1. How a Hacked Phone Scam Works: 4 Common Methods
Hacked phone scams share a common goal of gaining control over the victim's phone number, device, or linked financial accounts, but the method of access varies significantly and determines which laws apply.
Sim Swap Fraud
In a SIM swap attack, a criminal contacts the victim's wireless carrier and impersonates the account holder to transfer the phone number to a new SIM card. Once the transfer succeeds, the criminal receives all calls and texts intended for the victim, including one-time passwords and two-factor authentication codes. The criminal then uses those codes to access bank accounts, cryptocurrency wallets, and email accounts before the victim realizes the number has been moved.
The Federal Communications Commission adopted new SIM swap rules under 47 C.F.R. § 64.6 that took effect in July 2024, requiring carriers to notify customers of any SIM change request before completing the transfer and to verify identity through established secure methods. A carrier that fails to comply with these procedures and approves a fraudulent SIM swap may face regulatory exposure and may bear civil liability to the victim.
Tech Support Scam
In a tech support scam, a criminal contacts the victim by phone, text, or a browser pop-up claiming that the victim's phone or computer has been hacked and needs immediate repair. The criminal poses as a representative of Apple, Google, Microsoft, or a well-known security company. The victim is directed to download remote access software, which gives the criminal direct control over the device. The criminal then transfers funds from banking apps, collects stored passwords, or requests payment by wire transfer or gift card.
Posing as a technology company representative to deceive a victim into surrendering access or money may constitute criminal impersonation under New York Penal Law § 190.25 and a deceptive business practice under New York General Business Law (GBL) § 349.
Account Takeover through Social Engineering
Account takeover scams do not require physical or technical access to the device. The criminal calls or texts the victim while posing as a bank, carrier, or government agency and persuades the victim to read aloud a one-time verification code sent to the phone. With that code, the criminal resets the account password and takes control of the email, banking app, or social media account. The victim's phone is never directly accessed, but the result is the same as a SIM swap: the criminal holds authentication control.
New York Penal Law §§ 190.65 and 190.80 address identity theft in the second and first degree, covering situations where a criminal uses another person's personal identifying information to obtain money, property, or services.
Stalkerware and Spyware Installation
Stalkerware refers to applications installed on a victim's device without consent, typically by an intimate partner or family member with physical access to the phone. The application runs silently and transmits the victim's location, messages, calls, and browsing activity to the person who installed it. Unlike other hacked phone scams, the motivation is often surveillance and control rather than immediate financial theft.
New York Civil Rights Law § 52-b prohibits the dissemination of a person's intimate image without consent, and the conduct may also support claims under Penal Law § 120.45 (stalking in the fourth degree) when the surveillance causes the victim reasonable fear. If stalkerware is relevant to a domestic abuse situation, the Family Court Act provides additional protective options.
2. Federal and New York Laws That Cover Hacked Phone Scams
Federal and New York statutes address different aspects of a hacked phone scam, and more than one may apply to the same incident depending on the method used and the harm caused.
Federal Criminal Statutes
The Computer Fraud and Abuse Act (CFAA), 18 U.S.C. § 1030, prohibits unauthorized access to a protected computer, a category that includes smartphones and cloud-based accounts. A criminal who gains access to a victim's device or accounts without permission, or who exceeds authorized access to obtain financial information, commits a federal offense. CFAA violations carry sentences ranging from one year for basic unauthorized access to ten or more years for access that causes significant financial damage.
Federal wire fraud, 18 U.S.C. § 1343, applies when a hacked phone scam involves any use of electronic communications to execute a scheme to defraud. Most SIM swap attacks, tech support scams, and account takeovers satisfy this standard. Wire fraud carries a maximum sentence of 20 years in federal prison.
Federal identity theft, 18 U.S.C. § 1028, and aggravated identity theft, 18 U.S.C. § 1028A, apply when a criminal uses a victim's identifying information (including phone number, authentication codes, or account credentials) to commit fraud. Aggravated identity theft carries a mandatory minimum of two years in federal prison, consecutive to any other sentence.
New York Criminal Statutes
New York Penal Law §§ 156.05 through 156.35 cover computer trespass, computer tampering, and unlawful duplication of computer-related material. Computer trespass under § 156.10 is a Class E felony. Computer tampering under §§ 156.20 through 156.35 ranges from a Class A misdemeanor to a Class C felony depending on the damage caused and whether the defendant altered or destroyed data.
Penal Law § 155 covers larceny, including grand larceny in the first degree (§ 155.42) when the value of stolen property exceeds $1,000,000. A SIM swap that drains a bank account or cryptocurrency wallet may support grand larceny charges based on the amount stolen.
Penal Law §§ 190.77 through 190.82 cover identity theft in the third, second, and first degree. Identity theft in the first degree under § 190.80 is a Class D felony carrying up to seven years in state prison. The elements require proof that the defendant knowingly used a victim's personal identifying information to obtain money, property, or services.
3. Financial Recovery after a Hacked Phone Scam
Whether a victim can recover stolen funds depends on how the money was taken, which account held the funds, and how quickly the victim reported the loss to the financial institution.
When Efta Protects Bank Account Losses
The Electronic Fund Transfer Act (EFTA), 15 U.S.C. § 1693, and Regulation E govern unauthorized transfers from consumer bank accounts. A SIM swap that allows a criminal to initiate a transfer from the victim's bank account without the victim's authorization is an unauthorized electronic fund transfer under EFTA. The bank must reimburse the victim, subject to the reporting deadlines set by federal regulation.
The EFTA reporting timeline determines the consumer's maximum liability:
| When You Report to the Bank | Maximum Consumer Liability |
|---|---|
| Within 2 business days of learning of the loss | $50 |
| Between 3 and 60 days after the statement showing the transfer | $500 |
| After 60 days from the relevant statement | Full loss for transfers occurring after the 60-day period |
A tech support scam where the victim personally authorized the transfer, even under false pretenses, raises a more contested question under EFTA. The Consumer Financial Protection Bureau has taken the position that fraud-induced transfers may qualify as unauthorized under EFTA in cases involving impersonation. Whether a bank accepts that position or contests it depends on the specific facts. A bank that denies a valid EFTA dispute may be subject to a CFPB complaint, an NYDFS complaint for New York-supervised institutions, or a civil action in federal or state court.
Civil Claims against the Carrier
When a SIM swap succeeds because the wireless carrier failed to follow its own authentication procedures or the FCC's identity verification requirements under 47 C.F.R. § 64.6, the carrier may bear civil liability to the victim. A victim may bring a negligence claim or a GBL § 349 claim against the carrier when the carrier's failure was deceptive or materially unreasonable. GBL § 349 allows consumers to recover actual damages, a minimum of $50 in statutory damages, and attorney's fees when a business engages in deceptive acts or practices.
Civil Claims against the Scammer
A victim may also file a civil claim directly against the criminal for fraud, conversion, or unjust enrichment under New York common law. Unjust enrichment claims permit recovery of funds the defendant obtained without legal justification. The practical barrier is identifying and locating the scammer, particularly when the fraud was conducted through anonymous accounts or from outside the United States.
When the criminal used an intermediary to move stolen funds, that person may have acted as a money mule, knowingly or unknowingly relaying proceeds on behalf of the primary scammer. If the money mule's account can be identified through bank records, that individual may be subject to civil liability even when the principal scammer cannot be located. Compensation for losses in hacked phone scam cases may include the stolen amounts, consequential financial damages, and damages for harm to credit and financial standing where the legal standard is satisfied.
4. Criminal Reporting and Civil Remedies
Reporting a hacked phone scam to the correct agencies creates an official record, may trigger regulatory enforcement, and supports any subsequent civil action.
Where to File Criminal Reports
Victims should report to multiple agencies simultaneously rather than waiting for one to act:
- FBI Internet Crime Complaint Center (IC3) at ic3.gov handles federal computer and wire fraud referrals.
- Federal Trade Commission (FTC) at ReportFraud.ftc.gov builds a national database that supports broader enforcement investigations.
- FCC Consumer Complaint Center at consumercomplaints.fcc.gov for SIM swap fraud involving a carrier's failure to follow identity verification rules.
- Local law enforcement and the district attorney's office for state computer crime, identity theft, and larceny charges under New York Penal Law.
- New York Department of Financial Services (NYDFS) at dfs.ny.gov for bank-related losses involving a supervised institution.
Filing reports across agencies increases the likelihood that investigators will connect the scam to a broader pattern involving other victims.
Orders of Protection and Injunctive Relief
When the hacked phone scam involves a known individual, such as a former partner who installed stalkerware or a person identifiable through carrier records or transaction data, a victim may seek an order of protection through Family Court (Family Court Act Article 8 for qualifying relationships) or a civil injunction in Supreme Court under CPLR Article 63. An order of protection prohibits the defendant from contacting the victim through any medium, including by phone. Violating an order of protection is a separate criminal offense under Penal Law § 215.50.
When the harm involves ongoing invasion of privacy through stalkerware or the dissemination of private information obtained through phone access, a civil claim under New York common law may support both injunctive relief and damages.
Filing Deadlines for Civil Claims
New York imposes strict deadlines on civil claims arising from a hacked phone scam. An EFTA claim against a bank must be filed within one year of the violation. A civil claim for fraud under state law is generally subject to a six-year limitations period under CPLR § 213(8), measured from the date the fraud was committed. When the fraud was concealed and could not have been discovered with reasonable diligence, the statute of limitations may begin running from the date of discovery rather than the date of the act. Identifying the shortest applicable deadline early in the recovery process preserves all available options.
5. Steps to Take Immediately after a Hacked Phone Scam
Each hour of delay allows the scammer more time to move stolen funds beyond recovery. Take these steps as soon as you identify the scam:
- Contact your carrier immediately and report the unauthorized SIM change; ask the carrier to reverse it and add a port freeze or SIM lock to prevent further transfers.
- Notify your bank and dispute any unauthorized transfers, specifying the date, amount, and basis for the dispute under EFTA; ask the bank to freeze affected accounts.
- Change all passwords and revoke app permissions for email, financial accounts, and cloud storage using a separate, uncompromised device.
- Preserve all evidence including call logs, texts, pop-ups, remote access notifications, carrier confirmation emails, and account change alerts, without deleting anything before reporting.
- File reports with the IC3, FTC, and FCC to create official records with federal agencies.
- File an NYDFS complaint at dfs.ny.gov if your bank or carrier is supervised in New York, and document the reference number for follow-up.
A thorough evidence preservation approach at the outset supports every subsequent step, from regulatory complaints to civil litigation.
6. Frequently Asked Questions
Hacked phone scam victims frequently face overlapping questions about carrier liability, bank reimbursement, and what evidence actually supports a legal claim. The answers below address the most common issues that arise under New York and federal law.
Can I Hold My Wireless Carrier Responsible for a Sim Swap Scam?
Yes, in certain circumstances. If the carrier approved a SIM transfer without following the FCC's identity verification requirements under 47 C.F.R. § 64.6, or failed to notify you before completing the change, the carrier may be liable in negligence or under GBL § 349 for deceptive or unreasonable conduct. Whether liability attaches depends on whether the carrier followed its own security procedures and whether that failure caused your loss.
Will My Bank Reimburse Me for Money Stolen through a Sim Swap?
If a criminal used your phone number to bypass two-factor authentication and initiate a bank transfer without your authorization, EFTA requires the bank to reimburse you for that unauthorized transfer, provided you report the loss within the applicable deadlines. You must report within two business days of discovering the loss to limit liability to $50. A bank that denies a valid EFTA claim may be subject to a civil lawsuit, a CFPB complaint, or an NYDFS complaint.
Is Giving a Scammer Remote Access to My Phone a Crime on My Part?
No. A victim who grants remote access under false pretenses (believing they are speaking with Apple Support or their bank) has not committed a crime. The criminal who deceived the victim into granting access committed unauthorized computer access under the CFAA and potentially criminal impersonation under Penal Law § 190.25. Victims are not liable for losses caused by the scammer's fraudulent instructions.
What Evidence Do I Need to Support a Legal Claim after a Hacked Phone Scam?
The most useful evidence includes carrier records showing when the SIM change occurred and who requested it, bank records documenting the unauthorized transfers, call logs and texts from the scammer, screenshots of any pop-ups or remote access requests, and account change alerts received without your knowledge. A police report number and reference numbers from regulatory complaints strengthen both civil and criminal filings.
How Long Do I Have to File a Legal Claim for a Hacked Phone Scam in New York?
An EFTA claim against a bank must be filed within one year of the violation. Civil fraud claims are generally subject to a six-year period under CPLR § 213(8). When the scammer concealed their conduct and the victim could not reasonably have discovered the loss earlier, courts may apply a discovery rule, starting the clock from the date the victim knew or should have known of the fraud. The deadline analysis should be completed early to avoid losing available options.
Can I Recover Funds Sent in Gift Cards or Wire Transfers to a Tech Support Scammer?
Recovery is difficult but not always impossible. Gift card transactions are generally irreversible, and wire transfers sent to overseas accounts are rarely recovered through the banking system alone. If the tech support scam was operated by an identifiable business entity in the United States, a GBL § 349 claim or a small business fraud action may provide a civil recovery path. Reporting to the FTC also matters because the FTC has authority to seek disgorgement from domestic tech support scam operations identified through accumulated complaint data.
12 Jan, 2026

