SIM Swapping: How Your Phone Number Gets Stolen — and What to Do in the First Hour

Published September 27, 2026 | 14 min read

Key Takeaways

Why Your Phone Number Is the Prize

Your number is not valuable because someone wants to make calls. It is valuable because a large part of the internet treats possession of it as proof you are you.

Think about what a phone number unlocks: password reset codes, "confirm it's you" texts, bank verification calls, two-factor codes, and the account recovery path for your email — which is itself the reset mechanism for everything else. Control the number and you can often walk through the front door of every account tied to it, in order, without ever knowing a single password.

That is why a SIM swap is rarely the end goal. It is the first move.

How the Attack Actually Works

The attacker's objective is to get your number provisioned onto a SIM or eSIM they control. There are several routes, and none of them involve touching your phone.

Social engineering the carrier

Someone calls support, or walks into a store, claiming to be you with a lost or damaged phone. They are asked to verify identity: name, address, date of birth, perhaps a previous address or the last four digits of a payment card. If they can answer, the number is moved. The whole attack depends on knowing facts about you that a support agent treats as secret and a broker treats as inventory.

Insider help

This is the part that undercuts most advice on the subject. Multiple prosecutions have involved retail or call-centre employees who were bribed, recruited or extorted into performing swaps directly. Where an insider is involved, no answer you could have given and no password you could have chosen would have changed the outcome. Account-level locks help here precisely because they add a control the front-line employee cannot casually override.

eSIM transfer

A newer and faster route. If an attacker can get into your carrier's online account — through a reused password, a phishing page, or credentials from an infostealer log — then on many carriers they can transfer your line to an eSIM on their own device in minutes. No store visit, no shipping, nothing to intercept. Your carrier account has quietly become as important as your email.

Port-out fraud

Rather than a new SIM on the same carrier, the number is transferred to a different carrier entirely. Same outcome, different paperwork, and historically a weaker check — which is why the port-out PIN exists as a separate setting from your account password.

Network-level interception

Weaknesses in the signalling protocols carriers use between each other have been demonstrated repeatedly for redirecting text messages without moving the number at all. This is rarer and more technical than the routes above, and it is one more reason not to rely on SMS for anything that matters.

What the rules changed, and what they did not. In 2023 the FCC adopted requirements for carriers to authenticate customers before moving a number to a new SIM or a new carrier, and to notify customers when it happens, with the obligations phasing in afterwards. That genuinely raises the floor. It does not remove the attack — an insider, a compromised carrier account, or a sufficiently well-briefed caller all still work. Treat the rules as a reason to expect a notification, not a reason to skip the settings below.

How Attackers Choose Who to Hit

This is not usually random. Target selection tends to follow visible value:

The First Hour: What to Do, in Order

If your phone has lost service unexpectedly and you have any reason to suspect this, work through these in sequence. The order is deliberate — doing step four before step two wastes the only window you have.

1Confirm it is not an outage. Ten seconds: is anyone else on your carrier near you also offline? Does your phone say "SIM not provisioned", "No SIM" or "SOS only"? An outage affects an area; a swap affects one line. Do not spend twenty minutes rebooting.

2Call your carrier from a different phone, immediately. Borrow one. Say the words "I think I have been SIM swapped" — that phrase routes you faster than describing symptoms. Ask them to suspend the fraudulent line or restore your number to your SIM, and to put a lock on the account. This is the step that stops the bleeding.

3From a computer, secure your email first. Not your bank — your email. It is the reset path for everything else, so while the attacker holds your number, your email is the account they are working on. Change the password, then sign out of all sessions, then remove the phone number as a recovery method, then re-enrol two-factor with an app or a passkey.

4Then money. Bank, brokerage, payment apps, exchanges. Change passwords, revoke sessions, and remove SMS as a verification method where you can. If you hold cryptocurrency and your keys were ever on a phone or in a browser, move the funds to a wallet with a newly generated seed.

5Check for changes the attacker made. Forwarding rules and filters on your email are the classic one — a rule that quietly copies or deletes incoming mail survives a password change. Also check recovery emails, recovery phone numbers, and any newly added trusted devices.

6Document everything, then report. Times, what you lost, who you spoke to at the carrier. File with your local police, with the FBI's IC3 if you are in the US, and complaints with the FCC and FTC. Ask your carrier in writing for the records of the change — who authorised it, from where.

7Freeze your credit at all the bureaus. A swap often accompanies broader identity fraud. Our identity theft checklist covers the freezes.

The mistake that costs people the most

Waiting. A dead phone feels like a network problem, and the instinct is to reboot, wait, or go to a store in the morning. The attacker is working through your accounts in that time, and every minute is one they use. If in doubt, ring the carrier from another line. A wasted phone call costs nothing; an hour of hesitation can cost the accounts.

Preventing It — Ten Minutes, No Cost

1Set a carrier port-out PIN or number lock. Every major US carrier offers one, under names like Number Lock, SIM Protection or a port-out passcode, and it is separate from your account password. This is the single highest-value setting in this article. Do it now; it is a settings page or one phone call.

2Secure your carrier online account like your email. Unique password, strongest available second factor. The eSIM route runs entirely through that account, so a reused password there undoes the PIN you just set.

3Get SMS out of your accounts — as a factor and as recovery. This is the part people half-finish. Turning off SMS two-factor while leaving a recovery phone number on the account means the number still opens it. Check the recovery settings specifically. We covered why that gap matters in 2FA vs passkeys.

4Use passkeys or an authenticator app instead. Neither travels over the phone network, so moving your number achieves nothing against them.

5Consider a separate number for the services that insist on SMS. A voice-over-internet number is not attached to a SIM, so it cannot be SIM swapped. Two honest caveats: some banks refuse VoIP numbers outright, and the account holding that number becomes another thing to secure properly. It is a useful tool, not a magic one.

6Stop giving your real mobile number away. Every form, loyalty scheme and shop receipt is a chance for it to end up in a marketing database and, eventually, a breach. A number that is not linked to your name and address in a purchasable record is a much harder target.

7Keep quiet about holdings. If you own cryptocurrency, treat the amount as private. Target selection follows visible value, and there is no defence as effective as not being on the list.

If You Have Already Lost Money

Be prepared for this to be harder than it should be. Cryptocurrency transfers are effectively irreversible. Bank and card transactions have better odds and strict reporting windows, so speed matters. Subscribers who lost large sums have sued their carriers over inadequate identity checks; those cases are slow and outcomes have varied, so treat litigation as a long road rather than a plan.

The practical takeaways: report fast and in writing, keep every timestamp, ask the carrier for the audit record of the change, and do not let a support representative characterise it as "an error on the account" in the notes — the paperwork matters later. And be sceptical of anyone who contacts you afterwards offering to recover stolen funds for a fee. That is a second scam aimed at people who have just proven they are worth targeting.

The Part That Makes All of This Possible

Step back and look at what the attack actually consumes. Not a vulnerability, not malware, not your password. It consumes facts about you — your name, your mobile number, your current address, a previous address, your date of birth — assembled well enough to satisfy a support agent who is trying to be helpful.

Those are not secrets. They are the standard fields of a data broker record, sold in bulk, refreshed continuously, and cheap. The carrier's identity check is asking questions whose answers are for sale, and no setting on your phone changes that.

So the honest position, the same one we take across this series: the port-out PIN and passkeys close the technical routes, and they should be your first move because they are free. What remains afterwards is the human route — someone talking past a verification check with bought details. Removing your records from brokers does not make you unswappable. It makes you materially harder to impersonate, and it removes you from the lists these targets are picked from in the first place. We wrote about the general scope in what data brokers know about you, and the sharpest version in what happens when a data broker gets your Social Security number.

Set the PIN today. Then remove the answers.

A carrier number lock and a passkey on your email take ten minutes and cost nothing — do those first, whatever else you decide. Then, for the part that is not a settings page: Vigilant Privacy sends legal deletion demands to the brokers publishing the address, date of birth and relatives used to pass a carrier's identity check, and tracks what each one does about it, for $9.95/month.

Start free — no card required

Free privacy tools

No signup, no card, no data kept.