Advertisement

Could AI answer your customers from your own documents?

Assistants trained on your files, website and FAQs.

The Rap Sheet

Ajay Shinjin: Jailed Over a £200,000 SIM-Swap Crypto Theft That Paid for Gold Grills and Dubai

Criminals hijacked four strangers' phone numbers and emptied their crypto. Ajay Shinjin spent his £44,000 on gold teeth and Dubai. He got 2.5 years.

Ajay Shinjin, and the gold grills police seized.

Key numbers

  • £195K ($265K)

    Stolen

  • £44K+

    His share

  • 4

    Victims

  • 2.5 years

    Sentence

On 2 November 2021 a person in Britain who kept about £40,000 in cryptocurrency lost all of it. Nothing had been hacked on their computer and nobody had stolen their password. What had been stolen was their phone number. Over the next five days three more people lost money the same way: £8,000, then £17,000, then about £130,000.

Nearly five years later, on 8 October 2026, a 25-year-old Londoner called Ajay Shinjin, who also goes by AJ Marley Cruz, was jailed for two and a half years at Inner London Crown Court for his part in those thefts. He had pleaded guilty on 28 September to conspiracy to commit fraud by false representation and to transferring criminal property, the legal term for moving money that came from a crime. City of London Police, the force that leads on fraud in England and Wales, announced the sentence the same day.

Across the four victims, almost £200,000 of crypto was taken, worth about $265,000. More than £44,000 of it landed with Shinjin, who lived on Marsh Wall in Canary Wharf, London's banking district. Police said he spent it on holidays in Dubai, a high-end flat in Canary Wharf and gold-plated grills: removable gold covers that clip over the teeth, a piece of jewellery borrowed from hip-hop.

Bar chart of four victims losses in November 2021: £130,000, £40,000, £17,000 and £8,000CMZ chart. Data: City of London Police, via Decrypt and Crypto Times
Four victims, almost £200,000 in four days.
Advertisement

Free AI assistant

AI that works, and proves it.

Ask Cynt how AI could help your business. Free to try.

Free AI assistant

What a SIM swap is

Every mobile phone has a SIM card, the small chip that tells the phone company which number belongs to which handset. In a SIM swap, a criminal gets the phone company to move a victim's number onto a SIM card the criminal controls. Usually that means tricking or bribing someone at the phone company, or abusing its systems. The victim's phone suddenly loses signal. The criminal's phone now rings and receives texts for that number.

That matters because of the one-time passcodes that banks and crypto firms send by text message. Many people protect their accounts with two-factor authentication: a password plus a second check, often a six-digit code texted to their phone. It is the online version of a bank asking for a card and a PIN. Once a criminal has the phone number, the second check comes to them. Many sites also let customers reset a forgotten password by text, so the number can unlock the first lock as well.

Crypto is the favourite target for one simple reason. A bank transfer can often be stopped or reversed. A crypto transfer cannot. Cryptocurrency is digital money that moves directly between accounts over the internet, with no bank in the middle that can freeze a payment. Once the coins leave a victim's account on an exchange (a broker for digital coins, much like a share-dealing app) and reach a wallet the thief controls, there is nobody to call to get them back.

How the BT case unravelled

The thefts were not uncovered by the victims. They were uncovered by the phone company. In early November 2021, BT, the British telecoms group, found what police called unauthorised activity on its systems: customer phone numbers were being moved to SIM cards controlled by criminals. The published accounts do not say how the criminals got that access, whether through a member of staff, stolen staff logins or something else.

BT then traced the phones that had received the stolen numbers. According to police, they were eSIM handsets with two IMEI numbers. An eSIM is a SIM card built into the phone as software rather than a plastic chip, so a new number can be loaded onto it remotely in minutes. An IMEI is the serial number of the handset itself, like the chassis number on a car. BT's records of those serial numbers led police to several suspects. Shinjin was linked to four of the devices.

The four victims all reported their losses in the first week of November 2021. Police set out what happened to each one:

Victim one lost about £40,000 of crypto on 2 November 2021. About £27,000 of it went into Shinjin's personal crypto account.

Victim two lost about £17,000 between 5 and 7 November. All of it was later found in Shinjin's personal crypto wallet.

Victim three had about £8,000 taken from an account at Coinbase, the largest US crypto exchange, on 3 November. Police said Shinjin facilitated the theft, but the money was sent elsewhere.

Victim four lost about £130,000 between 6 and 7 November. Police said Shinjin facilitated that theft too.

Those four amounts add up to about £195,000, the "almost £200,000" in the police statement. Shinjin's own takings, about £27,000 plus about £17,000, make the "more than £44,000". The rest went to other people. Police described it as a conspiracy and said BT's data pointed to several suspects, but the published accounts of the sentencing do not name anyone else or say whether others have been charged.

Arrested twice, said nothing

Shinjin was first arrested at his flat in 2021. He was not charged then. In October 2023 he flew back into Heathrow Airport from Dubai and was arrested again, after what police called further evidence had come to light. In interviews he answered "no comment" to every question. He was about 20 when the thefts happened.

Detective Constable Simon Ardeman of City of London Police called it "a complex and calculated fraud that caused significant financial harm to a number of victims." He added: "SIM-swap fraud is a sophisticated and increasingly concerning form of offending, and this case demonstrates the devastating consequences it can have for victims." The conviction, he said, "sends a clear message that those who use technology to commit fraud will be brought to justice."

The crime he was jailed for is no longer rare. Cifas, the UK fraud prevention body that runs the National Fraud Database, a shared register of fraud cases reported by banks, phone companies and other firms, said unauthorised SIM swap cases rose 1,055% in 2024. On 4 August 2026 it reported a further 402% rise in the first six months of 2026 compared with the same period of 2025, and said criminals were using SIM swaps to intercept security codes and get past account protections.

How ordinary people protect themselves

The lesson of the Shinjin case is that a phone number is not a safe key. It belongs to the phone company, and the phone company can be fooled. Security experts give the same short list of defences.

Put a lock on the phone account. Ask the mobile network to add a PIN, password or extra security check that must be given before anyone can move the number to a new SIM or to another network. Some networks offer account protection that sets stricter checks on any change. Mark Birchall, a cybersecurity editor at Norton, the antivirus maker, recommends both.

Stop using text messages as the second check. Where a bank or crypto exchange allows it, switch two-factor authentication to an authenticator app, such as Google Authenticator or Microsoft Authenticator. The app makes the codes on the phone itself, so a criminal who steals the number gets nothing. Birchall's point is that this ties access to a physical device rather than to a phone number.

For large sums, use a hardware security key. This is a small device, about the size of a car key fob, that plugs into a computer or taps against a phone to approve a login. Without the physical key, nobody can sign in, whatever happens to the phone number.

Remove the phone number as a way to reset passwords on crypto and banking accounts wherever the service allows it.

Do not keep a large balance on an exchange account that is protected only by text-message codes. An exchange is a broker. Money left there is only as safe as the weakest way into the account.

Treat sudden loss of signal as an alarm. If a phone shows "No service" or "SOS only" for no obvious reason, call the network from another phone at once and check the bank and exchange accounts. In this case the four victims lost their money within hours or days of losing their numbers.

The aftermath

Shinjin began his sentence in October 2026, almost five years after the thefts. Most prisoners in England serving a fixed sentence of this length are released on licence before the end of it and serve the rest under supervision in the community.

The published accounts of the sentencing do not mention a confiscation order, the process under the Proceeds of Crime Act by which a court can order a convicted criminal to pay back what they made from crime, or compensation for the four victims. Nor do they say whether any of the stolen crypto was recovered. The £17,000 found in Shinjin's own wallet is the only part of the money police have said they traced to a specific account under his control.

Police said BT's data identified several suspects. No other names have been made public in connection with the case. BT, which also owns the mobile network EE, has not publicly said how the criminals got access to its systems in 2021.

Since then, SIM swapping has grown from a niche crime into a common one in Britain, according to Cifas figures: a 1,055% rise in 2024 and another 402% in the first half of 2026.

What this teaches

  • A phone number is not a safe key. It belongs to the phone company, and a criminal who fools the phone company gets every security text sent to it.
  • Text-message codes are the weakest form of two-factor authentication. An authenticator app or a hardware security key cannot be stolen by moving a phone number.
  • Ask the mobile network for a PIN or extra security on any SIM change or number transfer.
  • Crypto transfers cannot be reversed. Money left on an exchange account protected only by SMS can be gone in minutes.
  • Sudden 'No service' on a phone is an emergency: call the network from another phone and check bank and crypto accounts at once.
  • The trail stays. Phone company records of handset serial numbers and crypto account records tied Shinjin to the thefts, even though conviction took almost five years.
Advertisement

Powered by Cyntri AI

The technology behind this newsroom. Built by Cyntri AI.

AI-assisted publishing, content pipelines and analytics. Crypto Media Zone is our working example.

Powered by Cyntri AI