
French police warn of eSIM swapping scams causing average losses of 10,000 euros
Gendarmes in France are alerting smartphone users against SIM swapping fraud, where attackers convert hijacked mobile lines into eSIM profiles to intercept banking validation codes.
Mechanics of the eSIM takeover
French law enforcement and cybersecurity specialists are alerting the public to a sharp rise in SIM swapping scams, where fraudsters transfer a victim's phone number onto a new device. On 27 August 2026, the gendarmerie in the northern department of Somme issued a public warning describing the fraud as a scheme capable of emptying bank accounts in sixty seconds. The attack typically begins when perpetrators acquire personal information belonging to a target through data leaks, phishing, or direct phone theft. Fraudsters also exploit instances where customers leave physical SIM cards inside devices given to dishonest repair shops. Once in possession of personal identifiers, criminals contact mobile carriers while impersonating the legitimate account holder, asking customer service agents to convert the existing line into a digital eSIM profile. Because eSIM technology activates over cellular networks without requiring a physical card delivery, criminals can configure the victim's number onto their own hardware within minutes.
- Perpetrators obtain personal identification data through leaks, phishing, or stolen devices
- Scammers contact mobile carriers posing as the customer to request a digital eSIM transfer
- The legitimate subscriber loses cellular service as the phone number shifts to the attacker
- Attackers intercept banking and two-factor SMS codes to drain funds and reset account passwords
Bypassing authentication and draining funds
Once the eSIM profile activates on the attacker's phone, the victim's physical handset instantly loses connection to the mobile network. Fraudsters use this window of control to bypass two-factor authentication systems that rely on SMS delivery. By initiating password resets on online services, perpetrators intercept the one-time security codes generated by email providers, social networks, and banking portals. Cybersecurity expert Damien Bancal, founder of the technical portal Zataz, detailed how fraudsters exploit this vulnerability.
The hacker receives the two-factor authentication by message, which allows them to validate purchases, transfer money, and even open accounts.
Beyond raiding financial accounts, attackers exploit hijacked lines to make high-rate international calls outside standard subscription bundles, sometimes generating operator bills exceeding 1,500 euros before the subscriber detects the activity.
National scale and financial impact
Data compiled by consumer watchdog RMC Conso indicates that the threat has expanded well beyond local jurisdictions into a nationwide issue across France. In 2025, an estimated 65% of people in France encountered SIM swapping attempts or related fraudulent operations. Financial damages often reach severe levels, with the average loss standing at 10,000 euros per victim. In one documented incident, attackers transferred 17,000 euros out of a victim's bank account in several rapid transactions immediately following the SIM hijacking. Attackers also leverage the hijacked numbers to create unauthorized accounts, spread deceptive communications, and register on third-party platforms under the victim's stolen identity. Norton noted that possessing an associated email address or username is often sufficient for attackers to trigger automated account recovery workflows entirely over the stolen mobile number.
- Average loss per victim (RMC Conso)
- 10000 €
- Documented single victim loss
- 17000 €
- Out-of-bundle call charges
- 1500 €
Warning signals and defense steps
Security officials emphasize that early detection is essential to preventing total account compromise. The most immediate indicator of an ongoing attack is an unexplained, sudden loss of cellular network reception, accompanied by an inability to place phone calls or receive text messages. Gendarmes advise anyone experiencing an unexpected service cutoff to avoid waiting for connectivity to return on its own. Victims should immediately reach out to their mobile operator from an alternative phone line to request the deactivation of the newly issued eSIM and restore their original physical card. Users must also notify their banking institutions immediately to freeze payment methods, review outgoing transfers, and update credentials across all compromised services.


