A SIM swap attack is a cyberattack where a hacker transfers your phone number to their SIM card to access your accounts and bypass security.
Introduction
A mobile phone number has become a core component of an individual’s digital identity, serving not only as a primary communication tool but also as a means for account recovery and authentication across banking, email, and social media platforms.
This reliance has led to the rise of SIM swap attacks, a form of identity theft that allows attackers to take control of your phone number and bypass critical security protections.
SIM Swap Attack Explained
What Is a SIM Swap Attack?
A SIM swap attack is a type of identity theft where a fraudster transfers your phone number to the SIM card they control to access your accounts. Once successful, the attacker can receive your calls and text messages, intercept one-time passwords (OTPs), and gain access to your online accounts.
How Does a SIM Swap Attack Work?
A SIM swap attack typically works in three steps:
- The attacker gathers your personal information
- They contact your mobile carrier, and impersonate you
- They transfer your phone number to their SIM card
Once completed, they can intercept verification codes, and access your accounts.
How to Prevent a SIM Swap Attack
To protect yourself from SIM swap attacks:
- Avoid SMS-based two-factor authentication (2FA)
- Use authenticator apps or hardware security keys
- Set a port-out PIN with your carrier
- Limit personal information shared online
- Monitor your accounts regularly
What is a SIM Swap Attack?
A SIM swap attack (also known as SIM swapping, SIM swap fraud or SIM hijacking) is a type of identity theft where criminals trick a mobile carrier into transferring or swapping your phone number to a SIM card they control. By doing so, they can intercept your SMS messages to bypass 2FA, allowing them to steal bank accounts causing significant financial harm.
Once successful:
- Your phone loses service
- The attacker receives your calls and text messages
- They can intercept OTPs and verification codes
This allows them to reset passwords and gain access to sensitive accounts.
SIM swap fraud attracts criminals because it can be scaled easily, requires relatively little technical skill, and can yield substantial payouts from a single attack – especially when high-net-worth individuals or cryptocurrency investors are targeted.
Additionally, SIM swapping does not require advanced technical skills. Instead, it relies on the attacker’s ability to deceive or manipulate mobile carrier employees into transferring your phone number to a SIM card under their control.
By using basic personal information – often obtained from public records or data breaches -fraudsters can carry out these attacks through a simple phone call or in-person visit, without any need for coding or hacking expertise.
Once the attacker seizes control of a phone number, they can intercept sensitive verification codes to reset passwords for email, banking, and crypto platforms. By exploiting phone-based recovery systems, they can drain bank accounts or execute fraudulent transactions.

At this point:
- Your phone stops working
- The attacker gains full control of your phone number
- They intercept login verification codes and log in to your accounts
- They take over your accounts
Why SIM Swap Attacks are Dangerous
A SIM swap attack is particularly dangerous because it gives an attacker control over one of the most widely trusted authentication methods – your phone number.
Many organizations still rely on your phone number to confirm your identity through SMS-based 2FA. If a criminal gains access to those verification codes, they can begin unlocking accounts that would otherwise be well protected.
The impact often extends far beyond a single service. With access to your phone number, attackers can:
- Reset passwords
- Access emails, banking, and social media accounts
- Drain bank accounts
- Steal cryptocurrency or funds
- Impersonate you or spread scams to your contacts
- Lock you out of your accounts
What makes SIM swap attacks particularly concerning is how quietly they unfold and how difficult to detect and respond quickly. Victims may not realize anything is wrong until their phone suddenly loses service, by which point the attacker may already be accessing sensitive accounts.
Warning Signs of a SIM Swap Attack
Watch for these red flags:
- Sudden loss of mobile service (no calls, data or texts)
- “No signal” or “No service” on your phone
- Unexpected messages from your carrier
- Unexpected login alerts
- Password reset notifications you didn’t request
- Being locked out of accounts
If you notice any of these, act immediately to secure your accounts.
Learn more about SIM swapping warning signs from the American Bankers Association.
How to Protect Yourself
SIM swap attacks are highly dangerous, and can have a significant impact. Prevention is your best defense.
Avoid SMS-based 2FA
SMS-based 2FA is increasingly considered less secure. Since it relies on phone numbers rather than physical devices, it is vulnerable to SIM swap attacks and message interceptions. This means your account security may depend on your carrier’s ability to verify identities.
Use Authenticator Apps or Security Keys
Authenticator apps like Microsoft Authenticator, Authy and Google Authenticator – or hardware security keys – generate codes locally and provide stronger protection.
Set a strong PIN or Passcode
Ask your carrier to add a strong port-out PIN or passcode to your account. This adds an extra layer of protection, as the carrier will require this PIN/passcode before making SIM changes.
Be mindful of your digital footprint
Minimize the amount of personal information you share online. Attackers often use publicly available information to impersonate you.
Enable Biometric Security
Biometric authentication, such as fingerprint or facial recognition, provides stronger protection than PINs or patterns.
If your device is lost or stolen, biometric security gives you valuable time to secure your accounts.
Real-Life Examples
Over the last few years, the scale and impact of SIM swap attacks have grown significantly, transitioning from targeting individual social media accounts to draining hundreds of millions of dollars from financial and crypto institutions.
Below are notable examples of SIM swap attacks from the past few years:
FTX Incident (2022)
FTX was a major international cryptocurrency exchange that collapsed in November 2022. Around the time of its bankruptcy filing, attackers exploited account vulnerabilities and stole more than $400 million in crypto assets.
Some reports suggest techniques such as SIM swapping or credential compromise may have contributed to unauthorized withdrawals of the accounts.
T-Mobile SIM Swap Case
In 2020, a SIM swap attack involving a T-Mobile customer resulted in major financial losses. The company later agreed to a $33 million settlement, highlighting the risks in carrier verification processes.
Key Takeaways
- SIM swap attacks target your phone number to bypass security
- SMS-based 2FA is vulnerable to interception
- Prevention is far easier than recovery
- Strong authentication methods significantly reduce risk
Conclusion
SIM swap attacks are a growing threat in today’s digital world. While no system is completely immune, you can significantly reduce your risk by:
- Avoiding SMS-based authentication
- Using authentication apps or hardware security keys
- Enabling biometric security
- Securing your mobile account
Awareness and proactive security measures are your best defense.
Frequently Asked Questions
What is a SIM swap fraud?
A SIM swap attack happens when a fraudster convinces a mobile carrier – often through social engineering – to move your phone number onto a SIM card they control. Once they take over your number, they can intercept verification codes, reset passwords, break into accounts and access sensitive accounts such as banking, email, and social media.
How does a SIM swap attack work?
A SIM swap attack works by giving a criminal control of your mobile number through impersonation. They usually start by collecting personal details – such as your name, address, date of birth, and phone number – often taken from phishing attempts, social media, or data breaches.
Using that information, they contact your mobile carrier, claiming their phone was lost or damaged. If the carrier approves the request, your number is moved to the attacker’s SIM card.
What are the signs of a SIM swap attack?
A SIM swap attack often shows up as sudden loss of mobile service, even in areas where you normally have coverage. You might also receive strange messages from your carrier, see login alerts you didn’t trigger, or get password‑reset prompts you never requested.
In some cases, you may find yourself locked out of important accounts altogether. If any of these symptoms appear, treat it as urgent and secure your number and accounts right away.
How can I protecat myself?
You can reduce the risk of a SIM swap attack by strengthening how you secure your accounts and limiting what personal details are publicly visible.
Avoid relying on text‑message verification, since codes sent by SMS can be hijacked if someone gains control of your number. Instead, use authenticator apps or hardware keys that generate codes on your device.
Adding a strong port‑out PIN or account passcode with your carrier also makes unauthorized SIM changes harder. Keeping your digital footprint small and enabling biometric features like fingerprint or facial recognition adds another layer of protection if your phone is ever lost or stolen.
What should I do if I am a victim?
If you suspect your number has been taken over, act immediately. Contact your mobile carrier and request that they reverse the unauthorized SIM transfer. Once your number is restored, secure your key accounts by updating passwords, enabling app‑based authentication, and reviewing recent activity for signs of misuse.
It’s also important to alert your bank or financial institutions if you notice unusual transactions. After regaining control, add a stronger port‑out PIN or account passcode with your carrier to reduce the chance of another attempt.


