How Does SIM Swapping Work?
SIM swapping (also called SIM hijacking or port-out fraud) occurs when someone convinces a mobile carrier to transfer your phone number to a new SIM card without your authorization. The criminal then receives all calls and SMS intended for you — including verification codes from WhatsApp, banks, social media, and email services.
This attack is particularly insidious because the victim often doesn't realize what has happened until it's too late. The entire process can take as little as 15 minutes, during which the attacker can drain bank accounts, take over social media profiles, and access email — all using the intercepted SMS verification codes.
Typical attack steps:
- The attacker gathers your personal information (full name, date of birth, address, SSN, account PIN) — often from data breaches, social media, or social engineering
- They contact the mobile carrier either by visiting a store with fake ID, calling customer service, or using online chat support
- They impersonate you and request a SIM card replacement or number port, providing the stolen personal information as "verification"
- In some cases, they bribe carrier employees or exploit weak identity verification procedures
- Your phone number is transferred to a SIM card the criminal controls
- Your phone loses signal; the criminal receives all SMS and calls
- Using intercepted verification codes, they access your accounts that rely on SMS-based 2FA
Who's at Risk?
Anyone with a mobile phone number can be targeted, but certain profiles are more frequently attacked:
- Influencers and content creators: Their accounts are valuable for sale, ransom, or extortion. A single compromised account can be worth thousands of dollars on the black market.
- Business owners and professionals with access to sensitive data: Interest in corporate information, financial systems, or client databases.
- Cryptocurrency holders: SIM swapping has been used to steal millions in cryptocurrency because many exchange accounts rely on SMS-based 2FA.
- High-net-worth individuals: Direct access to bank accounts, investment portfolios, and financial services.
- Anyone using SMS as 2FA: The vulnerability lies in SMS dependency, not just the victim's profile. Even people with modest accounts can be targeted in mass attacks.
Signs You've Been Targeted
Recognizing the symptoms quickly can help you act before the damage escalates:
Your phone suddenly stops receiving calls and texts for no apparent reason (you're not in an area with no coverage). You may see "No Service," "SIM not registered," or "Emergency calls only." This is often the first and most critical sign that a SIM swap has occurred.
You receive notifications of "new login" or "verification code requested" on accounts you didn't access. This may indicate someone is trying (or has already managed) to access your accounts using the intercepted SMS codes.
Family or friends report receiving messages from you asking for money or codes. Your WhatsApp or other social media accounts may have already been taken over and are being used to scam your contacts.
You receive emails from your mobile carrier confirming a SIM change or number port that you didn't request. Act immediately — this confirms a SIM swap is in progress or has already been completed.
How to Protect Yourself
Protection against SIM swapping involves reducing SMS dependency and strengthening other authentication factors:
Use authenticator app instead of SMS
Switch from SMS-based 2FA to an authenticator app (Google Authenticator, Authy, Microsoft Authenticator) whenever possible. The code stays on your device, not on the SIM — so the attacker can't access it even after a successful SIM swap. For maximum security, consider hardware security keys like YubiKey.
Set a carrier PIN/passcode
Contact your carrier and set up a PIN or passcode required for any account changes, including SIM replacements and number ports. This adds an extra layer of verification that the attacker won't have. Most major carriers offer this service — AT&T, T-Mobile, Verizon, and others all support account PINs.
Use email for account recovery
Configure email as the recovery method for important accounts instead of phone number. Keep the recovery email secure with a strong password and app-based 2FA. This way, even if your SIM is swapped, attackers can't use the recovery process.