SIM swap vs IMSI catcher
SIM swap and IMSI catcher attacks are frequently conflated. They share a target (a subscriber) but not much else. One is a social-engineering attack against the operator's customer-service process; the other is a radio-layer man-in-the-middle.
| Attribute | SIM swap | IMSI catcher |
|---|---|---|
| Attack surface | Operator business process | Radio interface |
| Attacker access | No hardware — a phone call or portal | Fake base station, SDR |
| Cost | Near zero | Hundreds to tens of thousands of USD |
| Scale | One victim at a time | Every device in radio range |
| Persistence | Until victim re-swaps | While device is camped on rogue cell |
| Defense | Number-porting friction, MFA channel diversity | 5G SA (SUCI), rogue-cell detection |
Verdict
SIM swap is the vastly more common attack because it needs no hardware and scales with the operator's weakest CSR. IMSI catchers matter more for targeted, high-value surveillance. Confusing the two leads to the wrong controls — number-porting rules do not stop rogue cells, and 5G SUCI does not stop a call to customer service.