SIM swap warning signs and how to detect an attack in progress
The first sign is often the most disorienting. Your phone shows "No Service" or "SOS Only" in the status bar. You try to restart the device. Nothing changes. This is not a network outage. This is the moment your phone number has likely been taken.
A SIM swap attack does not announce itself politely. It creates a vacuum first: you lose cellular connectivity because the carrier has moved your number to a new SIM card that someone else holds. Your phone becomes a disconnected brick for voice, text and mobile data. You cannot call out, you cannot receive calls, SMS messages stop arriving. This silence is the attacker's opening.
Within minutes, if you still have Wi-Fi, a second wave hits. Password reset emails begin pouring into your inbox, and every service you use might be targeted at once. The attacker is racing through your accounts, triggering resets and intercepting the SMS verification codes that your carrier now sends to their device. The emails look legitimate because they are legitimate requests - just not initiated by you. You will see resets for email accounts first, then banking, then cryptocurrency exchange accounts, then social media. The sequence depends on what the attacker has learned about you from data breaches or social engineering. Each reset email is an alarm bell. Each one you cannot stop because your phone number no longer belongs to you.
The next sign is account lockout messages. You try to log into your email; it says the password was changed five minutes ago. You try your bank; the security questions have been reset. You try your crypto wallet; the 2FA method has been switched from authenticator app to SMS - or removed entirely. The attacker is moving faster than you can react without a working phone. Some victims report seeing strange devices logged into their accounts. Google sends an alert about a new sign-in from an unfamiliar phone in a different city. Facebook flags a login from a browser you have never used. These notifications are the attacker testing access while you still have some visibility.
Financial alerts follow. A withdrawal confirmation from your exchange account. A transfer of cryptocurrency you did not authorize. A new beneficiary added to your bank account. These are the final signs before irreversible loss occurs; by this point the attacker has probably drained any accessible funds. You may also notice that calls to your own number go straight to voicemail. Friends and family tell you they called but you did not answer. The voicemail greeting might change if the attacker set up a new voicemail box on the swapped SIM. Check your voicemail settings if you can still access them over Wi-Fi.
The entire attack sequence from first "No Service" to account takeover can take under ten minutes. Attackers run automated scripts. They have lists of your accounts and known passwords from prior breaches. They know exactly which services use SMS 2FA and which do not.
Your first five minutes: an action checklist
You cannot wait. Every second the attacker keeps control of your number costs you money and access. Do these things in order.
Minute one: Confirm it is a swap, not an outage. Try to call your own number from another phone. If it rings, but your phone shows no signal, your SIM has been swapped. A genuine network outage would not let calls reach your number while your device remained dead. Also check your carrier's outage page or social media. If there is no reported outage, assume compromise.
Minute two: Call your carrier immediately. Use a friend's phone or a landline. Do not use email or chat - those are too slow. Tell them "My phone number has been SIM swapped without my authorization. Freeze my account immediately. Block all SIM changes and port-out requests." Insist on speaking to the fraud department. If the first agent hesitates, ask for a supervisor. Do not hang up until you get a case number and confirmation that the old SIM is deactivated.
Minute three: Lock your financial accounts. Log into your bank, credit cards, and any crypto exchange from a computer or a tablet. Change passwords to strong fresh ones. Enable hardware-based 2FA if available - do not use SMS. Freeze your credit with all three bureaus if you have access. Transfer any remaining cryptocurrency to a new wallet that uses a hardware device or passkey, never SMS.
Minute four: Secure your primary email. Your email is the master key. If the attacker has not taken it yet, change its password immediately. Remove any recovery phone numbers that point to your compromised SIM. Add a hardware security key or authenticator app as 2FA. Check email forwarding rules - attackers often set up auto-forwarding to monitor your inbox.
Minute five: Warn your contacts and monitor. Use messaging apps or social media to tell close contacts you have been SIM swapped. Scammers often use the stolen number to impersonate you and ask friends for money. Then start documenting everything. Save the password reset emails. Record the exact time your service dropped. Note every account you find compromised. This documentation will be essential for police reports and carrier complaints.
After the first five minutes, contact your carrier again to request a new SIM in person at a retail store with government ID. Do not accept a mailed SIM - it gives the attacker more time. Report the incident to the FTC or your local cybercrime unit. Begin the long process of recovering each account.
The window to act is narrow. The first sign is the only warning you will get before the damage begins. Treat "No Service" as an emergency, not an inconvenience.
Not financial advice. rosiesol.xyz publishes market data and general information about Rosie. Crypto assets are volatile and you can lose everything you put in. Nothing here is a recommendation to buy, sell or hold, and we make no price predictions.
Prices are sourced from third parties and may be delayed or wrong. Verify anything you intend to act on against a primary source.