In the beginning, the prizes were Instagram handles.
A single-word username - @god, @fire, @rare - could sell for thousands of dollars on OGUsers, a forum founded in 2017 for trading "original" social media accounts. The market was driven by status: in certain corners of the internet, a rare handle was the digital equivalent of a vanity plate. Gamers wanted them. Hypebeasts wanted them. Flex culture demanded them.
To get them, you needed to take them from whoever already had them. Which meant finding a way to access the account. And the most reliable way to access an account was to control the phone number attached to it.
SIM swapping - convincing a carrier to transfer someone's phone number to a SIM you control - had existed since at least 2013 as a fraud vector. But OGUsers turned it into an industry. By 2019, the same community that had started by stealing Instagram handles was stealing millions of dollars in cryptocurrency per week. By 2020, they had compromised the internal tools of the most powerful social media company on earth.
//How SIM Swapping Works
Modern authentication is built on the assumption that your phone number is yours. SMS two-factor authentication sends a code to your number; if someone else gets that code, they control the account. SIM swapping attacks this assumption at its weakest point: the carrier's customer service desk.
The process, in its simplest form, is a social engineering call. A swapper calls T-Mobile, AT&T, or Verizon. They claim to be the account holder. They've lost their phone. They need the number ported to a new SIM. The carrier asks security questions - date of birth, last four of Social Security, billing address. The swapper has all of this, either from data breach databases or from targeted research on the victim.
The carrier ports the number. For a few minutes to a few hours, the victim's phone goes dead - no signal, no texts, no calls. The swapper uses those minutes to trigger password resets on every account tied to the phone number. Gmail. Apple ID. Coinbase. Binance. Everything that sends a recovery code by SMS.
//The OGUsers Scene
At its peak, OGUsers.com was a marketplace, a community, and a training ground. Members bought and sold handles. They ran reputation threads. They posted tutorials. They had a tiered vendor system. The forum had rules - no scamming members, required escrow for high-value trades - that mimicked the structure of legitimate e-commerce platforms. The irony was not lost on investigators who later described it as "remarkably well-organised for a criminal enterprise."
Behind the forum economy was a services layer. Dedicated "callers" made the carrier calls - specialists who had scripted the calls, knew which representatives were most susceptible, and had practiced until the social engineering was reflexive. "Lookers" sourced victim information from breach databases. "Coiners" handled the cryptocurrency extraction once accounts were accessed. The division of labour made the operation efficient and kept any one person from knowing the full picture.
Carrier insider corruption became a documented problem. AT&T acknowledged that several employees had accepted payments to facilitate swaps. T-Mobile faced multiple lawsuits from victims whose numbers were ported after insider involvement. The combination of social engineering and insider access made the carriers' own authentication systems effectively useless.
//The Escalation to Crypto
The transition from stealing Instagram handles to stealing cryptocurrency happened quickly once the community noticed how much money was sitting in unprotected Coinbase accounts. Crypto exchanges of the era almost universally relied on SMS 2FA. Wallets holding life-changing amounts of money were protected by nothing more than a text message.
Michael Terpin, a cryptocurrency investor, lost $23.8 million in a January 2018 SIM swap. The investigation traced responsibility to Ellis Pinsky - who was 15 years old at the time of the theft. Pinsky had masterminded the operation from his bedroom in Irvington, New York, directing a crew that included Nicholas Truglia in Manhattan. When investigators eventually caught up with Pinsky, he was 18. The statute of limitations on juvenile charges had run. He settled a civil lawsuit with Terpin in 2022 for $22 million.
Truglia, arrested in November 2018, was found to have participated in swaps totalling over $100 million. He was 21. His iCloud backup, seized in the arrest, connected him to the Terpin theft and to dozens of other victims.
//The Twitter Hack: July 15, 2020
At 3:17 PM EST on July 15, 2020, Barack Obama's Twitter account posted: "I am giving back to my community due to COVID-19. All Bitcoin sent to the address below will be sent back doubled." Within minutes, the same message appeared on accounts belonging to Joe Biden, Elon Musk, Bill Gates, Jeff Bezos, Apple, and Uber. Over 130 accounts in total. In three hours, over 400 people sent Bitcoin to the posted address. $121,000 left the victims' wallets. The take wasn't the point. The access was.
What had happened was this: a 17-year-old in Tampa named Graham Ivan Clark had, through a combination of phone-based social engineering and a phishing site he had built to mirror Twitter's internal VPN portal, convinced a Twitter employee to hand over their credentials. That employee's access was enough to reach Twitter's internal admin tools - a system called "Agent," used by support staff to manage accounts.
Clark didn't do this alone. Joseph O'Connor - PlugwalkJoe on OGUsers - had been one of the community's most prominent members for years. British, born in Merseyside, operating from Estepona, Spain, he had built a reputation as a prolific account thief and social engineer. He was involved in planning the Twitter operation and in monetising the access. A third member, Nima Fazeli of Orlando, had served as a broker.
Clark was arrested seventeen days later. He was 17. Florida prosecutors charged him in state court, where juvenile protections don't apply at that age for serious felonies. He pleaded guilty, received three years, and began cooperating. O'Connor was arrested in Spain in 2021 after months of Spanish police surveillance, extradited to the US, and sentenced to five years in 2023.
//The Demographics
The pattern across every major SIM swapping prosecution is the same: the perpetrators are overwhelmingly young, overwhelmingly English-speaking, and overwhelmingly self-taught. They didn't have computer science degrees. They didn't come out of nation-state hacking programs. They learned their craft from forum posts, Discord servers, and Telegram groups - the same community infrastructure that had existed for a generation of online crime.
This is why the SIM swapping scene is interesting beyond its financial impact. It represents a particular kind of threat: technically accessible, community-amplified, and almost impossible to prevent at the carrier level without fundamental changes to how phone number authentication works. The attacks are low-tech in execution - they don't require zero-days or sophisticated malware. They require confidence, a phone, and a willingness to lie.
Every carrier has since implemented "SIM swap locks" and increased verification requirements. Every carrier still gets swapped regularly.
//What Came After
OGUsers was seized by federal investigators in 2021. The site's data - usernames, posts, private messages - became a roadmap for prosecutions. Instagram, Twitter, and TikTok coordinated a simultaneous purge of hundreds of OG accounts. But the community didn't disappear; it dispersed into Telegram channels, private Discord servers, and successor forums that don't require registration under permanent handles.
The SIM swapping scene evolved into the COM - the broader English-speaking cybercrime ecosystem that spawned Lapsus$ and Scattered Spider. The same teenagers who had been stealing Instagram handles were, by 2022, inside Microsoft's internal Confluence. The escalation was consistent and predictable, and law enforcement was consistently a step behind.
The infrastructure that enabled all of it - SMS 2FA, carrier social engineering vulnerability, the assumption that a phone number means identity - remains largely intact.