A SIM swap, also known as SIM hijacking, is one of the fastest-growing and most damaging types of fraud in the mobile security world. In a SIM swap attack, a criminal convinces your mobile carrier that they are you and requests that your phone number be transferred to a new SIM card in their possession. Once the swap goes through, all of your calls and texts — including two-factor authentication codes — route to the attacker's phone instead of yours.
The consequences can be devastating. With access to your phone number, attackers can reset passwords for your email, bank accounts, cryptocurrency wallets, and social media profiles. They bypass the very security feature — SMS-based two-factor authentication — that you thought was protecting you. Victims regularly report drained bank accounts, emptied crypto wallets, and hijacked identities.
How Attackers Pull Off a SIM Swap
SIM swap attacks rely on social engineering more than technical hacking. The attacker typically gathers personal information about you before making the attack. This reconnaissance can come from data breaches, social media posts, phishing attempts, or even public records. The more details the attacker has — your full name, address, date of birth, the last four digits of your Social Security number — the more convincing they sound to customer service representatives.
Once armed with this information, the attacker contacts your mobile carrier pretending to be you. They might claim they've lost their phone, that it was stolen, or that they want to transfer their number to a new device. In some cases, carriers are fooled because the attacker's story is convincing and matches the accounts' stored information. In other cases, disgruntled or careless carrier employees assist the fraud, either knowingly or unknowingly.
If the carrier approves the request, your existing SIM card is deactivated, and a new SIM card with your phone number is provisioned into the attacker's device. The criminal then uses your phone number to receive the verification codes needed to break into your accounts, often beginning with email (the master key to everything else), then moving to financial services and crypto exchanges.
The Warning Signs You're Being Attacked
SIM swap attacks often leave telltale signs if you know what to look for. The most obvious is a sudden loss of cellular service. If your phone suddenly shows "No Service" or "SOS Only" despite having good coverage, and others around you have full signal, your SIM may have been deactivated by a swap. This is the single most common symptom, and it's your cue to act immediately.
Another sign is receiving login verification codes and password reset messages that you didn't request. If you're suddenly getting text messages about password resets for accounts you haven't touched, an attacker may be attempting to take over those accounts after gaining control of your number.
You might also notice that calls and texts stop coming through on your phone, or that you can't send text messages anymore. Some victims report that apps connected to their phone number stop working, or that they're logged out of accounts unexpectedly. If you suspect anything, contact your carrier immediately using a different phone or a landline — don't use your compromised number, and don't assume your account is safe.
Protecting Yourself from SIM Swaps
Your primary defense is adding a security PIN or passcode to your mobile carrier account. This is different from your phone's lock screen PIN. It's an extra authentication factor that carriers can require before making account changes like SIM swaps. Call your carrier and ask specifically about SIM swap protection — many carriers now offer this as a recommended security feature, and some require it by default.
Push for authentication methods that don't depend on SMS. This is the single most effective change you can make. For every account that supports it, switch your two-factor authentication from SMS codes to an authenticator app like Google Authenticator, Authy, or Duo. Those apps generate codes locally on your device using a shared secret, so they can't be intercepted by a SIM swap. For the accounts that matter most — banking, email, crypto — consider hardware security keys like YubiKey, which require physical possession of the key to authenticate.
Minimize how much personal information you expose. The less an attacker knows about you, the harder it is for them to impersonate you to a carrier. Review what you share on social media: your birthday, your mother's maiden name, your high school, your pet's name — these are all common security answers that attackers can use. Use a security freeze or PIN at your carrier, and never publish your phone number broadly online.
Use the extra protections offered by your services. Banks and crypto exchanges increasingly offer options like withdrawal whitelists (allowing transfers only to pre-approved addresses), transfer delays, and damaged-device verification. Enable every layer your service provides. If your carrier offers eSIM-based security features or the ability to block SIM changes entirely, use them.
What to Do If You're a Victim
Speed is critical. The moment you suspect a SIM swap, contact your carrier on another device immediately and report it. Ask for the new SIM to be deactivated and your number restored to your device. Then change the passwords and security settings on every critical account, starting with your email and banking. Also check for any transactions or transfers that were made during the attack window.
Contact your bank and financial institutions to flag potentially unauthorized activity. File a report with your country's relevant agencies. In the US, the FBI's Internet Crime Complaint Center (IC3) accepts reports about SIM swap fraud. If cryptocurrency was stolen, report it to the exchange involved and the appropriate regulatory body. Consider placing a fraud alert or credit freeze. And learn from the experience: a victim of SIM swap often becomes a lifelong advocate for authenticator apps and carrier PINs.
If your phone itself was also lost or stolen during the incident, or if you suspect an attacker gained access to your device before the swap, consider protecting your data with a remote wipe. Tools like CleanSlate let you erase your Android device remotely, ensuring that sensitive data on the phone never falls into the attacker's hands. If you're still using SMS for account security, see our guide to authentication limitations to understand why switching to authenticator apps matters.
The Bigger Picture
SIM swaps are a reminder that SMS-based security has serious vulnerabilities. The convenience of having verification codes sent to your phone must be weighed against the reality that your phone number can be taken over by someone who isn't you. For high-value accounts, authenticator apps and hardware keys are simply safer than SMS, and the effort to switch is small compared to the potential cost of a successful attack.