• en
  • zh
  • ru
  • es
  • What we do
  • Who we work for
  • Experience
  • Awards
  • Team
  • Expert advice
  • Guidelines
  • Contact
  • en
  • zh
  • ru
  • es

Expert advice

SIM Swapping and Phone Fraud in Poland: Criminal Threat

28.09.2026

SIM swapping is a form of identity-based fraud in which an offender obtains control over a victim’s mobile number by persuading, deceiving or unlawfully influencing a telecommunications provider to issue a replacement SIM card or activate an eSIM. Once the number is transferred, the offender may receive one-time passwords, reset account credentials and bypass SMS-based security measures used by banks, email providers and business platforms.

SIM swapping crime in Poland is not a separate offence defined under one provision of the Criminal Code. Its legal assessment depends on the conduct involved, the offender’s intent, the data obtained, and the financial or other harm caused. It may combine elements of fraud, unlawful access to information systems, impersonation and computer fraud.

For companies, the risk extends beyond an individual employee’s bank account. A compromised telephone number can enable access to corporate email, accounting platforms, cloud storage, payment approval tools or social-media accounts. This can cause direct losses, disclosure of confidential information, disruption of operations and reputational damage.


How SIM swapping and phone fraud work

A typical SIM swap attack begins with the collection of personal data. Criminals may obtain it through phishing, data leaks, social engineering, false job offers, fake courier messages or earlier account breaches. The information is then used to convince a telecom operator that the offender is the legitimate subscriber.

After the replacement SIM is activated, the victim’s physical phone often loses mobile network access. This may be the first visible warning sign. The offender can then intercept SMS messages containing authentication codes and password-reset links.

Phone fraud may also take other forms, including:

  • vishing – fraudulent telephone calls impersonating a bank, public authority, courier company or business partner;
  • caller ID spoofing – displaying a false number, including a number associated with a real institution;
  • smishing – fraudulent SMS messages containing malicious links or requests for payment;
  • fraudulent eSIM activation or unauthorised changes to a customer account;
  • mobile banking fraud involving intercepted authentication codes;
  • business email compromise supported by access to an employee’s phone number or email account.

The Act on Combating Abuse in Electronic Communications introduces measures intended to counter selected telecommunications abuses, including CLI spoofing and smishing. These measures are relevant to prevention, but they do not remove the need for internal incident-response procedures within a company.[4]


Criminal liability for SIM swapping crime in Poland

The primary legal qualification will depend on the facts. Where an offender deceives a victim, bank or telecom operator in order to obtain money or cause an unfavourable disposal of property, Article 286 § 1 of the Polish Criminal Code may apply. The provision concerns fraud committed with the purpose of obtaining a financial benefit.[1]

Where the conduct affects automated data processing, such as the entry, alteration or deletion of data in an IT system, Article 287 § 1 of the Criminal Code may be relevant. This provision addresses computer fraud and may apply, for example, where access to mobile banking is used to execute unauthorised transactions.[1]

Unauthorised access to data or an information system may also lead to liability under Article 267 §§ 1-2 of the Criminal Code. The provision covers obtaining information not intended for the offender and unlawfully accessing all or part of an IT system. The precise qualification depends on whether security measures were overcome, what information was obtained and how it was subsequently used.[1]

In some cases, an offender may impersonate another person by using their personal data or image. Article 190a § 2 of the Criminal Code criminalises impersonation where it causes pecuniary or personal harm. This may be relevant where stolen identity data is used to obtain a replacement SIM card, activate an eSIM or communicate with a financial institution.[1]

One act can fulfil the elements of several offences. Investigators and prosecutors therefore assess the entire sequence of events rather than only the unauthorised SIM replacement.


Mobile banking fraud and business consequences

For businesses, mobile banking fraud can create a fast-moving crisis. A criminal who controls the number of a finance director, authorised representative or administrator may attempt to change payment details, approve transfers or reset credentials for business accounts.

The risk is particularly high where SMS is the only second authentication factor. SMS codes remain widely used, but they are vulnerable when the telephone number itself is taken over. Companies should consider stronger authentication methods, including authenticator applications, hardware security keys and approval procedures requiring independent verification.

In practice, a business should treat the sudden loss of mobile service on an employee’s device as a potential security incident, especially if that employee has access to payments, sensitive data or privileged systems.

Immediate actions after a suspected SIM swap

  1. Contact the telecom operator through an independently verified channel and request immediate suspension of the affected number, SIM card and eSIM profiles.
  2. Contact banks, payment institutions and key service providers to block access, suspend transactions and secure accounts.
  3. Change passwords from a trusted device and revoke active sessions for email, banking, cloud and business applications.
  4. Preserve evidence, including screenshots, SMS messages, call logs, operator correspondence, bank notifications and records showing the loss of network access.
  5. Notify internal IT, compliance, management and data-protection personnel where company systems or personal data may have been affected.
  6. Report the matter to the Police or prosecutor’s office without delay, particularly where funds were transferred or confidential data was accessed.


Evidence and reporting telecom fraud in Poland

Early evidence preservation can materially affect the prospects of identifying offenders and recovering assets. Telecom and banking records may show the time of a SIM replacement, IP addresses, devices, transaction routes, login activity and communications with customer support.

In criminal proceedings, relevant information may be secured through procedural measures under the Code of Criminal Procedure, including the seizure of items and data. Article 218 of the Code provides a basis for obtaining certain telecommunications data for the purposes of pending proceedings, subject to statutory conditions.[2]

A company should also document its internal response. This includes the time of detection, persons notified, accounts blocked, financial exposure, systems affected and decisions made by management. Such documentation supports criminal proceedings, insurance notifications, regulatory assessments and internal accountability.

Where an incident involves personal data, the organisation should separately assess whether it constitutes a personal data breach requiring notification under Articles 33 and 34 of the GDPR. The obligation depends on the risk to the rights and freedoms of natural persons, not merely on the fact that a phone number was compromised.[5]


Prevention measures for companies and executives

Effective prevention combines technical controls, employee awareness and clear escalation rules. Relevant measures include:

  • restricting SMS authentication for high-value payments and administrator accounts;
  • requiring dual approval for changes to bank-account details and payments;
  • verifying payment instructions using a previously known contact channel;
  • limiting employee access rights according to role and business need;
  • training employees to recognise vishing, smishing and social-engineering attempts;
  • maintaining a documented incident-response process involving IT, legal, compliance and management;
  • monitoring suspicious account resets, eSIM activations and changes to authentication methods.

Further information on criminal risks connected with digital attacks is available in KKZ materials on cybercrime, scams and cybercrime prosecution in Poland.

This is informational material, not legal advice. The legal assessment of SIM swapping, phone fraud and mobile banking fraud depends on the evidence, financial flows, method of authentication and the roles of the persons involved.


Where criminal proceedings concern SIM swapping or phone fraud, it may be useful to consult the case with a lawyer and obtain an assessment of the situation. Kopeć & Zaborowski (KKZ) lawyers can discuss possible procedural steps and evidence-related issues.


FAQ – SIM Swapping and Phone Fraud in Poland

Is SIM swapping a crime in Poland?

SIM swapping may be a crime, although it is not a separate statutory offence. Depending on the facts, it may constitute fraud, computer fraud, unlawful access to an IT system, impersonation or other offences under the Criminal Code.

What is the first sign of a SIM swap attack?

A sudden loss of mobile network access, inability to make calls or receive SMS messages, or an unexpected notice of SIM or eSIM activation may indicate a SIM swap. The telecom operator and bank should be contacted immediately.

Can SIM swapping lead to mobile banking fraud?

Yes. If a bank uses SMS codes for login confirmation, password resets or transaction approval, control of the telephone number may enable an offender to access or attempt to access the customer’s banking services.

What criminal provisions may apply to phone fraud in Poland?

Common provisions include Article 286 § 1 of the Criminal Code on fraud, Article 287 § 1 on computer fraud, Article 267 on unlawful access to information or IT systems, and Article 190a § 2 on impersonation. The applicable provision depends on the conduct and evidence.

Should a company report a SIM swap to the Police?

A report should be considered promptly if funds, business data, customer data or access credentials may have been compromised. A swift report can support evidence preservation and measures aimed at tracing transactions.

Can a company rely only on SMS codes to secure payments?

SMS-only authentication creates a material risk in the event of SIM swapping. High-value payments and privileged accounts should use stronger authentication and independent approval procedures.


Bibliography

  • [1] Act of 6 June 1997 – Criminal Code, in particular Articles 190a, 267, 286 and 287, ISAP: https://isap.sejm.gov.pl/isap.nsf/DocDetails.xsp?id=WDU19970880553
  • [2] Act of 6 June 1997 – Code of Criminal Procedure, including Article 218, ISAP: https://isap.sejm.gov.pl/isap.nsf/DocDetails.xsp?id=WDU19970890555
  • [3] Act of 12 July 2024 – Electronic Communications Law, ISAP: https://isap.sejm.gov.pl/isap.nsf/DocDetails.xsp?id=WDU20240001221
  • [4] Act of 28 July 2023 on Combating Abuse in Electronic Communications, ISAP: https://isap.sejm.gov.pl/isap.nsf/DocDetails.xsp?id=WDU20230001703
  • [5] Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR), Articles 33-34, EUR-Lex: https://eur-lex.europa.eu/eli/reg/2016/679/oj

Need help?

Paweł Gołębiewski

Attorney-at-law, Head of International Criminal Law Practice

contact@kkz.com.pl

+48 509 211 000

Expert advice

Surveillance and Wiretapping in Poland: Defense Strategies

Read more
Surveillance and Wiretapping in Poland: Defense Strategies

Digital Evidence in Polish Criminal Cases: Admissibility

Read more
Digital Evidence in Polish Criminal Cases: Admissibility

Cross-Border Cybercrime: Poland’s International Cooperation

Read more
Cross-Border Cybercrime: Poland’s International Cooperation
See all Expert advice

How can
we help you?

Contact
the experts
Maciej Zaborowski

Maciej Zaborowski

Advocate, Managing Partner

Paweł Gołębiewski

Paweł Gołębiewski

Attorney-at-law, Head of International Criminal Law Practice

Menu

  • What we do
  • Who we work for
  • Team
  • Experience
  • Awards
  • Expert advice
  • Glossary
  • Guidelines
  • RODO & terms of service
  • Contact
Kancelaria Kopeć Zaborowski Adwokaci i Radcowie Prawni

What we do

  • Expert’s Report on Conditions in the Polish Justice System (Expert Witness)
  • Driving under the influence in Poland
  • Asset recovery in Poland
  • Cybercrime in Poland
  • Extradition in Poland
  • Show more +
  • White-collar crime in Poland
  • Whistleblowers in Poland
  • Letter of safe conduct in Poland
  • Intellectual property protection in Poland
  • Insurance Fraud in Poland
  • European Arrest Warrant in Poland
  • Criminal defense in Poland
  • Red Notice in Poland
  • Interpol in Poland
  • Frauds in Poland
  • Investigative audits and internal investigations in Poland
  • Criminal compliance in Poland
  • Corporate crimes in Poland
  • Money Laundering in Poland
  • Scams in Poland
  • Corruption in Poland
  • VAT Refund Fraud in Poland
  • Organaized Crime in Poland
  • Insider trading and disclosure of inside information in Poland
  • Criminal liability of company officers in Poland
  • Capital Fraud in Poland

Our other services: + Kopeć & Zaborowski + Lawyers in Poland + Kontrola celno-skarbowa + Blokada Konta + ESG w Firmie + Kontrola PIP

Created by Tomczak | Stanisławski

© Copyrights to Kopeć & Zaborowski Law Firm