SIM swapping is an identity-based attack in which a criminal transfers a victim’s mobile phone number to a SIM card or eSIM under the criminal’s control.
Once the transfer succeeds, calls and text messages intended for the victim may begin arriving on the attacker’s device. The victim’s phone may suddenly lose cellular service because their number is no longer associated with the original SIM.
Controlling the phone number can help an attacker intercept text-message verification codes, reset passwords, access financial accounts, impersonate the victim, or take over email and social-media profiles.
The attack does not necessarily involve physically stealing or replacing the SIM card inside the victim’s phone. In many incidents, the attacker persuades or manipulates a mobile carrier into activating the victim’s number on another device.
CISA defines SIM swapping as social engineering in which attackers convince a cellular provider to transfer control of a user’s phone number to a device controlled by the attacker. CISA’s phishing-resistant MFA guidance identifies SIM swapping as one reason organizations should move away from SMS-based authentication for high-value accounts.
How Does a SIM-Swapping Attack Work?
A typical SIM-swapping attack follows this pattern:
- The attacker identifies a valuable target.
- Personal information about the victim is collected.
- The attacker contacts the victim’s mobile carrier.
- They impersonate the victim and claim the phone or SIM was lost, damaged, or replaced.
- The attacker asks the carrier to activate the number on a new SIM or eSIM.
- If the request is approved, the victim’s original SIM loses service.
- Calls and SMS messages begin arriving on the attacker’s device.
- The attacker requests password resets or login verification codes.
- Online accounts are accessed or taken over.
- Passwords, recovery details, and authentication methods may be changed.
Not every incident follows this exact route. Attackers may also exploit compromised carrier accounts, corrupt insiders, stolen carrier credentials, vulnerable support systems, or fraudulent number-porting requests.
The defining feature is the unauthorized transfer of control over the victim’s telephone number.
What Information Do SIM Swappers Need?
Attackers may collect enough personal information to pass a carrier’s identity-verification process.
That information can come from:
- Social-media profiles
- Data breaches
- Phishing
- Public records
- Information-stealing malware
- Purchased identity data
- Previous account compromises
- Marketing databases
- Stolen mail
- Social-engineering calls
- Public professional profiles
Useful information may include:
- Full name
- Phone number
- Home address
- Date of birth
- Account number
- Email address
- Billing details
- Answers to security questions
- Recent transactions
- Carrier name
- Device information
- Government identification details
An attacker may know only part of this information initially. They can combine information from several sources or manipulate a customer-support representative into revealing clues.
Why Is SIM Swapping Dangerous?
A mobile phone number often acts as more than a communication address.
Services may use it for:
- Password resets
- Login verification
- SMS-based MFA
- Account-recovery calls
- Identity confirmation
- Transaction approval
- Security alerts
- Customer-support verification
When an attacker controls the number, they may receive the messages intended to prove the victim’s identity.
Possible consequences include:
- Email account takeover
- Bank-account access
- Cryptocurrency theft
- Social-media takeover
- Unauthorized password resets
- Financial fraud
- Identity theft
- Impersonation
- Exposure of private messages
- Loss of business accounts
- Removal of existing MFA
- Access to cloud services
- Fraudulent purchases
- New accounts opened in the victim’s name
The phone number alone may not be enough to access every account. Attackers frequently combine SIM swapping with stolen passwords, phishing, personal information, or account-recovery abuse.
What Is a SIM Card?
A subscriber identity module, or SIM, helps a mobile network associate a subscriber’s account and service with a device.
Traditional SIM cards are removable physical chips. An eSIM performs a similar function through a digital profile built into or downloaded to the device.
SIM swapping can affect both physical SIM cards and eSIM services. The attack targets the carrier’s process for transferring service, not merely the physical chip.
SIM Swapping vs. Port-Out Fraud
SIM swapping and port-out fraud both transfer control of a phone number, but they usually involve different processes.
In a SIM swap, the number is moved to another SIM or device while remaining with the same carrier.
In port-out fraud, the attacker transfers the victim’s number to an account at a different carrier.
The result for the victim can be similar: the original device loses service, while the attacker receives calls and messages.
The FCC describes port-out fraud as an attacker impersonating the victim, opening an account with another carrier, and arranging for the number to be transferred to that account. FCC guidance on port-out fraud recommends contacting the carrier, financial institutions, and other affected providers immediately when fraud is suspected.
SIM Swapping vs. Phone Cloning
SIM swapping transfers the phone number through a carrier or account process.
Phone or SIM cloning attempts to duplicate identifiers associated with a device or SIM.
The technical methods differ, although both may result in unauthorized use of mobile service or interception of communications.
Modern attacks described as “SIM swaps” more commonly rely on social engineering, account compromise, or fraudulent carrier requests rather than physically copying a SIM card.
SIM Swapping vs. Device Theft
Stealing a phone gives the attacker physical possession of the victim’s device.
SIM swapping does not require the attacker to touch the victim’s phone. The device may remain in the victim’s hand while cellular service suddenly disappears.
A stolen device can still create serious risk, particularly if it is unlocked or protected by a weak passcode. SIM swapping and device theft require overlapping but different defenses.
SIM Swapping vs. Phishing
Phishing attempts to trick a person into revealing information or visiting a deceptive website.
Attackers may use phishing to collect the information required for a SIM swap. They may impersonate the carrier, ask the victim to “verify” their account, or steal credentials for the carrier’s customer portal.
SIM swapping may then be used to intercept codes for other accounts.
SIM Swapping vs. MFA Fatigue
MFA fatigue attacks repeatedly send approval requests to a registered device, hoping the user accepts one.
SIM swapping redirects calls and SMS messages by transferring control of the telephone number.
Both attacks target authentication, but they affect different MFA methods:
- MFA fatigue primarily targets push-based approvals.
- SIM swapping primarily threatens phone-number-based verification.
Phishing-resistant authentication can reduce exposure to both.
Warning Signs of SIM Swapping
The most recognizable warning sign is a sudden and unexplained loss of mobile service.
Possible indicators include:
- No cellular signal in a location where service normally works
- Inability to make calls
- Inability to receive calls
- Text messages no longer arriving
- Mobile data unexpectedly stopping
- A notification that a SIM or eSIM was activated
- A message confirming a number transfer
- An unexpected carrier-account password reset
- Changes to the mobile account
- Security alerts from financial or email services
- Password resets the user did not request
- Login notifications from unfamiliar devices
- An inability to access email or financial accounts
- Unknown transactions
- Social-media messages the user did not send
- Calls from contacts saying the number behaved unusually
A temporary network outage can also cause a loss of service. However, unexplained service loss combined with account alerts, carrier notifications, or password-reset activity should be treated as urgent.
Can a SIM Swap Happen While the Phone Is Connected to Wi-Fi?
Yes.
The device may remain connected to Wi-Fi and continue running internet-based applications even after cellular service has moved to another SIM.
This can make the incident less obvious. Messaging applications that use internet connectivity may still work, while ordinary calls, SMS messages, and cellular data fail.
Users should check whether the phone still displays a normal carrier connection rather than assuming all service is intact because Wi-Fi works.
How Do Criminals Use a Swapped Number?
Intercepting SMS Codes
The attacker may attempt to log in using a password they already know.
When the service sends a verification code by SMS, it arrives on the attacker’s device.
This can defeat SMS-based MFA because the attacker controls the channel used as the second factor.
Resetting Passwords
Some services allow password recovery through a code sent to the registered phone number.
The attacker may choose “forgot password,” receive the code, create a new password, and lock the legitimate user out.
Taking Over Email
Email is a particularly valuable target because it is frequently used to reset other accounts.
After compromising email, the attacker may:
- Search for financial services
- Intercept security alerts
- Reset additional passwords
- Impersonate the victim
- Find sensitive documents
- Identify valuable contacts
Stealing Cryptocurrency
Cryptocurrency accounts can be attractive targets because transfers may be difficult to reverse.
Attackers may combine control of the phone number with:
- A stolen password
- Compromised email
- Personal information
- Account-recovery abuse
- Social engineering
Impersonating the Victim
The attacker may send messages or receive calls while appearing to use the victim’s legitimate number.
This can support:
- Fraud against friends
- Business scams
- Account-recovery attempts
- Support impersonation
- Further social engineering
Changing Recovery Information
After entering an account, the attacker may replace:
- The password
- Recovery email
- Phone number
- MFA method
- Trusted devices
- Security questions
These changes can preserve access even after the carrier returns the phone number to the victim.
Does SIM Swapping Give Attackers Access to Old Text Messages?
Usually, transferring a phone number does not automatically copy the historical messages stored on the victim’s original device.
The attacker can generally receive new calls and SMS messages sent after the transfer. They may also receive new verification codes or password-reset messages.
Old messages may become exposed through other means, such as cloud backups, synchronized accounts, compromised messaging services, device theft, or account takeover.
Can a SIM Swap Bypass an Authenticator App?
A properly configured authenticator application generally does not depend on the phone number or cellular SIM.
Transferring the number alone should not move the authenticator’s cryptographic secrets to the attacker’s device.
However, the attacker may still attempt to:
- Abuse account recovery
- Convince support to reset MFA
- Access a synchronized backup
- Compromise the user’s email
- Register a new authentication factor
- Steal an authenticated session
Authenticator applications provide better SIM-swap resistance than SMS, but phishing-resistant passkeys and hardware security keys offer stronger protection against a wider range of attacks.
How Can Individuals Prevent SIM Swapping?
Add a Carrier Account PIN
Ask the mobile carrier about adding a PIN, passcode, or other security control to the account.
The PIN should be:
- Unique
- Difficult to guess
- Different from the phone-unlock code
- Different from other account passwords
- Stored securely
Avoid using a birthday, postal code, or simple numeric sequence.
Enable a Number Lock or Port Freeze
Some carriers allow customers to block or lock unauthorized number transfers.
Names for this feature may include:
- Number lock
- Port lock
- Port freeze
- Transfer lock
- Account takeover protection
- Number-transfer protection
The user may need to complete an additional verification process before the number can be moved.
Carrier features and procedures vary, so customers should review the options available on their accounts.
Secure the Carrier Account
The online carrier account should use:
- A unique password
- Strong MFA
- Updated recovery information
- Login notifications
- Limited authorized users
If the carrier supports passkeys or an authenticator application, those methods are preferable to SMS verification on the same number being protected.
Avoid SMS for High-Value Accounts
SMS-based MFA is generally better than using only a password, but it is vulnerable to number-transfer attacks.
For email, banking, cryptocurrency, cloud, and business accounts, prefer:
- Passkeys
- Hardware security keys
- Platform authenticators
- Authenticator applications
- Device-bound credentials
The FTC warns that text-message verification may not stop a SIM swap and recommends stronger authentication such as an authenticator application or security key. FTC guidance on SIM-swap scams also advises contacting the carrier immediately if the phone unexpectedly loses service.
Use Unique Passwords
A SIM swap is often only one part of the attack.
The attacker may already possess the password through phishing, malware, credential stuffing, or a data breach.
Every important account should use a unique password. A password manager can generate and store them.
Protect the Primary Email Account
The email account should receive the strongest available protection because it controls recovery for many other services.
Use:
- A unique password
- A passkey or security key
- Secure recovery options
- Login alerts
- Session monitoring
- Regular review of connected applications
Avoid relying solely on the same phone number for both email recovery and MFA.
Limit Public Personal Information
Attackers may use personal details to impersonate the victim with a carrier or support representative.
Consider limiting public exposure of:
- Phone number
- Birthday
- Home address
- Family names
- Carrier information
- Travel plans
- Answers to common security questions
Information already exposed cannot always be removed, but reducing unnecessary disclosure makes impersonation more difficult.
Use a Strong Device Passcode
A strong device passcode protects information if the phone is physically stolen.
It does not prevent a remote SIM swap, but it reduces the risk of an attacker accessing email, authenticator applications, saved passwords, or account settings directly from the device.
Watch for Phishing
Do not provide carrier credentials, account PINs, passwords, or verification codes in response to unexpected messages or calls.
If a message claims there is a problem with the account, contact the carrier using its official application, website, or a verified support number.
How Can Mobile Carriers Reduce SIM-Swap Fraud?
Carriers can strengthen protection through:
- Secure customer verification
- Account PINs
- Number-transfer locks
- High-risk transaction alerts
- Employee access controls
- Fraud analytics
- Insider-threat monitoring
- Delays for suspicious transfers
- Separate-channel notifications
- Detailed audit logs
- Restrictions on support overrides
- Strong administrative authentication
- Customer-controlled account freezes
Verification should not depend entirely on personal information that may be publicly available or exposed in a breach.
The FCC adopted rules intended to protect consumers from SIM-swap and port-out fraud, including requirements related to secure authentication and customer notification. The commission announced July 8, 2024, as the compliance date for the relevant rules. FCC’s compliance announcement provides the regulatory timeline.
How Can Online Services Reduce SIM-Swap Risk?
Offer Phishing-Resistant MFA
Services should support authentication methods that do not depend on control of a phone number.
CISA recommends FIDO-based, phishing-resistant MFA because it is not susceptible to SIM swapping or push bombing in the same way as SMS and simple approval prompts. CISA’s Scattered Spider advisory prioritizes these protections for valuable enterprise accounts.
Treat Phone-Number Changes as High Risk
A recent SIM change, number port, or recovery-phone update can increase risk.
Where appropriate and legally permitted, a service may apply:
- Transaction delays
- Additional verification
- Withdrawal holds
- Reauthentication
- User notifications
- Manual review
A phone number should not automatically be treated as proof of the user’s identity.
Secure Recovery Workflows
Services should avoid making SMS the only recovery method.
Recovery should consider:
- Existing authenticators
- Recovery codes
- Trusted devices
- Verified support processes
- Risk signals
- Delays for sensitive changes
- Notifications through independent channels
Require Reauthentication for Sensitive Actions
A valid login should not automatically authorize:
- Password changes
- MFA removal
- Recovery changes
- Large transfers
- New payment recipients
- API-key creation
- Data exports
- Device enrollment
High-impact actions should require a fresh and appropriately strong verification step.
Notify Users Through Multiple Channels
Security alerts may be sent through:
- In-app notifications
- Existing trusted devices
- Push notifications
- Postal mail for certain high-risk events
A message sent only to the transferred number may be received by the attacker instead of the victim.
What Should You Do After a SIM Swap?
Contact the Mobile Carrier Immediately
Use another phone, the carrier’s official website, or an in-person store if necessary.
Tell the carrier that:
- Your number may have been transferred without authorization
- Your device lost service unexpectedly
- You need the number returned
- The account should be locked against further changes
- The incident should be documented
Ask the carrier to review:
- Recent SIM activations
- eSIM changes
- Port requests
- Authorized users
- Account PIN changes
- Support interactions
Secure the Email Account
Email should be one of the first online accounts secured.
From a trusted device:
- Change the password
- Revoke unfamiliar sessions
- Remove unknown devices
- Review recovery information
- Check forwarding rules
- Remove unfamiliar connected applications
- Enable phishing-resistant MFA
Contact Financial Institutions
Notify banks, payment services, cryptocurrency providers, and credit-card companies if relevant.
Ask them to:
- Restrict suspicious transactions
- Review recent activity
- Add fraud alerts
- Replace exposed credentials
- Secure account recovery
- Record the identity-theft risk
Recover Other Accounts
Prioritize:
- Banking and payments
- Mobile carrier account
- Password manager
- Cloud storage
- Social media
- Workplace accounts
- Shopping and loyalty accounts
For each service:
- Change the password
- Revoke sessions
- Remove unfamiliar devices
- Review recovery settings
- Replace SMS authentication
- Check connected applications
- Review activity
Preserve Evidence
Keep records of:
- Carrier notifications
- Service-loss timing
- Account alerts
- Password-reset messages
- Unauthorized transactions
- Support reference numbers
- Screenshots
- Email warnings
- Login history
These records may help financial institutions, carriers, law enforcement, regulators, or insurance providers investigate the incident.
Report the Fraud
Reporting options depend on the country and incident.
In the United States, victims may report relevant fraud to:
- The mobile carrier
- Financial institutions
- The Federal Trade Commission
- The Federal Communications Commission
- Local law enforcement
- Identity-theft reporting services
Use official government and provider websites rather than links in unexpected messages.
Can You Keep Your Phone Number After a SIM Swap?
In many cases, the carrier can return the number to the legitimate customer after verifying the account and reversing the unauthorized transfer.
Recovery speed depends on the carrier, transfer type, evidence, and account circumstances.
Restoring the number does not automatically secure online accounts already compromised during the incident. Passwords, sessions, recovery settings, MFA factors, and transactions must still be reviewed.
Does an eSIM Prevent SIM Swapping?
No.
An eSIM removes the need for a removable physical card, but service can still be fraudulently transferred or activated through carrier systems.
Security depends on the carrier’s account controls, identity verification, transfer procedures, notifications, and fraud detection.
Is SMS-Based MFA Better Than No MFA?
Generally, yes. A password plus an SMS code usually provides more protection than a password alone.
However, SMS depends on the security of the mobile number and carrier account. It can be threatened by SIM swapping, port-out fraud, phishing, malware, and message interception.
Users should move high-value accounts to phishing-resistant authentication whenever possible.
Can a SIM Swap Happen Without Social Engineering?
Yes.
Although social engineering is common, attackers may also use:
- Compromised carrier accounts
- Stolen employee credentials
- Malicious insiders
- Vulnerable carrier systems
- Fraudulent online transfer requests
- Weak self-service portals
- Forged identity documents
Carriers must protect their technical systems and internal processes as well as train customer-service staff.
How Long Does a SIM-Swap Attack Last?
The attacker may control the number until the carrier detects or reverses the transfer.
Even a short period can be enough to:
- Receive verification codes
- Reset passwords
- Create authenticated sessions
- Change recovery information
- Transfer funds
- Register another MFA method
After the number is restored, the attacker may retain access through sessions, tokens, connected applications, or changed security settings. Full recovery therefore extends beyond restoring cellular service.
A phone number is a useful communication channel, but it should not be treated as permanent proof of identity. Strong account security separates access from control of a transferable number by using passkeys, security keys, secure recovery, unique passwords, session monitoring, and transaction-specific verification.
