Privacy & Security 8 min readBy Mehadi ShawonPublished Updated

SIM Swap Fraud: How Hackers Hijack Your Phone Number (And How to Stop It)

SIM swap fraud lets an attacker move your phone number to their SIM and steal your SMS codes. Here is how SIM swapping works and how to protect your number.

Glowing SIM card being lifted out of a phone by a shadowy hand on a dark cyan circuit background, representing SIM swap fraud hijacking a phone number
Quick answer

SIM Swap Fraud: How Hackers Hijack Your Phone Number (And How to Stop It)

SIM swap fraud is when a criminal convinces or bribes your mobile carrier to move your phone number onto a SIM card they control. Your calls and texts — including SMS two-factor codes — then arrive on their phone. FBI Internet Crime Complaint Center data put reported SIM-swap losses at $72.6 million in 2022.

SIM swap fraud is theft of your phone number. Somebody contacts your mobile carrier, poses as you, and asks for your number to be moved to a new SIM card — and once that request succeeds, every call and text meant for you rings on their phone instead.

The reason attackers bother is simple: your phone number is still the recovery key for a huge share of online accounts. Reset a bank login, a webmail account or an exchange wallet and the code often arrives by text. Take the number, take the codes, take the accounts.

How SIM swapping actually works

A SIM swap is a social engineering attack against a call centre, not a hack against your handset. There is no malware involved and nothing to find on your phone afterwards, which is part of why victims are often confused about what happened.

  1. Reconnaissance: the attacker gathers your full name, mobile number, address, date of birth and often the last four digits of a card — usually from data-breach dumps, social media or a phishing page.
  2. Contact: they call, chat or walk into a store claiming to be you with a lost or damaged phone.
  3. Authentication bypass: they answer the knowledge questions with the harvested data, or in the worst cases they pay an insider at the carrier to push the change through.
  4. Cutover: the number is activated on their SIM or eSIM profile. Your device drops to 'No Service' because a number can only be live on one SIM at a time.
  5. Harvest: they trigger password resets on your email first, then work outwards through banking, crypto and social accounts using the SMS codes now landing on their device.

The whole sequence can finish in under an hour. Most of the damage happens while the victim is still trying to work out why their phone has no bars.

Phone number icon rerouting along a glowing blue path from one handset to another, illustrating how SIM swapping redirects calls and SMS codes

Why regulators treat SIM swap fraud as a carrier problem

Because the weak point is the carrier's identity check, the fix has partly been regulatory. On 15 November 2023 the US Federal Communications Commission adopted a Report and Order (FCC 23-95, WC Docket No. 21-341) requiring wireless providers to use secure customer authentication before transferring a number to a new SIM, and to notify customers whenever a SIM change or port-out request is made.

Loss data explains the urgency. Reported SIM-swap losses tracked by the FBI's Internet Crime Complaint Center reached $72.6 million in 2022 — and because SIM swapping is usually recorded as the method behind a fraud rather than the fraud itself, the true figure is widely believed to be higher.

Rules help, but they do not remove the risk. A determined attacker with a convincing story, or a bribed retail employee, still gets through. Which means the practical defence has to sit on your side of the counter.

The warning signs of a SIM swap attack

  • Your phone shows 'No Service', 'SOS only' or 'Emergency calls only' while other devices on the same network work fine.
  • You receive a carrier notification about a SIM change, eSIM transfer or port-out request that you did not start.
  • Password reset emails or login alerts arrive for accounts you were not touching.
  • Contacts say they received odd messages from your number.
  • Banking or exchange apps suddenly demand re-verification and then log you out.

Treat unexplained signal loss as an incident, not an inconvenience. Check whether the network is actually down in your area before assuming it is a coincidence — an outage affects everyone nearby, a SIM swap affects only you.

How to protect your phone number

Ranked roughly by how much risk each step removes:

  1. Set a carrier account PIN or passcode and, where offered, enable a number-transfer lock or port freeze in your carrier's app. This is the control that stops the swap itself.
  2. Move two-factor authentication off SMS. Authenticator apps generate codes on your device with no network delivery to intercept — see our comparison of authenticator apps versus SMS two-factor codes.
  3. Adopt passkeys or a hardware security key on your email and primary bank, since those cannot be replayed by someone holding your number.
  4. Remove your phone number as the recovery method wherever an app-based or backup-code option exists.
  5. Use unique, long passwords so a single breach does not hand over the knowledge answers an attacker needs — generate them with our password generator and stress-test your current ones with the password strength checker.
  6. Keep your date of birth, address and mobile number off public profiles; the reconnaissance step gets much harder without them.

If it has already happened

  1. Call your carrier from another phone and demand the number be restored and the fraudulent SIM deactivated.
  2. Regain control of your primary email account first — it is the master key to everything else.
  3. Change passwords on banking, payment and crypto accounts, and revoke active sessions.
  4. Tell your bank the compromise was a SIM swap so transactions can be flagged and disputed.
  5. File a report with your national fraud body (in the US, the FBI's IC3 at ic3.gov and the FTC at ReportFraud.ftc.gov) and keep the reference number.

SIM swapping versus the scams it is confused with

SIM swap fraud is often lumped in with unrelated threats, which leads people to buy the wrong protection. It is not a virus, so antivirus software does nothing for it. It is not an interception of the airwaves, so a VPN does not help either — although a VPN is still worthwhile for other reasons, as our guide to what a VPN actually does explains.

It is closer in spirit to phishing: both attack the human process around your account rather than the technology inside it. If you have ever handed details to a convincing fake login page, read what actually happens when you click a phishing link — those harvested details are exactly the raw material a SIM swap needs.

The reassuring part is that the defence is cheap. A carrier PIN takes two minutes to set, and moving your codes to an authenticator app takes an afternoon. After that, stealing your number stops being enough to steal your life.

What recovery looks like if it already happened

Speed decides how much a SIM swap costs you. The attacker's window is the period between your number going dark and you regaining control of it, and everything in that window is spent resetting passwords on accounts that trust SMS.

  1. Call your carrier from another phone and state that your number has been transferred without authorisation; ask for it to be restored and for the account to be locked.
  2. From a device you still control, change the password on your email account first, because it is the reset path for everything else.
  3. Revoke active sessions and check for forwarding rules or recovery addresses you did not add.
  4. Contact your bank and any exchange or payment account directly rather than waiting for a fraud alert.
  5. Replace SMS second factors with app-based or hardware ones as you go, so the same attack cannot be repeated.
  6. File a report with your national fraud body, which you will need for any dispute over losses.

Keep a written record of times, names and reference numbers from every call. Disputes over unauthorised transfers turn on the timeline, and reconstructing it from memory weeks later is far harder than noting it as you go.

Why carriers are now obliged to help

The FCC's 2023 order was written precisely because customers were being told their own carrier had done nothing wrong. Under it, carriers must authenticate customers securely before a SIM change or port-out and must notify the account holder when one is requested. If your provider cannot explain how the transfer was authorised, that is a documented failing rather than an argument you have to win from scratch.

Frequently Asked Questions

What is SIM swap fraud?+

SIM swap fraud is when a criminal persuades your mobile carrier to transfer your phone number to a SIM card they control, so your calls and text messages — including SMS two-factor codes — are delivered to their device instead of yours.

How do I know if my SIM has been swapped?+

The clearest sign is losing mobile service on your phone while other devices on the same network still work, especially alongside a carrier notification about a SIM change or port-out you did not request, or unexpected password reset emails.

Can a SIM swap happen without me doing anything wrong?+

Yes. The attack targets your carrier's identity check, not your phone. Data leaked in an unrelated breach can be enough for an attacker to answer the verification questions, and insider assistance at a retail store has been documented in prosecutions.

Does a VPN or antivirus protect against SIM swapping?+

No. There is no malware on your device to detect and no traffic to encrypt, because the swap happens inside the carrier's systems. A carrier account PIN, a number-transfer lock and app-based or passkey two-factor authentication are the controls that matter.

What should I do first if my number has been hijacked?+

Call your carrier from another phone to deactivate the fraudulent SIM and restore your number, then secure your primary email account before anything else, since email is the reset path for most other accounts. Report the fraud afterwards and keep the case reference.

Ad Space

Try the related free tools

Hands-on utilities from DigiMetrics Hub that go with this guide.

All tools