Case file · SIM SWAP 2018

How a SIM swap stole $23.8 million: the phone number that unlocked everything

Published 2026-09-29 · 4 min read · Missing control: Non-SMS MFA and carrier port locks

In 2018 a crypto investor lost about $23.8 million without ever losing his phone. A crew simply got his phone number moved to a SIM card they held.[1] This case file covers how a stolen phone number opens accounts, how one of the people involved ended up with a 12-year sentence, and the control that would have stopped it.

What happened

In 2018 a group of people targeted a cryptocurrency investor. They arranged for his mobile phone number to be linked to a SIM card in their possession, so that calls and texts meant for him went to them instead.[1]

With control of his number, the group got into his accounts and took about 3 million cryptocurrency tokens, worth roughly $23.8 million at the time.[1] The person reported to be the ringleader was a 15-year-old at the time.[1]

Nicholas Truglia, a Florida man then in his early 20s, played the money role. The stolen tokens were sent to his account, where he converted them into bitcoin and split the proceeds among the people involved. He kept about $673,000 for himself.[1][2]

How it worked

A SIM card is what ties a phone number to a physical phone. Carriers can move a number to a new SIM, which is useful when a customer loses a phone. A SIM swap is when a criminal gets that transfer done without the real owner's permission, often by persuading or paying someone at the carrier, or by passing its identity checks with stolen personal details.

Once the number moves, the victim's phone goes quiet and the criminal's phone starts receiving everything. That matters because many online accounts use a text message code as the second step of logging in, or as the way to reset a forgotten password. If the text goes to the wrong phone, the second step protects nothing. In this case, taking over the number was the key that let the group reach the investor's accounts.[1]

The victim later sued his mobile carrier over its security. A California judge dismissed his claim for $200 million in damages in 2020 but allowed other parts of the case to continue.[1]

What it cost

Truglia was arrested in 2018 and was also sent to California to face separate charges over a different SIM swap involving about $1 million.[1] On December 2, 2022, he was sentenced to 18 months in prison for his role in the $23.8 million theft and ordered to repay more than $20 million within 60 days.[1] The alleged ringleader separately agreed in a civil settlement in November 2022 to pay $22 million.[1]

Truglia did not pay. Court records showed he had more than $53 million in assets, and after his release he moved money and bought luxury goods. He was detained again in May 2023, released in November 2024, and still made no payments.[2] Prosecutors pointed to a video interview in which he suggested he could keep stolen crypto even after a long prison term.[2]

In July 2025 a judge resentenced him to 12 years in prison, well above the 51 to 63 months that federal guidelines recommended, citing his refusal to pay and his efforts to hide assets.[2]

The missing control

The missing control: multi-factor sign-in that does not rely on text messages, backed by a port and SIM lock on the phone account. An authenticator app or hardware security key stays with the owner even if the phone number is stolen, and a carrier lock makes the number itself far harder to move.

Either layer would have broken this theft. With app-based or key-based sign-in, hijacking the number would not have delivered the codes needed to get into the accounts. With a carrier PIN or lock that blocks SIM changes and number transfers without extra verification, the number would have been much harder to hijack in the first place. The accounts treated the phone number as proof of identity, and the phone number turned out to be the weakest link.

What to do in your business

Watch the case
They Took His Phone Number, Then Twenty Million DollarsDrops 2026-12-16
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More identity and access cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. The Record: SIM swapper gets 18 months, must pay back $20 million he stole from crypto investor
  2. Decrypt: SIM swapper in $20 million crypto theft resentenced to 12 years in prison