At a meeting of the Consumer Credit Market Association (CCMA) held on August 19, participants identified fraud prevention and identity verification during SIM card reissuance as a new practical area of focus for the Association.
“Every day, the lending market faces situations where a customer loses access to financial services not because of their own negligence, but due to a technical loophole in the number reissuance process,” noted Association Council Chairman Oleksandr Kholod.
This refers to the risk of a number—which was previously linked to BankID, a credit bureau, a personal account, or another customer identification tool—being resold or reissued. A working group has been formed to address this issue; it has been tasked with collecting practical case studies from market participants and preparing a statement to mobile network operators.
SIM Swap as a Threat to BankID: The Scale of the Problem
The financial phone number is a key element of the NBU’s BankID system: access to banking services is protected by two-factor authentication, and without control over this number, attackers cannot use someone else’s BankID even if they know the password.
At the same time, a significant portion of SIM cards in Ukraine remain prepaid and effectively anonymous, which makes it difficult to monitor changes in the number’s ownership. According to the National Bank of Ukraine, losses from payment card fraud rose by 24% in 2025, reaching 1.4 billion UAH, and SIM swapping—the hijacking of a number through the reissuance of a SIM card—is one of the key schemes used by attackers.












