The US Secret Service has uncovered and disrupted facilities operating SIM servers across the New York tristate area, which are devices capable of managing and coordinating up to 100,000 SIM cards simultaneously. These SIM servers have been identified as tools frequently leveraged by cybercriminals for a variety of illicit activities, including large-scale scamming operations. The Secret Service has raised concerns that, beyond their use in fraud, these devices could be weaponized to launch attacks against critical infrastructure, potentially disrupting mobile networks and communications. The discovery of these facilities highlights the growing sophistication and scale of cyber-enabled fraud operations in the United States. Law enforcement officials have warned that the presence of such high-capacity SIM management devices poses a significant risk to both consumers and businesses, as they can be used to automate and amplify phishing, smishing, and other social engineering attacks. The Secret Service's investigation into these operations is ongoing, with efforts focused on identifying the individuals and criminal groups responsible for deploying and operating the SIM servers. The takedown of these facilities is expected to have a disruptive effect on the cybercriminal ecosystem, at least temporarily reducing the volume of SIM-based scams in the region. Security experts have noted that the use of SIM farms is a growing trend among threat actors seeking to bypass traditional anti-fraud controls and scale their operations. The incident underscores the need for telecommunications providers to enhance monitoring and detection of anomalous SIM activity within their networks. In addition to fraud, the potential for these devices to be used in attacks targeting mobile infrastructure has prompted calls for increased collaboration between law enforcement, telecom operators, and cybersecurity professionals. The Secret Service has advised organizations to remain vigilant for signs of SIM-related fraud and to implement robust authentication measures to mitigate the risk of account takeovers. The exposure of these SIM server operations also raises questions about the adequacy of current regulatory and technical safeguards in preventing the abuse of telecommunications infrastructure. The incident has prompted renewed discussion about the balance between privacy, security, and the need for effective oversight of mobile network operations. As investigations continue, further details about the scale and impact of the disrupted operations are expected to emerge. The Secret Service's actions represent a significant step in combating the misuse of SIM technology for cybercrime and highlight the evolving tactics of threat actors in the digital age.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
A critical Cisco zero-day, CVE-2025-20352, was reported as under active exploitation and affecting as many as 2 million devices. The SNMP-related flaw could let attackers crash systems or obtain root access.
Attackers launched a broad campaign distributing Atomic macOS stealer malware through fake GitHub Pages sites. The operation targeted Mac users with infostealer delivery infrastructure designed to appear legitimate.
A phishing campaign targeted PyPI users in an effort to steal account credentials. The activity threatened software package maintainers and the broader Python package ecosystem.
A malicious npm package masquerading as Postmark MCP was found stealing users' email data. The package represented a software supply-chain threat aimed at developers and downstream users.
Reporting linked BRICKSTORM malware to Chinese threat actors targeting technology and legal organizations. The malware set included stealthy backdoors and credential stealers that could remain undetected for more than a year.
Microsoft identified a phishing campaign in which attackers used AI-generated code to obfuscate malware embedded in SVG files. The activity highlighted growing use of AI techniques in email-borne malware delivery.
UK law enforcement arrested a suspect in connection with a ransomware attack that caused disruption at European airports. No ransomware group had publicly claimed responsibility at the time of reporting.
Jaguar Land Rover suffered a major cyberattack that disrupted operations and halted production worldwide, causing financial and supply-chain impacts. Scattered Spider was suspected, though attribution was not presented as confirmed.
CISA disclosed that a U.S. federal agency was compromised through exploitation of GeoServer vulnerability CVE-2024-36401. The incident established active real-world abuse of the flaw against government infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.