SIM Swapping: How Attackers Steal Your Phone Number
Picture the moment it starts. Your phone, sitting on the desk where it always sits, quietly stops working. No bars. Maybe “emergency calls only.” You assume it’s the network. It isn’t. Somewhere, a stranger just convinced your wireless carrier that they’re you, and your phone number now lives on a SIM card in their hand.
That’s a SIM swap. A SIM, the small chip that ties your phone to your number, gets “swapped” so your calls and texts route to the attacker instead of you. Here’s the part the breathless coverage skips: it usually isn’t a feat of hacking. It’s a phone call to customer service. I spent years on the inside watching this industry build account-recovery flows around phone numbers because a number was convenient and almost everyone had one. That convenience is the whole vulnerability.
The good news, and there is good news, is that SIM swapping is one of the more preventable attacks out there once you understand it. There are exactly two places to stop it, and both are within your control.
What a SIM Swap Actually Is
A SIM swap happens when an attacker talks your wireless provider into moving your number from your SIM to a SIM they control. A close cousin, port-out fraud, moves your number to a brand-new account the attacker opens at a different carrier. The mechanics differ slightly. The result is identical. Every call and text meant for you goes to them.
On its own, that sounds like a nuisance more than a catastrophe. The danger is what your number unlocks. So many accounts treat your phone as proof of identity that the number becomes a skeleton key. The FBI describes this as a two-stage crime. First the attacker takes over the number. Then they fire off “forgot password” and “account recovery” requests at your bank, your email, your social accounts, and wait for the one-time codes to arrive by text, on their phone now, not yours. They reset the passwords and walk in.
That’s why the number matters more than people assume. It’s rarely the prize. It’s the bridge to the prize.
How Attackers Talk a Carrier Into It
The mechanics are more mundane than the headlines suggest, and understanding the boring version is what makes you harder to hit. The FBI says criminals run these schemes three ways: social engineering, insider threat, or phishing. Social engineering just means manipulating a person instead of breaking a system. In the most common version, the attacker calls your carrier, pretends to be you, and answers the verification questions well enough that an employee moves your number. In other cases they bribe a carrier employee outright, or phish their way into the internal tools that perform swaps.
Where do they get the answers to your security questions? Usually from places you’d never think to guard. Data breaches spill names, addresses, and account details by the millions. Phishing harvests more, and a surprising amount sits in plain view online. They arrive at the call with just enough about you to sound real.
The research here is unusually clear, and it’s worth knowing. Princeton researchers tested how five major prepaid carriers verified customers and found every one of them used challenges that could be defeated. An attacker only had to beat the weakest one. Some of the information used to verify identity could even be manipulated by the attacker beforehand. Recent call records were one example. Bait a target into placing or answering a call, and that call later shows up as the “proof” the carrier asks for. The lead researcher made a point I’d underline twice: this doesn’t take a sophisticated operation. An ordinary criminal can do it.
So when you read that someone got “hacked,” reset your mental picture. No one breached a telecom’s core network. Someone exploited a customer-service script that was designed for a customer who locked themselves out, not for a world where your phone number guards your bank.
Why SMS Recovery and SMS Two-Factor Are Weaker Than They Look
This is the part that changes how you should set up your accounts.
Two-factor authentication, or 2FA, adds a second step beyond your password so a stolen password alone isn’t enough. The most common second step is a code texted to your phone over SMS. It’s better than a password by itself. It’s also the weakest of the mainstream options, for a simple reason: it depends on control of your phone number, and you just saw how that control can be taken.
The federal government’s own identity guidance says as much. NIST, which sets the standards, treats phone-based codes as a restricted method and notes they aren’t phishing-resistant, because a convincing fake login page can capture a typed code in real time. The practical ranking is steady across sources. Hardware security keys, small physical devices you tap or plug in, sit at the top. Authenticator apps, which generate codes right on your device, are the strong everyday default. SMS sits at the bottom of the three, useful but vulnerable.
There’s a subtle failure mode that trips up even careful people. A service can offer a strong login and still be weak if its recovery path runs through SMS. Princeton found 17 websites where a single SIM swap could open the account, because those sites allowed text messages both for two-factor login and for password resets. Move your login off SMS and you’ve helped yourself. You haven’t finished the job if “forgot password” still texts a code to a number an attacker can steal.
The mistake even careful people make
Switching your login off text messages is only half the job. If your password reset still sends a code to your number, a SIM swap can undo everything. Check the recovery settings too, not just the login settings.
Authenticator apps have one more edge. They keep working when your cell service goes dark, which is exactly when a SIM swap is unfolding. An app generates codes with no signal at all. The text-message approach fails right when you need it most.
The Warning Sign Most People Miss
The clearest early signal is the one that’s easiest to dismiss. Your phone suddenly loses service for no reason. The FCC says this is often the first sign, with the device going dark or dropping to emergency-only calls. If everyone around you still has bars and there’s no area outage, don’t shrug it off as a glitch. Treat it as a flag.
Other tells tend to arrive together:
- Getting locked out of accounts you could log into yesterday
- Alerts from your bank, email, or a social platform about a login or settings change you didn’t make
- Your usual 2FA codes simply never showing up
If you suspect a swap is happening, speed matters and the order matters. Contact your wireless carrier immediately, using another phone or a wifi call, since your own line may be dead. Get the number back under your control. Then secure your accounts, starting with the email address that can reset everything else, then your financial accounts. Then report it. The FBI’s sequence is the same: reach the carrier, change passwords, alert your financial institutions, and file a report with law enforcement and the FBI’s complaint center at IC3.gov.
Two rules from the FTC are worth burning into memory while you’re at it. Never trust contact details the caller gives you. Look up your bank or carrier yourself, from a statement or an app you already have. And anyone who asks you to read back a verification code is a scammer, full stop. A real institution never needs your code. The person asking for it is trying to walk into your account with it.
The Defenses That Actually Work
Remember those two places to stop a SIM swap. Here they are.
Lock Down the Carrier Account
The first defense hardens the exact spot where the attack begins. Set a PIN or passcode on your wireless account, separate from anything else, so no change goes through without it. The FTC recommends this directly. Beyond the basic PIN, ask your carrier for a number lock or port-out protection, sometimes called a number transfer PIN, which blocks your number from being moved to another device or carrier without an extra check.
That layer got stronger recently. Under FCC rules that took effect in 2024, wireless providers must offer every customer a free account lock that blocks SIM changes and port-outs, and must notify you when either is requested. Turn it on.
A carrier PIN isn’t a magic shield. It only helps if the provider enforces it every time, and enforcement has been uneven. But it’s one of the few defenses that directly guards the point of failure, so it’s worth the ten minutes. One caution: don’t pick a PIN someone could guess. Skip your birthday and the last four of your Social Security number. Use something random and store it in a password manager.
Move Important Accounts Off SMS
The highest-value move is shifting your important accounts away from text-message codes for both login and recovery. The FBI recommends stronger methods: biometrics, physical security tokens, or standalone authenticator apps.
For most people, an authenticator app is the right balance of strength and simplicity. It’s meaningfully harder to defeat than SMS. For your highest-value accounts, your primary email, your brokerage, anything holding crypto, or an admin account you use to log into other systems, a hardware security key is the stronger choice, because it’s built to resist phishing and doesn’t lean on the phone network at all.
Start where the leverage is. Your primary email goes first, because it can reset almost everything else. Then financial accounts, cloud storage, social media, and your password manager. While you’re tightening logins, shrink the raw material attackers use to impersonate you. The FBI advises against posting your phone number or broadcasting financial details on public social media. The less an attacker can find, the weaker their phone call to your carrier sounds.
How to Move Accounts Off SMS Without Locking Yourself Out
This is the step that scares people off, and the fear is reasonable. Nobody wants to swap in a stronger lock and then get shut out of their own bank. The trick is to treat it as a staged change, not a single toggle.
While you’re still signed in on a device you trust, add the stronger method before you remove SMS. For most accounts that means turning on an authenticator app. For your highest-value ones, it might mean registering a security key. Get the new method working first.
Then add a backup that doesn’t depend on your phone number. A second security key is ideal for critical accounts. Backup codes, the one-time strings a service lets you generate and save, work as a fallback too. Login.gov, the government’s own sign-in service, advises keeping at least two methods on every account so losing one doesn’t lock you out. Treat backup codes as break-glass recovery, not your main defense, and store them somewhere a thief or a phishing message can’t reach.
Only once the stronger method and the backup are both in place should you remove SMS from sign-in. Then check your recovery settings separately and strip SMS out of password reset and account recovery there too. That second step is the one people skip, and it’s the one Princeton’s research shows can quietly undo everything you just did.
Keep the carrier protections on regardless. Even after your critical accounts are off text messages, a carrier PIN, a port-out lock, and that FCC-required account lock are still worth having, because your number can still be used for fraud or to attack some account you forgot to update. And if a site offers nothing but SMS, using it still beats a password alone. Just treat it as a temporary compromise, not a finished job.
The Honest Bottom Line
SIM swapping works because too many systems still accept your phone number as proof that you’re you. The attack almost always begins with ordinary social engineering against a carrier, not exotic telecom wizardry, and it only turns dangerous because text messages are still wired into so many password resets and login steps. Strip the mystery away and the fix is clear. The defenses come in pairs: harden the carrier account with a PIN and an account lock, and move both your login and your recovery off SMS. Authenticator apps are the right default for most people. Hardware keys are strongest for the accounts you can’t afford to lose.
If you want the deeper version of the second half of that fix, my breakdown of which kind of two-factor authentication actually protects you goes method by method. And if you’re reading this because something already went wrong, start with getting back into a hacked email account or recovering a hacked social media account, then come back and close the door behind you.
You don’t need to be frightened of this one. You need to know where it starts and put a lock on both ends.
Tom Reardon spent over 20 years in product and operations at major identity protection providers. He writes at MyScamGuide.com to give consumers the honest picture the industry’s marketing never did.
Recommended resources:
- IC3.gov: the FBI’s Internet Crime Complaint Center, where you report a SIM swap or online fraud
- FTC: What’s a verification code: the never-share-your-code rule, explained
- FCC SIM swap and port-out rules: the free account-lock protections your carrier now has to offer