A law built for the counter, a crime that moved online
Germany's answer to anonymous SIM cards was, for two decades, a document check. Since July 1, 2017, §172 of the Telecommunications Act (TKG) — originally §111 — has required carriers to verify a customer's name, address and birthdate against a national ID card, passport or residence permit before any SIM is activated. The rule exists because a phone number tied to a real, checked identity is harder to use anonymously for fraud, harassment or terrorism financing, and it has done that job reasonably well at the point of sale.
What it was never built for is a customer who already has a valid, ID-verified contract logging into their own online account. That is the gap now being exploited. Investigators at the Landeskriminalamt (LKA) Niedersachsen, and reporting from Notebookcheck published September 2, 2026, describe a scheme that never touches a shop or a photo ID at all: attackers call posing as a courier, tell the victim a delivery needs a security code, and read back an SMS that actually came from the carrier — not DHL or Hermes. Once the victim repeats the code, the attacker is inside the carrier's web portal, where they self-order a replacement eSIM. It activates on the attacker's device within minutes, automatically killing the victim's own SIM. From there, LKA Niedersachsen has documented cases where the same access chain reached the victim's email and, in at least one case, wiped out a cryptocurrency holding — what investigators call a "total loss."
Steelmanning the identity-check instinct
The instinct behind Germany's ID-binding regime is defensible, and it would be wrong to wave it away. A phone number is now the de facto master key to a person's digital life — banking mTANs, email recovery, authenticator resets — so requiring a verified human behind every number is a legitimate, proportionate policy goal, not bureaucratic overreach. The 2017 mandate also made a real dent in the anonymous-burner-phone economy that German security services had specifically flagged as a terrorism-financing risk. None of that logic has expired.
The problem is that the control was built for a single choke point — the retail transaction — and telecom self-service has quietly opened a second, unguarded one. As the BfDI's 2023 notice on SIM-swapping and authentication already flagged, providers need "risk-appropriate" safeguards at every access point where an account can be changed — not just at the counter where a card is first issued. That warning went largely unheeded on the online-account side.
The asymmetry inside the carriers
What makes this a policy story, not just a scam story, is that the three major carriers handle the same risk inconsistently. Notebookcheck's carrier-by-carrier review found Telekom offers multi-factor authentication as an opt-in, Vodafone recommends but doesn't require backup codes, and O2 mandates a second factor — but defaults that second factor to an SMS sent to the very number under attack, with no authenticator-app alternative. A mandatory second factor that arrives on the compromised channel is not a second factor; it's theater. The BSI's own consumer guidance already tells consumers not to receive a code on the same device used to log in — a principle carriers apparently haven't applied to their own account-recovery flows.
Proportionate response, not a re-run of 2017
The fix here is not another identity-document mandate. It is closing the authentication gap the 2017 law never anticipated: carriers should default to app-based or hardware second factors for any account or SIM change, not SMS; eSIM re-issuance should trigger a cooling-off window or an out-of-band confirmation on the existing device before the old SIM dies; and number-portability rules — protected as a consumer right under TKG §59 since December 1, 2021 — should stay intact rather than being used as an excuse to relock numbers to carriers, which would punish legitimate switchers to catch a comparatively small number of fraud cases.
That scale point matters for calibration. As of a 2022 baseline reported by Heise, LKA Niedersachsen logged only low double-digit SIM-swap cases per year, and major carriers told the outlet the technique had "practically" stopped — right before the online-account variant emerged. The lesson isn't that the threat is huge; it's that a fraud vector can hollow out a working identity regime through a side door long before the case count justifies a headline. Regulators and carriers should fix the authentication mechanics now, at low cost and no burden on the 99.9% of customers who will never be targeted, rather than wait for volume to force a heavier-handed rule that recreates 2017's paperwork for a problem paperwork can't solve.