Your phone went silent. Your bank texted to confirm a transfer you did not make. Your email started rejecting your password.
Within hours, the wallets were drained, the brokerage account was liquidated, and the email that anchored every other account in your life was being used by someone in another time zone.
By the time you got the line back from the carrier, the damage was already cascading. This is the moment we step in.
Quinnlan Varcoe, Founder and CEO, sets the methodology every SIM swap scam investigation runs under and reviews case findings before they leave the practice. The practitioner team executes the technical work.
Engagements are confidential, NDA-protected, and structured to begin within 24 to 48 hours of the consultation because the cleanup window for cascading account compromise is short.
Pricing is hourly at $400 per hour, the same standardized rate every SleuthX engagement bills at, including expert testimony in Quinn's certified areas of incident response and intrusion analysis. The alternative is a done-for-you device package from $3,000, each including the $995 lifetime license.
Optional fixed-fee tracks for well-bounded scope and sliding-scale pricing for individuals who lost retirement or operating funds are available on the first call.
What this is
A forensic SIM swap attack recovery engagement produces the documented evidentiary record that the FBI Internet Crime Complaint Center, the FBI Cyber Division and Secret Service Cyber Fraud Task Force, the Federal Communications Commission, your state public utilities commission, your wireless carrier's executive escalation channel, your cyber and crime insurance carrier, civil counsel pursuing the carrier under 47 U.S.C. §222 (enforced through the private damages action in §§206–207) and state-law negligence theories, and where applicable, plaintiff trial counsel and licensed crypto asset-recovery partners can act on.
The investigation traces how the swap was authorized (in-store insider, call-center social engineering, online portal compromise, stolen carrier credentials), reconstructs the cascading account-takeover timeline across email, banking, brokerage, crypto exchanges, and corporate accounts, identifies any persistent criminal access, and produces the carrier-grievance and civil-action package that the institutions with subpoena power and recovery authority use to act on your case.
Who this is for
- Cryptocurrency holders whose hot wallet, exchange account, or seed-phrase storage was compromised in the cascading account-takeover that followed a SIM swap.
- Executives and senior employees whose carrier-side compromise unlocked corporate single-sign-on, email, and access to sensitive workplace systems, frequently triggering a parallel corporate cybersecurity incident.
- High-net-worth individuals and family-office principals whose phone number is the recovery factor on a substantial concentration of financial accounts and who lost meaningful sums in the cascading compromise.
- MFA-protected high-value account holders who believed SMS-based two-factor authentication was sufficient and discovered the limits of that assumption in the worst possible way.
- Anyone who lost access to email, banking, or workplace accounts after a sudden phone outage and needs a forensic investigator to determine the scope of the compromise and produce the case file for recovery.
One boundary worth naming: this page assumes a criminal stranger.
If the person with your number or your accounts is someone you know, a partner or ex who had your phone and knows your passwords, the recovery order changes, because locking them out is visible to them: what to do if someone has access to your phone walks that case.
How the engagement works
- Free confidential consultation by phone or video. NDA-protected. 30 to 60 minutes. Direct conversation with Quinn, the founder and CEO who sets the methodology behind every engagement. We hear the timeline, identify the immediate triage actions (port-freeze, account-recovery sequence, evidence preservation), and tell you whether forensic investigation will materially help or whether the situation can be resolved by going straight to the carrier and your bank.
- Scoped engagement with a written proposal and pricing. Choose the $995 self-serve tool or a done-for-you device package from $3,000 (each including the $995 license); a refundable retainer covers intake, immediate identity-hardening triage, and the first round of account-takeover and carrier-side evidence preservation. $400/hour flat for anything beyond a package.
- Forensic acquisition of relevant artifacts. Wireless carrier account history (CPNI request, port-history, account-change logs), email account login and device-fingerprint history, banking and brokerage account exports, cryptocurrency exchange account exports and transaction history, hardware security key and authenticator-app provisioning logs, and where applicable, corporate single-sign-on access logs (with employer authorization).
- Investigation and reconstruction. Source of the SIM swap (in-store insider, call-center social engineering, online portal compromise, stolen carrier credentials), full cascading account-takeover timeline mapped against the swap window, identification of any persistent criminal access (residual mail rules, OAuth tokens, recovery-factor pollution), and where crypto was stolen, off-ramp jurisdiction and exchange identification for coordination with licensed asset-recovery partners.
- Identity hardening. Migration off SMS-based authentication for every account that supports it, hardware security key deployment, recovery-factor rotation to clean accounts the criminal does not know about, carrier-side port-freeze and porting PIN configuration, eSIM transition where supported, data-broker scrub to reduce the public attack surface that enables the next swap.
- Written report built on documented methodology and a clear chain of custody so the findings can withstand courtroom scrutiny, though admissibility is ultimately the court's call. It is structured for the specific pathways that apply: FBI IC3 and Cyber Division referral, FCC and state PUC formal carrier complaints, civil action against the wireless carrier under 47 U.S.C. §222 (enforced through §§206–207) and state-law negligence theories, cyber insurance claim, and where crypto was stolen, evidence-package coordination with licensed asset-recovery partners.
- Coordination with the wireless carrier's executive escalation channel, FBI Cyber Division, Secret Service Cyber Fraud Task Force, FCC and state PUC, your insurance carrier, civil counsel, and where applicable, licensed asset-recovery partners.
How we work a SIM swap case
- Written scope before any work. You see a written scope covering deliverables, timeline, and price, and you approve it before we begin. You are never billed for work you did not authorize.
- We commit to findings, not outcomes. We tell you up front what the evidence can and cannot establish. Recovery, attribution, and prosecution are decided by banks, platforms, insurers, and courts. We produce the record they act on, and we put that distinction in writing.
- Every case is investigated, not just scanned. A credentialed examiner reviews every case before findings leave the practice. You get a documented investigation to court-admissible standards, not a single automated scan and a one-line answer.
- We will tell you if you do not need us. If a free or simpler step would resolve your situation, whether a police report, an IC3 filing, or a platform's own recovery flow, we point you there first.
- No fees contingent on recovery. We charge for the forensic and coordination work at standard rates, never a percentage of funds recovered. Getting the money back is controlled by your bank, the carrier, your insurer, civil counsel, and law enforcement. We produce the case file and the FCC carrier-grievance package that make their work tractable, and we charge for that work whether or not the funds come back.
SIM swap protection is structural, not behavioral
The hardest lesson from a SIM swap is that the protections most people have are inadequate against a determined attacker. SMS-based two-factor authentication is not a meaningful defense against a criminal who can take over the phone number itself. Carrier-side port-freezes and porting PINs are useful but defeated by insiders. The defense that works is structural:
- every high-value account moved off SMS to a hardware security key or app-based authenticator
- recovery factors rotated to clean accounts that no public profile or data broker connects to your name
- the carrier account locked down to in-store-only authentication
- and the public attack surface (data brokers, social media, professional profiles) reduced to make the next swap operationally harder
We deliver this hardening as the second deliverable of every SIM swap recovery engagement, after the timeline reconstruction. It is the work that makes a second swap far harder to pull off.
Evidence for a bank dispute, a Regulation E claim, or a carrier lawsuit
Where a SIM swap led to a fraudulent transfer, the forensic record is what turns a denied claim into a documented one. We assemble the carrier-side and account-access evidence in the form your bank's fraud team, a Regulation E error-resolution claim, or your cyber-insurance carrier actually asks for, namely the swap timeline, the unauthorized-change logs, and the account-takeover artifacts, preserved under a documented chain of custody. Regulation E is the right tool for a narrow slice: unauthorized electronic fund transfers on a consumer bank account, covering debit-card and ACH fraud, where you generally have 60 days to notify the bank and it has roughly 10 business days to investigate. It does not reach wire transfers, brokerage liquidations, or crypto withdrawals, which fall outside Reg E and run on other tracks. If you are weighing a civil suit or arbitration against the carrier, that same package is the forensic report your attorney needs: plaintiffs' firms that litigate SIM-swap cases under 47 U.S.C. §222 (via the §§206–207 damages action) and state negligence theories require exactly this evidence, and we coordinate the hand-off to counsel you retain. We investigate and document; recovering the funds is controlled by your bank, insurer, and counsel, and we do not guarantee it.

















