SIM Swapping: How Hackers Clone Your Phone Number

In a SIM swap attack, criminals transfer your phone number to a SIM card in their possession. With it, they receive all your SMS messages — including verification codes — and can take over your accounts. It's one of the most devastating attacks for anyone using SMS as a second authentication factor.

Intercepts SMS Critical risk

How Does SIM Swapping Work?

SIM swapping (also called SIM hijacking or port-out fraud) occurs when someone convinces a mobile carrier to transfer your phone number to a new SIM card without your authorization. The criminal then receives all calls and SMS intended for you — including verification codes from WhatsApp, banks, social media, and email services.

This attack is particularly insidious because the victim often doesn't realize what has happened until it's too late. The entire process can take as little as 15 minutes, during which the attacker can drain bank accounts, take over social media profiles, and access email — all using the intercepted SMS verification codes.

Typical attack steps:

  1. The attacker gathers your personal information (full name, date of birth, address, SSN, account PIN) — often from data breaches, social media, or social engineering
  2. They contact the mobile carrier either by visiting a store with fake ID, calling customer service, or using online chat support
  3. They impersonate you and request a SIM card replacement or number port, providing the stolen personal information as "verification"
  4. In some cases, they bribe carrier employees or exploit weak identity verification procedures
  5. Your phone number is transferred to a SIM card the criminal controls
  6. Your phone loses signal; the criminal receives all SMS and calls
  7. Using intercepted verification codes, they access your accounts that rely on SMS-based 2FA
Why it's so dangerous: If you use SMS for account recovery or as a second authentication factor, the attacker gains total control. They can access WhatsApp, banking apps, email, and social media — often within minutes of the swap being completed.

Who's at Risk?

Anyone with a mobile phone number can be targeted, but certain profiles are more frequently attacked:

  • Influencers and content creators: Their accounts are valuable for sale, ransom, or extortion. A single compromised account can be worth thousands of dollars on the black market.
  • Business owners and professionals with access to sensitive data: Interest in corporate information, financial systems, or client databases.
  • Cryptocurrency holders: SIM swapping has been used to steal millions in cryptocurrency because many exchange accounts rely on SMS-based 2FA.
  • High-net-worth individuals: Direct access to bank accounts, investment portfolios, and financial services.
  • Anyone using SMS as 2FA: The vulnerability lies in SMS dependency, not just the victim's profile. Even people with modest accounts can be targeted in mass attacks.
Important: You don't need to be famous or wealthy to be targeted. Criminals conduct mass attacks using data from breaches. If your personal information has appeared in any data leak, you could be a target.

Signs You've Been Targeted

Recognizing the symptoms quickly can help you act before the damage escalates:

Your phone suddenly stops receiving calls and texts for no apparent reason (you're not in an area with no coverage). You may see "No Service," "SIM not registered," or "Emergency calls only." This is often the first and most critical sign that a SIM swap has occurred.

You receive notifications of "new login" or "verification code requested" on accounts you didn't access. This may indicate someone is trying (or has already managed) to access your accounts using the intercepted SMS codes.

Family or friends report receiving messages from you asking for money or codes. Your WhatsApp or other social media accounts may have already been taken over and are being used to scam your contacts.

You receive emails from your mobile carrier confirming a SIM change or number port that you didn't request. Act immediately — this confirms a SIM swap is in progress or has already been completed.

If you suspect a SIM swap: Contact your carrier immediately, block the old SIM, and request a new one. Then change passwords and check active sessions on all your accounts. File a police report and notify your bank. Time is critical — every minute counts.

How to Protect Yourself

Protection against SIM swapping involves reducing SMS dependency and strengthening other authentication factors:

Critical

Use authenticator app instead of SMS

Switch from SMS-based 2FA to an authenticator app (Google Authenticator, Authy, Microsoft Authenticator) whenever possible. The code stays on your device, not on the SIM — so the attacker can't access it even after a successful SIM swap. For maximum security, consider hardware security keys like YubiKey.

Critical

Set a carrier PIN/passcode

Contact your carrier and set up a PIN or passcode required for any account changes, including SIM replacements and number ports. This adds an extra layer of verification that the attacker won't have. Most major carriers offer this service — AT&T, T-Mobile, Verizon, and others all support account PINs.

Important

Use email for account recovery

Configure email as the recovery method for important accounts instead of phone number. Keep the recovery email secure with a strong password and app-based 2FA. This way, even if your SIM is swapped, attackers can't use the recovery process.

Summary: SIM swapping is only devastating when SMS is the sole or primary verification method. Migrate to authenticator apps, set a carrier PIN, and secure your accounts with non-SMS recovery options. These steps make SIM swap attacks far less effective.