SIM swap and account takeover
Your phone number is no longer just a way to reach you. It is the key that opens your email, your bank accounts, your cryptocurrency exchange, and your social media. And it can be stolen without anyone taking your phone.
SIM swap - also called SIM hijacking or port-out fraud - is a method of account takeover in which an attacker convinces or coerces a mobile carrier into transferring your phone number to a SIM card they control. Once your number is on their device, every SMS message meant for you goes to them. Every password reset that uses SMS verification, every two-factor authentication code sent via text, every "is this you?" prompt that relies on your phone number - all of it lands in the attacker's hands.
This page covers the full landscape: how these attacks work, what tools and settings block them, what signs to watch for, and the decisions that determine whether you become a target or a hard target.
How SIM swaps actually happen
There is no single method. Attackers have multiple paths to the same result, and they choose based on what information they already have about you and which carrier you use.
The most common approach is social engineering of mobile carrier support agents. The attacker calls the carrier's customer service line, provides enough personal information to pass basic verification - name, address, date of birth, sometimes the last four digits of a Social Security number - and claims to have lost their phone or bought a new one. They request a SIM swap to a new SIM card they already have. If the agent processes the request without additional checks, the victim's phone goes dead and the attacker's lights up.
A more targeted version is SIM swapping via fake ID at a carrier store. The attacker visits a retail location in person, presents a forged driver's license or passport with the victim's name and the attacker's photo, and requests a replacement SIM. Retail employees under pressure to process customers quickly may not scrutinize the ID closely.
Port-out fraud using stolen personal information takes a slightly different route. Instead of a SIM swap within the same carrier, the attacker initiates a number port to a different carrier entirely. The porting system relies on account numbers and PINs that can often be found in data breaches or obtained through phishing. Once the port completes, the number belongs to a different carrier - and the original carrier cannot undo it.
Some attacks exploit SS7 protocol vulnerabilities, the signaling system that carriers use to route calls and texts. Attackers who gain access to SS7 networks can intercept SMS messages without touching the victim's carrier account at all. This method is rare and typically requires connections inside the telecom industry, but it exists.
Insider threat at mobile carrier retail locations is another vector. An employee with access to customer account systems performs the swap directly, often for payment arranged through dark web forums. Carrier employee account access sold on dark web forums makes this a recurring problem.
The newest and fastest-growing method involves eSIM profile download via compromised carrier account. Because eSIMs can be activated remotely, an attacker who gains access to your carrier account online can download a new eSIM profile to their device. The victim's existing eSIM is deactivated in the process. This method requires no physical SIM card, no store visit, and no social engineering of a support agent - just your carrier login credentials.
For a deeper look at the social engineering techniques attackers use on support agents, see How SIM swap social engineering tricks carrier support agents.
The warning signs: what to watch for
SIM swap attacks are not invisible. They leave traces, but those traces are easy to miss if you do not know what to look for.
The most obvious sign is "No service" or "SOS only" on device after number stolen. Your phone loses all cellular connectivity. Calls go straight to voicemail. Data stops working. This happens because the carrier deactivated your SIM when they activated the attacker's.
Other error messages include "SIM not provisioned" after swap completes, "Invalid SIM" error on original device during active swap, and "Your number has been transferred to another carrier" - a text that some carriers send when a port-out request is processed. If you see "Port-out request pending" notification from losing carrier, you may still have time to cancel it.
Attackers often flood your email with password reset requests to distract you from the SIM swap itself. "Password reset requested" email flood during takeover is a deliberate tactic. You receive dozens or hundreds of reset emails from services you use, burying any carrier notification about the swap. While you are sorting through the noise, the attacker is using your phone number to reset your actual passwords.
You might also see "Account recovery code sent to phone number ending in XXXX" - a prompt on a service you did not initiate - or "We noticed a new sign-in from an unrecognized device" security alerts arriving while you still have service but the attacker is already moving.
For a complete list of signs and what to do the moment you spot one, read SIM swap warning signs and how to detect an attack in progress.
What the attacker does with your number
Once the SIM swap succeeds, the attacker does not stop at owning your phone number. They use it to take over everything else.
The most dangerous target is your email account compromise as the gateway after a SIM swap attack. Email is the master key. Almost every online service allows password reset via email. If the attacker can reset your email password using SMS verification sent to their stolen number, they then control your email. From there, they can reset passwords for your bank, your cryptocurrency exchange, your social media, your domain registrar - any service that sends a reset link to that email.
Account takeover through password reset with intercepted SMS 2FA is the standard playbook. The attacker visits a service's login page, clicks "forgot password," and requests a reset code via SMS. That code goes to their phone, not yours. They enter it, set a new password, and are in.
Cryptocurrency exchange SIM swap risk and account protection is a specific and severe version of this problem. Exchanges typically require SMS verification for withdrawals or for changing security settings. With your number, an attacker can drain your balance in minutes. Cryptocurrency transactions are irreversible.
Bank account takeover through SIM swap intercepted SMS codes follows the same pattern. Many banks still rely on SMS codes for wire transfers, adding new payees, or changing account details. The attacker resets your online banking password via SMS, then initiates transfers to accounts they control.
WhatsApp Signal Telegram account hijack through SIM swap happens because these messaging apps use SMS verification as the primary method of proving you own the number. The attacker installs WhatsApp on their phone, enters your number, and enters the SMS code they just received. Your WhatsApp account is now theirs. They can message your contacts, read your chats, and impersonate you.
The ultimate danger is that the attacker locks victim out of their own phone number permanently by setting a new account PIN, enabling number lock features you cannot undo, or porting the number to a carrier you cannot reach.
The tools that stop SIM swaps
No single tool makes you immune, but the right combination makes you a target that most attackers will skip.
Hardware Security Keys
A hardware security key - such as a YubiKey or Google Titan Security Key - is the strongest defense available. These keys use the FIDO2/WebAuthn standard. They do not send a code over a network. They do not rely on your phone number. They cannot be phished. Even if an attacker has your phone number, your email password, and your date of birth, they cannot log into an account that requires a physical key you possess.
The Google Advanced Protection Program defense against SIM swap requires two hardware security keys for your Google account. Once enrolled, Google blocks nearly all account recovery methods that rely on SMS or backup codes. The only way to recover your account is with your physical keys. This is the single most effective measure a typical person can take.
For setup guidance across multiple accounts, see Hardware security key setup to prevent SIM swap account takeover.
Authenticator apps vs. security keys
Authenticator app vs hardware security key for stopping SIM swaps is a decision every security-conscious person needs to make. Authenticator apps generate time-based one-time passwords (TOTP) on your device. They are far more secure than SMS because the codes are generated locally and never transmitted. But they are not phishing-proof. An attacker can trick you into entering a TOTP code on a fake login page, then use that code immediately.
Hardware security keys solve this problem. The key uses cryptographic challenge-response instead of a shared secret. It cannot be tricked into revealing a code. For high-value accounts - email, cryptocurrency exchanges, domain registrars - the key is the better choice.
Carrier-Level Protections
Carrier Number Lock and port freeze to prevent SIM swap are features that some carriers offer. A Number Lock or port freeze prevents any SIM change or number port from being processed unless you disable the lock first, often through a separate PIN or biometric verification within the carrier's app. These features are typically free but not universal. They are not a complete defense - an attacker who gains access to your carrier account can disable them - but they add a barrier.
A carrier account takeover protection PIN is a separate PIN that must be provided before any account changes are made. This is better than relying on your date of birth or Social Security number, which are already in data breaches.
Remove phone number from recovery options
Remove phone number from account recovery options to stop SIM swap is a counterintuitive but effective step. If your phone number is not listed as a recovery method for your email or financial accounts, an attacker who steals your number cannot use it to reset those accounts. The trade-off is that you lose SMS as a recovery fallback. If you have hardware security keys and authenticator apps, you do not need SMS recovery.
Google Voice for SMS 2FA
Google Voice number for 2FA to protect against SIM swap is a partial solution. A Google Voice number cannot be SIM-swapped because it is not tied to a physical SIM. If you use a Google Voice number for SMS 2FA, an attacker cannot intercept those codes by stealing your carrier number. However, Google Voice itself can be compromised if the attacker gains access to your Google account. This is a defense layer, not a silver bullet.
Dedicated email for financial accounts
Dedicated email for financial accounts to limit SIM swap damage limits the blast radius. If your bank and exchange accounts use an email address that is not used for anything else - and that email is protected by a hardware security key - then compromising your primary email does not give the attacker access to your finances. This separation is simple and effective.
The decisions that determine your risk
Every choice you make about authentication, account recovery, and carrier settings either increases or decreases your exposure.
The most consequential decision is SMS-based 2FA versus authenticator app TOTP. SMS is the weakest form of two-factor authentication that is still widely accepted. It can be intercepted, redirected, and social-engineered. Switching to an authenticator app eliminates the entire class of attacks that depend on SMS interception.
Authenticator app versus hardware security key is the next decision. For most accounts, an authenticator app is sufficient. For your email account, your cryptocurrency exchange, and your domain registrar, a hardware security key is worth the setup effort.
Physical SIM versus eSIM for security is a newer consideration. eSIMs cannot be physically stolen, but they can be remotely reprogrammed if the attacker has your carrier login. eSIM is not immune to SIM swapping - the attack method simply changes.
Single carrier account PIN versus unique per-line PIN matters if you have multiple phone lines on one account. A single PIN means one compromise unlocks all lines. Per-line PINs limit the damage.
Cloud backup of TOTP seeds versus no backup is a trade-off between convenience and security. Services like Authy store your TOTP seeds in the cloud, which means you can recover them if you lose your phone. It also means an attacker who compromises your Authy account can regenerate your codes. Google Authenticator now offers cloud backup as well. If you use a single-device app like Aegis or Raivo OTP, you are responsible for backing up the seeds yourself.
Prepaid carrier versus postpaid carrier for SIM swap risk is not a clear-cut advantage. Prepaid accounts often have weaker identity verification, which makes social engineering easier. But some prepaid carriers offer strong port protections. The carrier matters more than the plan type.
Authy multi-device sync enabled versus disabled is a setting that many people do not know exists. With sync enabled, your TOTP codes are available on any device where you log into Authy. This is convenient. It also means an attacker who gets your Authy backup password can access your codes from their own device.
What does not protect you
Several common beliefs about SIM swap protection are wrong.
"I have a strong password so SIM swap can't affect me" - The attacker does not need your password. They reset it using your phone number.
"Two-factor authentication via SMS is secure enough" - It is not. SMS 2FA is the attack vector, not the defense.
"My carrier will protect me from SIM swapping" - Carriers have improved, but the attack still succeeds thousands of times per year. Carrier employees are the weakest link.
"eSIM is immune to SIM swapping" - It is not. The attack method changes from physical social engineering to account takeover, but the result is the same.
"SIM swaps only happen to cryptocurrency investors" - Cryptocurrency holders are high-value targets, but bank accounts, email accounts, and social media are also stolen via SIM swap.
"I would immediately notice a SIM swap in progress" - Many victims notice only when they try to use their phone and find it has no service. By then, the attacker has already reset passwords.
For a full list of misconceptions, see SIM swap myths and misconceptions that put accounts at risk.
Monitoring and Recovery
Even with the best defenses
Not financial advice. rosiesol.xyz publishes market data and general information about Rosie. Crypto assets are volatile and you can lose everything you put in. Nothing here is a recommendation to buy, sell or hold, and we make no price predictions.
Prices are sourced from third parties and may be delayed or wrong. Verify anything you intend to act on against a primary source.