SIM Swap Attacks: How a Phone Number Gets Stolen
Your phone number is not something you own. It is an entry in your carrier's database, and it can be moved to someone else's device by a member of staff in under a minute. Everything that treats that number as proof of who you are, and a great deal does, moves with it.
What a SIM swap is
The attacker persuades your mobile operator to reassign your number to a SIM or eSIM profile they control. From that moment, calls and texts to your number reach them, and your handset drops off the network.
What follows takes minutes, because the industry spent a decade building password recovery on top of SMS. Reset links and one-time codes arrive at the attacker's device. Email goes first, because email resets everything else; then banking, then exchanges, then whatever else is worth taking. Victims routinely describe watching notification after notification arrive on a phone that can no longer receive them.
How it is actually done
- Social engineering of support staff. The most common route. The attacker calls or walks into a shop with your name, address, date of birth and often the last digits of a card, all of which can be bought from a people-search site, and reports a lost phone. The agent is measured on resolving calls quickly and does so.
- Insider access. Documented repeatedly in prosecutions: retail or call-centre staff paid per swap. This defeats every verification control, because the person performing the check is the attacker's accomplice.
- Port-out to another carrier. Rather than swapping the SIM at your operator, the number is ported to a new operator entirely, using account details the attacker has gathered.
- Taking over the carrier's own online account. If your carrier portal has a reused password and no second factor, the attacker can order a replacement SIM or move an eSIM profile without speaking to anyone.
- eSIM profile transfer. The newer variation. No physical card is posted, so the delay that used to give victims warning has gone.
The information used to pass verification was not stolen from you. Address history, date of birth, previous phone numbers and relatives' names are sold openly by people-search companies and sit in breach corpora by the hundred million. A carrier asking for them is not authenticating you; it is testing whether the caller has done ten minutes of research. This is the same data problem described in how data brokers work.
The symptoms, in order
- Service stops. No signal, no calls, no texts. Wifi keeps working, which is what makes people assume it is a network fault.
- Unexpected carrier messages just before it, a confirmation of a SIM change, a porting request, or a security code you did not request.
- A wave of password reset emails for accounts you did not ask to reset.
- Being signed out of apps on your other devices.
- Contacts receiving messages from your number.
The window between the first and third of these is often under ten minutes. Treating sudden unexplained loss of service as a possible attack rather than a fault is the single most useful habit here.
The first ten minutes
- Get to another connection. Wifi on the same handset still works; a friend's phone or a laptop will do.
- Call your carrier from another line and say the words "SIM swap" or "unauthorised port". Ask them to reverse it and freeze the account. Carriers have a process for this and it is faster than a general support queue.
- Secure email next, not your bank. Change the password over wifi, switch the second factor away from SMS, and revoke every active session.
- Then financial accounts. Call the bank's fraud line directly rather than relying on the app, and tell them your number was hijacked so they stop trusting SMS verification on your account.
- Work through the persistence checklist: forwarding rules, recovery addresses, connected apps, exactly as in the account compromise runbook. Anything the attacker reached in those minutes may have been altered.
- Report it. Your national fraud or cybercrime body, and get a reference number; you will likely need it for any dispute.
Preventing it
Two categories: making the swap harder, and making it matter less. The second is more reliable, because the first depends on other people's staff.
Harden the carrier account
- Set a port-out PIN, transfer PIN or number lock. Nearly every carrier offers one under a different name, almost nobody enables it, and it is the control that gives a support agent something to check. Regulators in several countries now require carriers to verify a customer before changing a SIM or porting a number, but the protection only engages if you have set the credential.
- Give the carrier portal a unique password and its own second factor. It is an account like any other, and it is usually forgotten.
- Ask for a note requiring in-person identification for SIM changes, where the carrier supports it.
Reduce what the number is worth
- Remove SMS as a second factor wherever an authenticator app or passkey is available, see the two-factor guide and passkeys.
- Remove SMS as a recovery route, which matters more. A number that cannot reset your email is worth far less than one that can, and an attacker will always take the weakest path available.
- Do not publish your number. Keep it off social profiles, domain records and public documents, and check the discoverability setting that lets people find your accounts by phone number.
- Use a separate number for services that insist on one: a voice-over-IP line that is not tied to a carrier account cannot be SIM-swapped, though it has its own weaknesses.
- Consider whether your bank offers app-based approval rather than SMS codes, and switch if it does.
If you hold cryptocurrency, treat this as the primary threat. SIM swapping exists at scale largely because irreversible transfers make it profitable, and the reported losses run to substantial sums per victim. Exchange accounts should never have SMS enabled in any capacity, and holdings of consequence belong in hardware wallets where a phone number is irrelevant to control of the funds.
Why this keeps working
The phone number was never designed to be an identity credential. It is a routing address, assigned by a commercial entity, transferable by customer service, and shared with every company that ever asked you for a contact detail. Using it as proof of identity was a convenience decision made when the alternative was worse, and it has outlived its justification.
It persists because it is easy: services get a cheap verification channel, and users get something familiar. But the security of a bank account should not rest on how a retail assistant handles a stranger with a plausible story, and until services stop accepting SMS, the practical defence is to remove it from your own accounts one at a time.
See where your details are already exposed, which is what attackers use to pass a carrier's verification questions, with the MyRecon email check.
Questions people ask
What is the first sign of a SIM swap?
Your phone loses mobile service and will not recover, no calls, no texts, often an "emergency calls only" or "no SIM" indicator, while wifi still works. If that happens without explanation and is quickly followed by password reset emails, treat it as an attack in progress rather than a network fault.
Can a SIM swap happen if I use an eSIM?
Yes. An eSIM removes the physical card but not the underlying process: the number is still an account with a carrier, and transferring the profile to a new device is a support operation an attacker can target in the same way.
Does a port-out PIN actually stop it?
It stops the common version. Most successful swaps come from a support agent being socially engineered, and a PIN or port freeze gives that agent something to check that the attacker does not have. It does not stop an insider with system access, which is why it is worth removing SMS from your important accounts as well.
Why do attackers want a phone number specifically?
Because so many services treat it as proof of identity. It receives one-time codes, it authorises password resets, it retrieves voicemail, and it is accepted as a verification factor by banks and platforms, so controlling it for even twenty minutes can be enough to take several accounts.