Posts Tagged ‘SIM farm’

ICE Dismantles Criminal SIM Farms

Wednesday, July 29th, 2026

Remember last year’s story about a “SIM farm” that was later linked to China? ICE just shut down a whole lot more.

Immigration and Customs Enforcement’s (ICE’s) Homeland Security Investigations carried out a nationwide operation between June 22 and July 10 that dismantled “SIM farms” run by transnational criminal organizations.

SIM (subscriber identity module) farms are systems containing large numbers of SIM cards from different wireless carriers, often housed in banks of cellphones, modems, or specialized devices known as SIM boxes.

These can be used to send and receive bulk messages or calls and often exploit voice over internet protocol (VoIP) technology to do so. Initially developed for legitimate purposes, the technology has become prominent among organized fraudsters targeting mass audiences through phishing texts, scam calls, and fraudulent online accounts.

The recent nationwide operation, dubbed Operation Signal Break, “dismantled critical command-and-control infrastructure used to perpetrate large-scale telecommunications fraud across the United States,” ICE said in a July 24 statement.

Authorities will now analyze the seized SIM data to identify victims and assess losses caused by such fraud. The illicit proceeds from the fraud, which are suspected to be linked to Chinese transnational criminal organizations and distribution networks, will be traced.

This is expected to support criminal indictments, sanctions targeting national and international infrastructure used in criminal activity, and asset seizures. SIM box operations are estimated to result in losses worth $15 million annually to Americans, according to ICE.

SIM box fraud, “also known as interconnect bypass fraud, is a scheme in which fraudsters reroute international calls to appear as local ones,” a Nov. 8, 2025, post from IT services provider Synaptique said.

For instance, when a foreign national calls someone in the United States, the call is diverted through VOIP to a SIM box in America instead of passing through a legitimate international call gateway. The SIM box then uses one of the local SIM cards to place a new local call to the recipient.

SIM boxes can be used by criminals to communicate in a clandestine manner. Foreign rival states and intelligence agencies can also use SIM boxes in their operations.

In its statement, ICE said that Operation Signal Break mobilized specialized SIM Box Surge Teams composed of criminal analysts, special agents, and computer forensic analysts, surging them to California, Florida, Texas, Massachusetts, New York, and New Jersey to tackle SIM farm operations.

“I commend our special agents for their outstanding dedication and teamwork in dismantling illicit telecommunications infrastructure,” Homeland Security Investigations (HSI) Acting Executive Associate Director John Condon said in the statement.

“Their relentless pursuit of justice and commitment to protecting the integrity of our communications networks have made our communities safer and sends a clear message to those seeking to exploit our systems to defraud Americans.”

Since 2024, the HSI has seized more than 1,900 SIM boxes, more than 500,000 SIM cards, and in excess of $700,000 in illicit proceeds. It has executed more than 116 federal criminal search warrants. In total, 68 SIM farms used to facilitate fraudulent texts and calls have been disrupted across 15 states. The probes have led to one criminal arrest and 11 administrative arrests.

68 SIM farms seems like a lot. I wonder if some are involved in those spam calls I receive every day on my iPhone, the ones I never pick up, and instead they roll to voicemail and leave a silent 1 second message.

I also note that ICE seems to be involved in a whole lot of cross-border crime enforcement action that have nothing to do with deporting the illegal alien felons Democrats seem to love above citizens…

Followup: Attack SIM Farm Is China’s

Sunday, October 5th, 2025

Remember the story from 10 days ago or so about the SIM farm that looked poised for a telecom infrastructure attack on New York City?

Well, as suspected, it was China’s.

New details emerged in an exclusive report from Blaze News, citing sources within the Department of Homeland Security and the U.S. intelligence community, who revealed that these SIM farms had been operational for more than a year and were operated by China’s Ministry of State Security.

“This is something that is a direct threat to our nation right now,” a top intelligence official told Blaze News. “A direct threat to our nation, and it needs to be shut down today — like ASAP. Only five of them have been taken down so far.”

The Blaze’s report continues:

The SIM networks were put in place and are managed by China’s Ministry of State Security, an ultra-secretive, massive espionage agency that has grown in prominence and global activity in recent years, according to the journal China Leadership Monitor.

The MSS employs more than 800,000 people, nearly double the Soviet KGB at its peak. The MSS “now operates worldwide at a scale and tempo not seen in decades,” China Leadership Monitor wrote in a recent newsletter.

Several officials who spoke with Blaze News anonymously said the establishment and use of this destructive network by China should be considered an act of war. The potential threat to America would be “second only to thermonuclear war,” one source said.

“It’s absolutely an act of war — an internationally recognized act of war,” one intelligence expert told Blaze News. “Cyberattacks on critical infrastructure is, and facilitating terrorism to the point where you’re trying to kill high-ranking members of the United States government. Those two alone are acts of war.”

. . .

“These things were being used all summer to SWAT people since Trump was elected,” said one source, speaking anonymously because the source is not authorized to discuss an ongoing investigation. “Swatting — that’s a terrorist act. The Trump administration declared that a terrorist act.”

While the Chinese facilitated the SWAT raids, it is believed that Americans who are familiar with the system — either through a government or a criminal enterprise — are initiating the hoax calls, the source said.

If Americans are indeed working with a foreign power to commit terrorist acts against American citizens, that opens a whole host of legal and national security tools to go after domestic terror networks.

The swatting of a senior Secret Service official and some Secret Service protectees last spring led to the investigation that discovered the Chinese SIM farms in the Tri-State area, the Secret Service confirmed to Blaze News. A Secret Service engineer assigned to the investigation was key to discovering the SIM network.

An intelligence analyst told Blaze News that:

What’s shocking is that there may be up to 100 or more of these sites everywhere. There’s probably 60, 80, 100 of these in the United States.

The discovery of weaponized SIM farm nodes by China should not come as a surprise. This is because the Chinese Communist Party’s ongoing irregular warfare campaign against the U.S. has been supercharged over the years, especially in the era of Trump.

If theses SIM farms are active, there should be ways for telecomms to algorithmically search for mobile call hotspots where too many calls issue from too small an area. Let’s hope they’re doing that and working with various U.S. three letter agencies to shut them down right now.

How many other instances of Chinese infrastructure attack centers currently lie in wait to attack the U.S.?

NYC Infrastructure Attack Thwarted

Wednesday, September 24th, 2025

This seems like a story that should have gotten a lot more attention than it has. “Secret Service Dismantles Weaponized SIM Farms Designed To ‘Shut Down’ NYC Cell Networks.”

Hours before President Donald Trump’s address to the United Nations General Assembly, the U.S. Secret Service announced that it had dismantled a massive, decentralized SIM farm network, just 35 miles from New York City, hidden inside five abandoned apartment buildings. The telecommunications stealth weapon was capable of paralyzing regional cell networks through denial-of-service attacks.

Key Details from the Secret Service Report:

Investigators seized 300 SIM servers and 100,000 SIM cards across multiple sites.

The devices enabled anonymous threats, encrypted communications, and could launch telecom attacks such as:

  • Disabling cell towers
  • Denial-of-service attacks
  • Secure communication for criminal enterprises
  • If you want secure communications networks, there are lots of cheaper ways to do it that don’t involve rooms of rackmountable servers full of SIM cards. This setup suggests a big planned infrastructure hit.

    Early analysis shows links between nation-state actors and known criminals.

    CBS News described the seizure as the largest of its kind, noting the network was scattered across abandoned apartment buildings at more than five sites, roughly 35 miles from New York City.

    Pretty ballsy to just pick abandoned apartment buildings and go “Hey, let’s just move lots of really expensive equipment in here for a future attack. I’m sure no one will notice.”

    “This network had the potential to disable cell phone towers and essentially shut down the cellular network in New York City,” Secret Service Special Agent in Charge Matt McCool stated in a video released in the report by the agency.

    Beyond DDoS attacks, the SIM farms could also support psychological warfare operations such as:

  • Mass disinformation campaigns
  • Emergency false alerts (e.g., fake evacuation texts)
  • CBS, citing multiple officials briefed on the probe, reported that early findings suggest the network was used for communications between foreign governments and individuals already known to U.S. law enforcement.

    In our view, the likelihood of this being part of a larger threat vector for potential physical terrorism appears elevated. Consider this: disrupting communications in tandem with a physical attack would be the playbook for foreign adversaries…

    The Secret Service tweet shows an awful lot of specialized hardware:

    The scale of the thing suggests a state actor behind the plot, most likely China or Russia.

    A bigger concern is that such a telecom infrastructure attack probably wouldn’t be the main attack, but likely a secondary attack to slow response to or amplify the chaos of the primary attack. You don’t spend this much time and effort to annoy New Yorkers for a day or two before countermeasures can be deployed.

    No, this was a supporting element for something much bigger.

    So what was the primary attack supposed to be?