London man jailed for SIM-swap ring that stole £200,000 in crypto from BT customers
A London man has been jailed for two and a half years for running a SIM-swap ring that stole nearly £200,000 in cryptocurrency from four BT customers in 2021, highlighting how phone network hijacks remain a viable attack vector against exchange users despite years of warnings.
- Ajay Shinjin, 25, pocketed £44,000 of stolen funds and spent it on Dubai holidays, a luxury Canary Wharf flat and gold-plated teeth grills.
- Four victims lost £130,000, £17,000, £8,000 and £40,000 respectively between November 2 and 7, 2021, after criminals hijacked their BT phone numbers.
- BT detected unauthorized SIM transfers in early November 2021; police traced devices to suspects and secured conviction more than four years after thefts occurred.
- £200,000 total cryptocurrency stolen from four BT customers via SIM-swap attacks in November 2021
- 2.5 years prison sentence handed to Ajay Shinjin at Inner London Crown Court on Thursday
- 4+ years time elapsed between reported thefts and conviction in October 2026
Ajay Shinjin, 25, a London resident also known as AJ Marley Cruz, pleaded guilty on September 28 to conspiracy to commit fraud by false representation and transferring criminal property, receiving his sentence at Inner London Crown Court on Thursday. The case began when BT detected unauthorized activity on its systems in early November 2021, according to the City of London Police. Criminals had transferred customer phone numbers to SIM cards they controlled, allowing them to intercept one-time passcodes sent by banks and crypto exchanges via text message, the standard second-factor authentication that protects account access.
Four victims drained of £130,000, £17,000, £8,000 and £40,000 in a single week
Police identified four victims between November 2 and 7, 2021. The first lost approximately £40,000, with £27,000 of that sum traced to Shinjin’s personal crypto wallet. The second victim’s entire loss of roughly £17,000, stolen between November 5 and 7, was later recovered in Shinjin’s account.
A third victim had about £8,000 drained from a Coinbase account on November 3, with Shinjin identified as facilitating the theft before the funds were transferred onward. The fourth victim, the heaviest hit of the group, lost approximately £130,000 in cryptocurrency between November 6 and 7, with Shinjin again identified by investigators as having facilitated the attack.
Shinjin spent his cut of the proceeds on a luxury flat in Canary Wharf, holidays in Dubai and gold-plated dental grills, according to police.
BT traced eSIM devices to suspects four years before conviction
When BT’s network team discovered the unauthorized transfers in early November 2021, they traced the devices receiving the hijacked numbers to eSIM-enabled handsets, each with two IMEI identifiers. That technical footprint allowed detectives to connect Shinjin to four of the devices used in the attacks. He was arrested at his flat in 2021 but released pending further investigation.
New evidence emerged that prompted a second arrest on October 2023, when Shinjin was apprehended at Heathrow Airport as he arrived from Dubai; he declined to comment during subsequent interviews.
Detective Constable Simon Ardeman of the City of London Police said the conviction demonstrates that “SIM-swap fraud is a sophisticated and increasingly concerning form of offending” and that such attacks remain difficult to detect and prevent.
SIM-swap fraud is a sophisticated and increasingly concerning form of offending, and this case demonstrates the devastating consequences it can have for victims.
Detective Constable Simon Ardeman, City of London Police
The four-year gap between the November 2021 thefts and October 2026 conviction underscores how resource-intensive SIM-swap investigations remain, even with forensic links to specific devices and individuals.
SIM-swap attacks continue to target exchange users globally
SIM-swap fraud targeting cryptocurrency users has not slowed despite increased awareness and regulatory focus. In June 2026, the FBI and Homeland Security Investigations helped Polish cybercrime police arrest four suspects accused of conducting similar SIM-swap attacks to drain cryptocurrency exchange accounts.
The tactic exploits a fundamental vulnerability in telecom infrastructure: customer service representatives at mobile carriers can be socially engineered into transferring a phone number to a new SIM card with minimal verification, granting attackers immediate access to SMS-based authentication codes that protect high-value accounts.
Institutional crypto investors and exchange operators have invested in alternative authentication standards and hardware security keys to mitigate exposure, yet SMS remains endemic to consumer onboarding and account recovery at most major platforms. The Shinjin case and parallel prosecutions suggest law enforcement has developed sufficient forensic capability to trace device IMEI data and link it to individuals, though the years required to investigate and prosecute remain a significant friction.
The CCS read. We see institutional investors and operators drawing two lessons from this case. First, that SMS-based second-factor authentication is not a durable security perimeter for high-balance accounts, and that exchanges and custody providers must continue moving toward passwordless and hardware-backed authentication. Second, that regulatory and law enforcement capability to pursue SIM-swap networks is maturing, but remains slow, meaning civil security measures remain the primary defense for users holding meaningful positions.
The sentencing does not resolve whether BT faces civil or regulatory liability for the unauthorized access on its 2021 systems, nor whether the UK’s Financial Conduct Authority will tighten telecom verification standards for crypto exchange account transfers. Watchlist: whether major UK and EU exchanges strengthen SMS alternatives as a condition of regulatory approval over the next 12 months, and whether the Shinjin conviction prompts BT or other carriers to publish data on SIM-swap fraud attempts and success rates.