Active Incident? 24/7 Response →
SleuthX

Beware of recovery scams

No legitimate service can guarantee it will get your money or account back for an up-front fee.

The FBI warns that “recovery scheme fraudsters charge an up-front fee and either cease communication with the victim after receiving an initial deposit or produce an incomplete or inaccurate tracing report and request additional fees to recover funds.” These schemes deliberately target people who have already been scammed once. Never pay an up-front fee to a company that contacts you promising to recover lost funds, accounts, or cryptocurrency, especially if they ask for payment in gift cards, wire transfer, or cryptocurrency. FBI sources: IC3 Public Service Announcement I-081123-PSA · FBI San Diego — Seizes Cryptocurrency Recovery Websites

For Individuals, Executives, and Crypto Holders

SIM Swap Attack Recovery
Telecom forensics. Identity hardening. Carrier accountability.

SIM swap attack recovery for individuals whose phone number was hijacked by a criminal who then took over email, banking, brokerage, crypto, and corporate accounts. We deliver telecom forensics, account-access timeline reconstruction, identity hardening, and the FCC carrier-grievance package that supports civil action against the wireless provider. We investigate and document; we do not guarantee recovery of funds. SleuthX, Inc. is an independent digital-forensics company; regulated investigative work is handled by our licensed Florida PI partner network under their own licenses.

Your phone went silent. Your bank texted to confirm a transfer you did not make. Your email started rejecting your password.

Within hours, the wallets were drained, the brokerage account was liquidated, and the email that anchored every other account in your life was being used by someone in another time zone.

By the time you got the line back from the carrier, the damage was already cascading. This is the moment we step in.

Quinnlan Varcoe, Founder and CEO, sets the methodology every SIM swap scam investigation runs under and reviews case findings before they leave the practice. The practitioner team executes the technical work.

Engagements are confidential, NDA-protected, and structured to begin within 24 to 48 hours of the consultation because the cleanup window for cascading account compromise is short.

Pricing is hourly at $400 per hour, the same standardized rate every SleuthX engagement bills at, including expert testimony in Quinn's certified areas of incident response and intrusion analysis. The alternative is a done-for-you device package from $3,000, each including the $995 lifetime license.

Optional fixed-fee tracks for well-bounded scope and sliding-scale pricing for individuals who lost retirement or operating funds are available on the first call.

What this is

A forensic SIM swap attack recovery engagement produces the documented evidentiary record that the FBI Internet Crime Complaint Center, the FBI Cyber Division and Secret Service Cyber Fraud Task Force, the Federal Communications Commission, your state public utilities commission, your wireless carrier's executive escalation channel, your cyber and crime insurance carrier, civil counsel pursuing the carrier under 47 U.S.C. §222 (enforced through the private damages action in §§206–207) and state-law negligence theories, and where applicable, plaintiff trial counsel and licensed crypto asset-recovery partners can act on.

The investigation traces how the swap was authorized (in-store insider, call-center social engineering, online portal compromise, stolen carrier credentials), reconstructs the cascading account-takeover timeline across email, banking, brokerage, crypto exchanges, and corporate accounts, identifies any persistent criminal access, and produces the carrier-grievance and civil-action package that the institutions with subpoena power and recovery authority use to act on your case.

Who this is for

One boundary worth naming: this page assumes a criminal stranger.

If the person with your number or your accounts is someone you know, a partner or ex who had your phone and knows your passwords, the recovery order changes, because locking them out is visible to them: what to do if someone has access to your phone walks that case.

How the engagement works

  1. Free confidential consultation by phone or video. NDA-protected. 30 to 60 minutes. Direct conversation with Quinn, the founder and CEO who sets the methodology behind every engagement. We hear the timeline, identify the immediate triage actions (port-freeze, account-recovery sequence, evidence preservation), and tell you whether forensic investigation will materially help or whether the situation can be resolved by going straight to the carrier and your bank.
  2. Scoped engagement with a written proposal and pricing. Choose the $995 self-serve tool or a done-for-you device package from $3,000 (each including the $995 license); a refundable retainer covers intake, immediate identity-hardening triage, and the first round of account-takeover and carrier-side evidence preservation. $400/hour flat for anything beyond a package.
  3. Forensic acquisition of relevant artifacts. Wireless carrier account history (CPNI request, port-history, account-change logs), email account login and device-fingerprint history, banking and brokerage account exports, cryptocurrency exchange account exports and transaction history, hardware security key and authenticator-app provisioning logs, and where applicable, corporate single-sign-on access logs (with employer authorization).
  4. Investigation and reconstruction. Source of the SIM swap (in-store insider, call-center social engineering, online portal compromise, stolen carrier credentials), full cascading account-takeover timeline mapped against the swap window, identification of any persistent criminal access (residual mail rules, OAuth tokens, recovery-factor pollution), and where crypto was stolen, off-ramp jurisdiction and exchange identification for coordination with licensed asset-recovery partners.
  5. Identity hardening. Migration off SMS-based authentication for every account that supports it, hardware security key deployment, recovery-factor rotation to clean accounts the criminal does not know about, carrier-side port-freeze and porting PIN configuration, eSIM transition where supported, data-broker scrub to reduce the public attack surface that enables the next swap.
  6. Written report built on documented methodology and a clear chain of custody so the findings can withstand courtroom scrutiny, though admissibility is ultimately the court's call. It is structured for the specific pathways that apply: FBI IC3 and Cyber Division referral, FCC and state PUC formal carrier complaints, civil action against the wireless carrier under 47 U.S.C. §222 (enforced through §§206–207) and state-law negligence theories, cyber insurance claim, and where crypto was stolen, evidence-package coordination with licensed asset-recovery partners.
  7. Coordination with the wireless carrier's executive escalation channel, FBI Cyber Division, Secret Service Cyber Fraud Task Force, FCC and state PUC, your insurance carrier, civil counsel, and where applicable, licensed asset-recovery partners.

How we work a SIM swap case

SIM swap protection is structural, not behavioral

The hardest lesson from a SIM swap is that the protections most people have are inadequate against a determined attacker. SMS-based two-factor authentication is not a meaningful defense against a criminal who can take over the phone number itself. Carrier-side port-freezes and porting PINs are useful but defeated by insiders. The defense that works is structural:

We deliver this hardening as the second deliverable of every SIM swap recovery engagement, after the timeline reconstruction. It is the work that makes a second swap far harder to pull off.

Evidence for a bank dispute, a Regulation E claim, or a carrier lawsuit

Where a SIM swap led to a fraudulent transfer, the forensic record is what turns a denied claim into a documented one. We assemble the carrier-side and account-access evidence in the form your bank's fraud team, a Regulation E error-resolution claim, or your cyber-insurance carrier actually asks for, namely the swap timeline, the unauthorized-change logs, and the account-takeover artifacts, preserved under a documented chain of custody. Regulation E is the right tool for a narrow slice: unauthorized electronic fund transfers on a consumer bank account, covering debit-card and ACH fraud, where you generally have 60 days to notify the bank and it has roughly 10 business days to investigate. It does not reach wire transfers, brokerage liquidations, or crypto withdrawals, which fall outside Reg E and run on other tracks. If you are weighing a civil suit or arbitration against the carrier, that same package is the forensic report your attorney needs: plaintiffs' firms that litigate SIM-swap cases under 47 U.S.C. §222 (via the §§206–207 damages action) and state negligence theories require exactly this evidence, and we coordinate the hand-off to counsel you retain. We investigate and document; recovering the funds is controlled by your bank, insurer, and counsel, and we do not guarantee it.

How We Work

A confidential, structured engagement.

01

Confidential Consultation

A direct conversation with Quinn, the founder and CEO who oversees every engagement. NDA-protected. No sales process.

02

Scoped Engagement

A clear written proposal with defined deliverables, timeline, and pricing. No hidden costs.

03

Investigation and Findings

Forensic work conducted to court-admissible standards, with regular communication and a written summary you can act on.

Meet Your Practitioner

Quinnlan Varcoe

Founder & CEO

GIAC-certified · 9 industry certifications

With operational experience across Fortune 50 security programs and the defense industrial base, Quinnlan founded SleuthX in 2022 to provide clients with the caliber of expertise typically reserved for the largest enterprises. Her work in threat intelligence and digital forensics has earned the trust of 26,000+ cybersecurity professionals who follow her analysis.

“26,000 professionals follow my work because I say what others won't — and I can back it up technically.”

Fortune 50 BackgroundDefense IndustryThreat IntelligenceDigital PrivacyIncident Response
Quinnlan Varcoe, Founder & CEO

Certified Expertise

GIAC

Frequently asked about SIM swap attack recovery

My phone went dead and now my accounts are gone. What is happening and what do I do first?
What is almost certainly happening is a SIM swap attack: a criminal social-engineered your wireless carrier (or paid an insider at the carrier) to transfer your phone number to a SIM card the criminal controls. Once the criminal owns your number, they own every account that uses SMS as a recovery factor or as a second factor of authentication: email, banking, brokerage, crypto exchanges, payment apps, and frequently the corporate single-sign-on you use at work. The first three actions matter enormously and are time-sensitive. First, call your carrier from a different phone immediately, identify yourself in person at a retail store if possible, and demand the line be returned to your control with a port-freeze and a porting PIN added to the account. Second, from any device you still control, change passwords on email first, then financial accounts, then crypto exchanges, and rotate every recovery email and recovery phone number to a new account the criminal does not know about. Third, file an FBI IC3 complaint and a complaint with the Federal Communications Commission and your state public utilities commission against the carrier. Then call us. The forensic window for recovering attribution evidence on the carrier-side compromise is short.
How is a SIM swap attack recovery investigation different from a carrier complaint?
A carrier complaint is a customer-service ticket filed against the company that let the swap happen. A SIM swap attack recovery engagement produces the documented forensic record that turns that complaint into a viable claim and supports every other recovery pathway. We acquire the carrier's account-history records (CPNI, port logs, account-change logs), reconstruct the timeline of unauthorized account changes, identify the channel through which the swap was authorized (in-store insider, call-center social engineering, online portal compromise, account-takeover via stolen carrier credentials), correlate the swap timing with the downstream account takeovers (email, banking, brokerage, crypto), and produce a chain-of-custody package that supports civil litigation against the carrier under 47 U.S.C. §222 (a carrier duty a private plaintiff enforces through §§206–207) and state-law negligence theories, FCC and state PUC formal complaints, IC3 and FBI Cyber Division referral, cyber insurance claims, and where crypto was stolen, evidence-package coordination with licensed asset-recovery partners.
Can you actually help me recover stolen crypto from a SIM swap?
Be clear-eyed about two very different outcomes here. Getting your phone number back from the carrier is usually fast, often within hours. Recovering money or crypto that was drained while the attacker controlled your number is a separate and much harder problem, and stolen crypto is frequently not recoverable at all once it leaves your control. We help with the forensic and coordination side, not the direct recovery. Cryptocurrency stolen via SIM swap is typically moved through exchanges, mixers, and chain-hops within hours or days of the takeover. Recovery requires blockchain tracing (which we coordinate with specialist partners; we do not perform on-chain tracing in-house), exchange-level legal demands (which require licensed counsel or law-enforcement subpoena), and frequently international cooperation. What we deliver is the forensic case file: timeline of the SIM swap, account-takeover artifacts on every wallet and exchange account that was compromised, carrier-side evidence supporting civil action against the wireless provider, and IC3 and FBI Cyber Division referral package. We then coordinate the introduction to a licensed asset-recovery partner where one is appropriate. We do not promise crypto recovery and we do not take fees contingent on recovery; that structure is reserved for licensed asset-recovery counsel and we are not that. And be wary of anyone who guarantees they can get your crypto or drained funds back for an up-front fee, because that guarantee is itself a scam, and the FBI and FTC warn that these fake recovery operators specifically target people who were just hit.
What about my email account, my banking, my work accounts? How bad is this and how long does cleanup take?
How bad it is depends on how long the criminal had control of your number before you noticed. A swap that lasted ninety minutes typically results in two or three primary account takeovers (most commonly the email account that anchors everything else, plus one or two financial accounts). A swap that lasted twelve hours typically results in cascading compromise across twenty or more accounts as the criminal works systematically through every service that uses SMS-based password reset. Cleanup is not a one-day job. We typically scope a SIM swap recovery as a 12 to 25 hour forensic engagement, structured across roughly two to four weeks: account-takeover triage in the first 48 hours, full timeline reconstruction in the first week, identity-hardening in the second week (rotating every recovery factor away from SMS, deploying hardware security keys on every account that supports them, locking carrier-side port-freezes and porting PINs in place), and the FCC/PUC carrier-grievance package and civil-action support documentation in the third week. Run it yourself in the SleuthX tool for $995 once, or have our team do it for you in a done-for-you device package from $3,000 (each including the $995 lifetime license); anything beyond a package is scoped per case at a flat $400/hour.
Should I sue my wireless carrier for the SIM swap?
Talk to a plaintiffs attorney who handles telecommunications-fraud cases before answering that question. There is a body of case law (T-Mobile, AT&T, Verizon have all been sued repeatedly for SIM swap negligence) and the legal theories include the carrier's duty to protect customer proprietary network information under 47 U.S.C. §222, a duty a private plaintiff enforces through the damages action in §§206–207 and the theory the Ninth Circuit allowed to proceed in Terpin v. AT&T (2024), where it survived summary judgment rather than winning on the merits. Others are state-law negligence and gross negligence, breach of contract against the carrier's customer agreement, and where the swap was facilitated by a corrupt insider, agency-theory claims that hold the carrier responsible for the insider's conduct. That is persuasive authority, not a settled nationwide right to sue, and many carrier agreements compel arbitration, which can keep the dispute out of court entirely. Whether a suit is viable in your case depends on the specific facts: how the swap was authorized, what the carrier knew or should have known, whether port-freeze or PIN protections were in place and bypassed, and the size of the loss relative to the cost of litigation. Our forensic report is the foundation of any such case. We do not provide legal advice and we do not represent clients in litigation; we produce the evidence and refer to plaintiffs counsel where appropriate.
How much does a SIM swap attack recovery cost?
You have two ways to work with us. Run the investigation yourself in the SleuthX tool for $995 once. That is lifetime access, with usage metered from a prepaid balance you top up anytime. Or have our team do it for you in a done-for-you device package: $3,000 for one device, $7,000 for three, $12,000 for five, each including the $995 lifetime license. Where the case expands beyond a package (multi-month criminal persistence, multi-jurisdictional crypto theft, corporate single-sign-on compromise that bridges into a workplace cybersecurity incident), it is scoped per case at a flat $400/hour, with no multipliers. Sliding-scale pricing is on the table on the first call for individuals who lost retirement, payroll, or operating funds and cannot fund a full engagement at headline rates.
Can you actually identify the people behind the SIM swap?
Sometimes, and the attribution evidence on SIM swap cases is meaningfully better than on most other fraud verticals because the carrier-side records are subpoena-able and the criminal's downstream account activity (email logins, exchange logins, IP and device fingerprint logs) is often well-preserved on the platforms they touched. Mid-tier SIM swap operations operate inside the United States and reuse cashout infrastructure (specific exchanges, specific mule accounts, specific OTC desks) that creates attribution patterns. Identification of a specific named individual usually requires law-enforcement subpoena power; we produce the evidentiary package that the FBI Cyber Division, the Secret Service Cyber Fraud Task Force, and state attorneys general use to open or extend cases. Several high-profile SIM swap prosecutions in recent years followed exactly this evidentiary pattern: the California REACT Task Force's string of SIM-swap cases, and separately the federal Scattered Spider prosecution of Noah Urban in Florida, who was arrested in 2024 and sentenced to ten years in August 2025.
How do I prevent this from happening again after the cleanup?
SIM swap protection is structural, not behavioral. The single highest-leverage change is moving every account that supports it off SMS-based authentication and onto either a hardware security key (YubiKey, Google Titan) or an app-based authenticator (Google Authenticator, Authy, 1Password) with the recovery factors rotated to a new email address that the criminal does not know about and that itself has hardware-key authentication. The second is locking the carrier account: port-freeze enabled, porting PIN set to a value not derivable from public information, account-PIN rotation, in-store-only authentication for any future account changes, and where supported, eSIM-only operation that prevents physical-SIM transfer entirely. The third is reducing the public attack surface: removing personal information from data brokers, scrubbing the phone number from social media and professional profiles, and reducing the number of services that have your number on file. We deliver this hardening as part of every SIM swap recovery engagement, and it is the deliverable that makes a second swap far harder to pull off. Follow-on targeting, including repeat swap attempts and fake "recovery" scams that circle back to fresh victims, is a known risk after a first attack.
Quinnlan Varcoe, Founder & CEO
Quinnlan Varcoe
GIAC-certified · Founder & CEO

Schedule Your Session

Schedule a confidential consultation

A direct conversation with Quinn, the founder and CEO who oversees every engagement. NDA-protected. No sales process. Most engagements begin within 48 hours.

Free, confidential · NDA-protected · no obligation.

  1. 1. Book a 30-minute call — we scope your situation, no charge.
  2. 2. You get a written scope — deliverables, timeline, and price — before any work begins.
  3. 3. Approve it and we start; most engagements begin within 48 hours.

Transparent pricing

Trusted by partners across the practice

DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management
DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management