A London resident has been sentenced to two and a half years in prison for his involvement in a SIM-swap fraud scheme that resulted in the theft of almost £200,000 ($265,000) worth of cryptocurrency. Ajay Shinjin, 25, also known as AJ Marley Cruz, pleaded guilty on September 28 at Inner London Crown Court to conspiracy to commit fraud by false representation and transferring criminal property. The City of London Police described the operation as complex and calculated. Shinjin personally received more than £44,000 of the stolen funds, which he spent on luxury holidays in Dubai, a high-end apartment in Canary Wharf, and gold-plated teeth grills.
The fraud relied on criminals taking control of victims' phone numbers by transferring them to SIM cards under their possession, allowing them to intercept one-time passcodes sent by banks and crypto platforms. In November 2021, telecommunications provider BT identified unauthorized activity where customer numbers were moved to criminal-controlled devices. This data helped police trace suspects, linking Shinjin to four specific devices. Victims suffered significant losses: one lost about £40,000 in crypto, with Shinjin receiving approximately £27,000; another lost roughly £17,000, all of which went to Shinjin's wallet. He also assisted in stealing about £8,000 from a Coinbase account and approximately £130,000 from a fourth victim. Shinjin was initially arrested in 2021 and re-arrested at Heathrow Airport in October 2023 upon returning from Dubai after further evidence emerged.
This sentencing highlights the persistent vulnerability of SMS-based authentication within the digital asset ecosystem. By exploiting the transferability of phone numbers, attackers bypassed security layers designed to protect accounts, demonstrating that reliance on carrier infrastructure creates a single point of failure for both traditional banking and cryptocurrency exchanges. The case underscores how easily stolen digital assets can be converted into tangible luxury goods or real estate, complicating recovery efforts and emphasizing the need for robust internal controls at financial institutions to detect anomalous access patterns linked to number porting events.
The sharp rise in recorded SIM-swap cases, noted by Cifas as increasing 402% in the first half of 2026, suggests this method remains a preferred vector for cybercriminals despite growing awareness. Regulatory bodies and platform operators face pressure to mandate stronger verification protocols, such as app-based two-factor authentication, rather than permitting text-message codes. As institutional adoption expands, the operational risk associated with identity verification failures becomes more critical, potentially influencing compliance standards and insurance requirements for custody solutions. Monitoring carrier-level security enhancements will be essential to determine if technical barriers can effectively mitigate these recurring fraud attempts.


