Ask most people to name their most important credential and they will say their password. It is not. For anyone operating in Bangladesh, the single most valuable thing an attacker can take is your mobile number — because your number is what every other account uses to prove you are you. Lose control of it for thirty minutes and the passwords stop mattering.
A SIM swap is the fraudulent re-issue of a mobile number onto a SIM the attacker controls. There is no malware, no exploit, and nothing for an antivirus to catch. The network does exactly what it was designed to do — it delivers your calls and messages to the SIM registered to your number. The attack is simply that the SIM is no longer yours.
What follows is what we see in assessments, what the public record shows, and what actually reduces the risk.
One number, everything behind it
Bangladesh has built an unusually large share of its digital economy on SMS delivered to a mobile number. As of January 2025 there were 239.3 million registered MFS accounts in the country, up from 219.12 million a year earlier, moving close to Tk 1.72 trillion in a single month — a 32.56% year-on-year rise — through a network of roughly 1.83 million agents.1
Every one of those accounts is anchored to a phone number. So is your bank's transaction alert, your card's 3-D Secure code, your NID-linked government service, your email account recovery, your WhatsApp registration, and your Facebook password reset. The number is not one credential among many. It is the master key that unlocks the recovery path for all the others.
A password protects one account. A phone number protects — or surrenders — every account that can reset itself by SMS.
What a SIM swap actually is
The attacker does not need your handset, your PIN, or your password. They need the operator to agree that they are you. There are three routes to that, and all three are in active use.
1. Impersonation at the counter
The attacker walks into a customer care point or retail outlet with your name, your NID number, your date of birth, your mother's name and a plausible story: the SIM was lost, the handset was stolen, the fingerprint reader keeps failing. The strongest control Bangladesh has here is biometric verification — since 2015 SIM registration and re-registration have required a fingerprint match against the BTRC's central platform, backed by NID data.2 That control is real, and it is why crude impersonation fails more often here than in markets without it.
It is not absolute. Biometric systems have exception paths, and exception paths are where fraud lives. The BTRC has itself defined a “special procedure” for cases where the ordinary check cannot work — a subscriber abroad transferring a SIM to a nominee, an elderly or ill subscriber whose fingerprints will not match, or transfer to an heir after a death — handled with an NID and supporting certification instead.2 Every one of those is a legitimate, necessary accommodation. Every one is also a documented, publicly known way to obtain a number without a matching fingerprint, and a target worth studying for anyone planning against a specific person.
2. An insider
The second route skips the deception entirely. A retail agent, an outsourced customer care operator, or a distributor's staff member performs the swap knowingly. This is not hypothetical in Bangladesh. In 2016, police in Chittagong arrested two bKash agents after crooks obtained 157 SIMs from an operator and re-registered them in their own names under the then-new biometric system, using them to drain mobile money accounts. The regulator's own director general publicly assigned responsibility for the resulting theft.3
Insider swaps are the hardest variety to defend against as a customer, because nothing in the process looks wrong from the outside. This is precisely why the technical controls discussed later — getting your number off the critical path — matter more than any amount of vigilance at the counter.
3. Buying the answers first
The counter staff will ask verification questions. The attacker's job is to already know the answers, and in the current environment those answers are for sale.
Between October 2025 and May 2026, Bangladesh's Criminal Investigation Department arrested three men running an online network selling citizens' data. Md Siam Howlader, 23, was arrested on 13 October 2025 after a Facebook account was seen advertising the service; a network administrator, Md Al Amin, 23, followed on 28 October; and on 5 May 2026 CID raided a Dhaka address and arrested Md Arman Hossain, 22, a computer science student, seizing three mobile phones, six SIM cards — three of them bKash merchant SIMs — and a laptop. The product they were selling, through an Android application named “Sob Akhane” and an associated website, was NID information, SMS records, MFS account details for bKash, Rocket and Nagad, and bank account information, paid for on demand.4
Read that inventory again in the context of a verification script at a service counter. It is not a list of stolen data. It is a list of correct answers.
This sits on top of a broader exposure problem. A single government portal operated by the Office of the Registrar General, Birth & Death Registration exposed the personal data of an estimated 50 million citizens in 2023 — names, phone numbers, email addresses and national ID numbers — discoverable through an ordinary Google search and left accessible for five days.5
Why the local context makes this harder
Two developments over the past year have made something clear that was previously easy to ignore: most people in Bangladesh cannot reliably answer the question what is registered in my name?
In July 2025 the BTRC cut the ownership cap from 15 SIMs per NID to 10, citing national security among its reasons. Roughly 6.7 million SIMs held by 2.6 million users were slated for deactivation, with a voluntary cancellation window from August and operator-led deactivation running from 1 November 2025.6 A follow-on plan to reduce the cap to five was subsequently deferred until after the national polls.7
Then, in January 2026, the rollout of the National Equipment Identity Register produced an uncomfortable public moment. Citizens checking the new system found 30 to 40 handsets registered against their NID, and in one reported case 53, with 42 added in a single month by someone who had not bought a phone in four years. BTRC and the operators attributed much of this to migration artefacts — over 300 crore historical records uploaded with migration dates displaying as current dates — and around 1.1 million SIMs deactivated in error during launch were subsequently restored. But BTRC officials also acknowledged the underlying reality directly: someone else registers SIM cards using another person's NID without their knowledge. Specialists warned of the obvious consequence — if a crime is committed using a connection registered to your identity, you are the one on the record.8
If you have never checked what is registered against your NID, you are not defending a known perimeter. You are guessing at one.
The 24-hour lock is a speed bump, not a wall
Bangladesh does have one automatic safeguard, and it is a good one. Under Bangladesh Bank direction, when a SIM carrying an MFS account is replaced, the operator notifies the provider and the account is suspended — bKash's terms specify a minimum of 24 hours, and in practice the window runs to 24–36 hours by arrangement with the mobile network operators.9
Understand what that protects and what it does not. It protects the MFS balance. It does nothing for everything else that resets by SMS, and a competent attacker knows the clock is running, so they do not spend the window on your bKash account. They spend it on:
- Your email. The highest-value target in the sequence, because email is the recovery path for everything that does not use SMS. Once email is taken, the phone number becomes optional.
- Your messaging accounts. WhatsApp, Telegram and Signal registration is tied to the number. Taking over the account gives an attacker your contact list, your group memberships, and — most damagingly for a public figure — the ability to send messages that your contacts have every reason to believe are from you.
- Your social accounts. Password reset by SMS remains widely enabled, and often remains enabled as a fallback even after a stronger method is added.
- Card and internet banking flows that use one-time codes without a separate lockout rule.
By the time the MFS suspension lifts, the attacker frequently no longer needs the number at all. The account takeover has already been completed elsewhere, and the number was only ever the entry point.
What it looks like when it works
The clearest documented account of the full mechanism comes from a US federal prosecution, and it is worth reading precisely because nothing in it is sophisticated.
On 9 January 2024, Eric Council Jr. used a portable ID card printer to produce a physical identity document, walked into an AT&T store in Huntsville, Alabama, presented the fake ID with a story about needing a replacement SIM, and obtained the SIM linked to a number he did not own. He then walked to a nearby Apple store, bought an iPhone, inserted the SIM, and received the password reset codes for the US Securities and Exchange Commission's official @SECGov account on X. He photographed the reset code and passed it to co-conspirators, who posted a false announcement that a spot Bitcoin ETF had been approved. Bitcoin rose roughly $1,000 and then fell nearly $2,000, wiping out tens of millions in market positions. Council pleaded guilty in February 2025 and was sentenced to 14 months in prison, three years of supervised release, and forfeiture of $50,000.10
A financial market regulator. A printer, a story, and a walk between two shops. The gap between the value of the target and the sophistication of the attack is the entire point.
The reported volumes are meaningful without being the main argument. The FBI's Internet Crime Complaint Center logged 1,611 SIM swap complaints with more than $68 million in losses in 2021, rising to 2,026 complaints and $72.6 million in 2022, then falling to 1,075 and $48.8 million in 2023 and 982 and $26.0 million in 2024 — a decline that followed the FCC's November 2023 SIM swap rules and carrier alerting.11 Two things follow. Regulation and carrier-side controls demonstrably work. And these figures count only what was reported to one agency in one country, where a mature complaint mechanism exists — which is not the environment most Bangladeshi victims are operating in.
Seven changes that actually reduce the risk
The strategic move is simple to state and takes some work to implement: stop letting your phone number function as an identity document. In order of impact:
1. Move your email off SMS recovery first
Email is the keystone. Before touching anything else, replace SMS as the second factor and the recovery method on your primary email account with an authenticator app or, better, a hardware security key or passkey. This single change breaks the chain that makes a SIM swap catastrophic rather than merely inconvenient.
2. Remove the SMS fallback, not just the SMS default
This is the step people miss, and it quietly undoes all the others. Adding an authenticator app while leaving “text me a code instead” enabled means your account security is still exactly the strength of your phone number, because an attacker will simply choose the weaker path. On every critical account, check the recovery and fallback options and remove the phone number where the platform allows it. Where it cannot be removed, that account should be treated as SMS-protected regardless of what else you have configured.
3. Separate the financial number from the public number
The number printed on your business card, published in a directory, used for WhatsApp and given to vendors should not be the number your bank, your MFS accounts and your email recovery are attached to. A second, unpublished number used for nothing else removes your financial identity from the reconnaissance an attacker can do for free. It is the cheapest structural improvement available, and it survives the mistakes you will inevitably make elsewhere.
4. Adopt NIST's position on SMS codes
The US National Institute of Standards and Technology now classifies SMS and PSTN-delivered one-time passcodes as a restricted authenticator in its digital identity guidelines — permitted only with a documented risk assessment, a migration plan, and notice to users. The guidance further advises verifiers to weigh signals such as a recent SIM change or number port before delivering a code over the phone network.12 If you run an institution, this is the standard your own authentication design should be measured against. If you are an individual, it is the reason to stop treating an SMS code as strong protection.
5. Audit what is registered against your NID — and re-audit it
Dial *16001# from any operator and enter the last four digits of your NID; the reply lists the SIMs registered to your identity. It is free and works across Grameenphone, Robi, Airtel, Banglalink and Teletalk.13 Handsets can be checked separately through the BTRC's NEIR citizen portal. Do this now, do it for every adult in your household, and put it on a calendar — quarterly is reasonable. A connection registered in your name that you did not open is both an exposure and, potentially, a liability.
6. Know the signal, and treat it as an alarm
A SIM swap has one unmistakable symptom: your phone abruptly loses network service and will not recover. No bars, “Emergency calls only”, no SMS, no calls — while Wi-Fi still works normally. Most people interpret this as a network fault and wait. The correct interpretation, for anyone with a meaningful risk profile, is that you have minutes rather than hours. This is worth briefing to family and staff explicitly, because they will otherwise wait until morning.
7. Extend all of the above to the people around you
A principal with hardware keys on every account is still exposed through a spouse whose email recovery runs to a shared number, an assistant who can authorise payments and uses SMS codes, or a household manager whose NID has been used to register connections they know nothing about. In our engagements, the largest single reduction in exposure usually comes from bringing associated personnel up to the principal's standard — not from hardening the principal further. The same logic that governs OSINT footprint reduction applies here.
The first hour, if it happens
Decide this sequence in advance, write it down, and give it to the people who may have to act on it while you are unreachable.
- Call the operator from another phone immediately and report a fraudulent SIM replacement. Ask for the number to be suspended, not merely investigated. Note the time and the reference.
- Lock the email account next, from a device that is already signed in: change the password, sign out all sessions, and remove the phone number from recovery.
- Contact the bank and MFS provider and request a hold. The 24-hour MFS suspension buys time here — use it rather than assume it.
- Warn your contacts through a channel that is not the compromised number. Messaging account takeover is used for fraud against the victim's contacts far more often than against the victim.
- File with CID's Cyber Police Centre and preserve everything — timestamps, SMS records, transaction references. Recovery of funds, where it happens at all, depends almost entirely on speed.
- Afterwards, treat every account that had SMS recovery as suspect, not just the ones you saw activity on.
What a structured programme looks like
For a principal, a family office or an institution, this is not a checklist exercise done once. We treat number and identity exposure as a mapped surface with an owner and a review cycle: an inventory of every account that can be reset by phone number, migration of each to phrase-resistant authentication, segregation of financial identifiers from published ones, hardware keys issued and enrolled for the principal and the personnel who can act on their behalf, documented incident procedure held by more than one person, and periodic re-verification of what is registered against each NID in the household.
None of it is exotic. It is inventory, migration and maintenance. The reason it goes undone is that a phone number does not feel like a credential — right up to the afternoon somebody else is holding it.
Sources
- Bangladesh Bank MFS statistics, reported by The Financial Express, “Bangladesh MFS accounts surge by 20 million in a year, transactions up 32pc” — thefinancialexpress.com.bd
- BTRC Biometric SIM Registration System and Central Biometric Verification Monitoring Platform — btrc.gov.bd; on the three defined exception cases, Prothom Alo, “SIMs to be issued through ‘special procedure’ in 3 biometric complication cases” — en.prothomalo.com
- 2016 Chittagong SIM re-registration and mobile money theft case — The Daily Star, “Regulator blames bKash for mobile money theft” — thedailystar.net; The Independent — theindependentbd.com
- CID arrests over the sale of NID, SMS, MFS and bank account data via the “Sob Akhane” application — UNB, “CID arrests app developer for alleged role in selling sensitive citizen data” — unb.com.bd; New Age, “CID busts cybercrime ring selling personal data” — newagebd.net
- 2023 Bangladesh government website data exposure — TechCrunch, The Record
- BTRC reduction of the per-NID SIM ownership cap to 10 — Prothom Alo, “SIMs exceeding 10 per NID to be deactivated: BTRC” (30 July 2025) — en.prothomalo.com; on the start of deactivation, The Business Standard — tbsnews.net
- Deferral of the plan to cut the cap to five — The Daily Star, “Plan to reduce SIM limits deferred until after polls” — thedailystar.net
- NEIR rollout and handsets registered against citizens' NIDs — Prothom Alo, “People concerned after seeing 30-40 mobile phones registered in their name” (3 January 2026) — en.prothomalo.com
- MFS account suspension following SIM replacement, per Bangladesh Bank direction — bKash terms and conditions — robi.com.bd
- United States v. Eric Council Jr., SIM swap takeover of the SEC's @SECGov account — US Department of Justice — justice.gov, DOJ guilty plea release
- FBI Internet Crime Complaint Center SIM swapping complaint and loss figures, 2021–2024 — ic3.gov public service announcement and IC3 annual reports
- NIST Special Publication 800-63B, Digital Identity Guidelines — treatment of out-of-band authenticators using the public switched telephone network — pages.nist.gov
- BTRC SIM registration check service,
*16001#— operator notice, Grameenphone — grameenphone.com; handset registration via the NEIR citizen portal — neir.btrc.gov.bd
Figures are quoted as published by the sources listed above and reflect the period each covers. Regulatory limits and operator procedures in Bangladesh have changed several times in recent years — verify current rules with your operator before relying on them.