A fake ID, an AT&T counter, and a hijacked number: anatomy of a SIM swap
Eric Council Jr. walked into a phone store, claimed a stranger's number, and used the codes it received to hijack the SEC's own X account. He drew 14 months in prison.
On January 9, 2024, the U.S. Securities and Exchange Commission's official X account posted that it had approved the first spot Bitcoin ETFs. It hadn't. Bitcoin jumped more than $1,000 within minutes, then fell over $2,000 once Chair Gary Gensler confirmed the account had been hijacked, per court records. The break-in began not with a hack but with a visit to a phone store.
One counterfeit ID
Eric Council Jr., 25, of Alabama, obtained a victim's personal details from co-conspirators, printed a fake identification card, and walked into an AT&T store in Huntsville claiming to be an FBI agent whose phone had broken, prosecutors said. He left with a new SIM card tied to the victim's number, bought an iPhone at a nearby Apple store, and used it to receive the two-factor codes protecting the @SECGov account. A co-conspirator posted the false approval, and Council was paid $50,000 in Bitcoin. Investigators noted he later searched online for how to tell whether the FBI was investigating him. He pleaded guilty and, in May 2025, was sentenced to 14 months in prison and three years of supervised release.
Why your number is the weak link
The attack works because so many services still treat a phone number as proof of identity. When a carrier moves a number to a new SIM — a legitimate feature for people who lose a phone — every text-message code, password reset and login prompt follows it. Whoever holds the number can then walk through 'forgot password' flows on email, exchange and social accounts. The SEC case stands out only for its target.
For an ordinary holder the exposure is the same. Because a phone number often sits behind the recovery path for email — and email sits behind everything else — a single successful swap can cascade across a victim's whole digital life. Every defense that matters removes the number from that critical path.
Harden your accounts
- Replace SMS text codes with an authenticator app or, better, a hardware security key; both are tied to a device, not a transferable number.
- Set a PIN or passcode with your mobile carrier and turn on any port-out or number-transfer lock they offer.
- Remove your phone number as a recovery or fallback option on email, banking and crypto accounts wherever the service allows.
- Keep meaningful crypto behind a hardware wallet, so a captured number alone cannot move funds.
- Treat sudden loss of cell service as a possible alarm — an unexpected 'no signal' can mean your number was ported away.
SIM swapping turns a customer-service convenience into a master key. Security agencies now urge dropping SMS-based two-factor authentication altogether, and the SEC hoax is a very public reminder of what one counterfeit ID and one compliant phone-store clerk can unlock.
— Sources: [BleepingComputer](https://www.bleepingcomputer.com/news/security/hacker-pleads-guilty-to-sim-swap-attack-on-us-sec-x-account/) · [The Register](https://www.theregister.com/2025/05/19/sim_swapper_sec_x_account/)
NOT FINANCIAL ADVICE · VERIFY EVERYTHING