025, 1:32:00 AM

Last updated: 10/20/2025, 3:49:42 AM

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats