SIM swapping: when your phone number gets stolen
No signal out of nowhere – and minutes later your accounts are gone. In a SIM swap, scammers move your number onto their own card and catch every code sent to you.
- From another device on Wi-Fi, check whether account alerts have come in.
- Call your carrier immediately from someone else’s phone and have the SIM blocked.
- Change your email password first, then banking, then the rest.
- Sign out of all sessions and move text-message 2FA to an app.
- Call your bank and review recent activity.
SIM swapping is not a technical attack on your phone. It is an attack on your carrier. Scammers pose as you and have your number moved to a new card. From that moment on, every code sent by text goes to them – and with it, the key to your most important accounts.
The short version
- Sudden loss of service with no explanation is the key early warning.
- Text-message 2FA is the weak point. An authenticator app or passkeys are safer.
- Set an account PIN with your carrier. It is the single most effective lock.
- Your number is an ID, not a contact detail. Publish it sparingly.
- In an emergency the order counts: block the SIM, then email, then money.
How the attack runs
- Collecting data: name, address, date of birth and carrier – mostly from data breaches and public sources.
- Making contact with the carrier or walking into a store with a story about a lost or broken phone.
- A replacement SIM or eSIM profile is issued and activated.
- Your phone drops off the network. That moment is the start of the attacker’s window.
- Account takeover: password resets by text at your email provider, bank, crypto exchange and social accounts.
Prevention: four things that work
Set up once, protected from then on
- 1. Set an account PIN or port-out lock with your carrier – a code required for any change to your account. This is the single most important step, and all major US carriers offer it.
- 2. Replace text-message 2FA: an authenticator app or a hardware security key for email, banking and crypto.
- 3. Review your recovery options. If every account falls back to your phone number, that number is a single point of failure. Save backup codes somewhere safe.
- 4. Publish your number sparingly – not in profiles, not in listings, not in every form.
There is a full walkthrough in Two-factor authentication: how to set it up .
The core point
Your phone number is an ID document now, not a contact detail. Lock it down with a PIN at your carrier, and take it out of the second-factor role anywhere money or your email account is involved.If it happens: the right order
- Get the SIM blocked – call the carrier, report the fraud, have a new SIM issued to you.
- Take back your email account: change the password, sign out of all sessions, check for forwarding rules. See Check active sessions .
- Call your bank and card issuers, freeze what needs freezing and review recent activity.
- Check any crypto accounts – that is where losses become permanent fastest.
- Move every text-message 2FA setting to an app or a security key.
- Report it at IdentityTheft.gov and keep the paperwork. Your bank and carrier will ask for it.
The longer plans are in Account hacked and the emergency section .
Who gets targeted
SIM swapping takes more effort than mass phishing, so it goes after targets worth the trouble:
- People holding crypto – irreversible transactions make them the main target.
- Well-known social accounts with a large following.
- People whose details are easy to look up – see Remove your data from people-search sites .
For the wider picture, see the identity protection section .
Frequently asked questions
How do I know my number has been taken over?
Your phone loses service and stays on no signal or emergency calls only, while other devices in the same place work fine. Restarting changes nothing. Notifications about password changes on your accounts often follow within minutes.
Does this make text-message 2FA worthless?
No. Text-message 2FA is much better than no second factor at all. It is simply the weakest kind. For email, banking and crypto, move to an authenticator app, or better still to passkeys or a hardware security key.
How do scammers get a replacement SIM in the first place?
By talking their way past the carrier, in a store or on the phone, using details they collected beforehand: name, address, date of birth, account number. Most of it comes from data breaches and from what is publicly searchable about you.