SIM Swap Attacks: How They Work & How to Protect Your Number

Published 2026-07-24 · Plan Finder · cellphoneplans.co

Affiliate Disclosure: CellPhonePlans earns commissions from qualifying purchases through Amazon Associates and eBay Partner Network links. Carrier links go directly to providers — we may earn referral credit where noted. Our recommendations are editorially independent.

What Is a SIM Swap Attack?

A SIM swap attack occurs when a criminal convinces your mobile carrier to transfer your phone number to a SIM card they control. Once the transfer completes, the attacker receives all calls and text messages sent to your number — including one-time passcodes for banking, email, cryptocurrency exchanges, and any other account that uses SMS-based two-factor authentication. The attack works because carrier customer service representatives have the ability to reassign phone numbers between SIM cards, and social engineering techniques or insider corruption can bypass the identity verification steps meant to prevent unauthorized transfers. The victim typically notices something is wrong when their phone suddenly shows "No Service" or "SOS Only" — by then, the attacker may already be draining bank accounts or resetting passwords on critical accounts.

How SIM Swap Attacks Work

The attack follows a predictable sequence. First, the attacker gathers personal information about the victim — full name, address, date of birth, last four digits of their Social Security number, and the answer to common security questions. This information is often available through data broker websites, social media profiles, previous data breaches, or phishing emails. With this information in hand, the attacker contacts the victim's carrier, posing as the account holder. They claim their phone was lost, damaged, or stolen and request that the phone number be transferred to a new SIM card. If the carrier representative accepts the story, the transfer happens within minutes. Immediately after the swap, the attacker uses the hijacked number to intercept SMS verification codes and take over the victim's bank accounts, email, and other sensitive services.

Why Carriers Are Vulnerable

Mobile carriers process millions of legitimate SIM changes per year — lost phones, broken phones, upgrades, and carrier switches all require SIM reassignment. The volume of legitimate requests makes it difficult to distinguish fraudulent ones. Customer service representatives are evaluated on speed and customer satisfaction, creating pressure to process requests quickly rather than thoroughly verify identity. In some cases, carrier employees have been bribed by attackers to process fraudulent SIM swaps. The FCC issued new rules in 2024 requiring carriers to strengthen authentication before processing SIM changes and to notify customers of any SIM swap request, but enforcement and implementation vary across carriers.

How to Protect Your Number

Enable Carrier Account PIN or Passcode

Every major carrier allows you to set a PIN or passcode on your account that must be provided before any changes — including SIM swaps — are processed. This is separate from your unlock PIN or device passcode. On T-Mobile, set an account PIN through the T-Life app or your online account settings. Verizon allows a four-digit account PIN through the My Verizon app. AT&T offers a passcode through the myAT&T app. Set this PIN immediately if you have not already. Choose a random number that cannot be guessed from personal information — not your birthday, not your address, not the last four digits of your phone number.

Enable SIM Protection and Port-Out Lock

T-Mobile offers a feature called SIM Protection that prevents your number from being moved to another device without additional verification. Enable it through the T-Life app under Security settings. T-Mobile also offers Port Out Protection, which blocks number transfers to other carriers — available for postpaid, prepaid, and Metro by T-Mobile customers. Verizon offers Number Lock through the My Verizon app. AT&T provides extra security features through myAT&T. These carrier-specific protections add a second layer beyond the account PIN and are the single most effective step you can take. For step-by-step instructions on all carriers, see our Port-Out Lock Setup Guide.

Move Away From SMS-Based Two-Factor Authentication

The ultimate defense against SIM swap attacks is to stop relying on SMS for account verification entirely. Switch critical accounts — banking, email, cryptocurrency — to authenticator apps like Google Authenticator, Authy, or Microsoft Authenticator. These apps generate time-based codes on your physical device rather than sending them via text message, making them immune to SIM swap attacks. Hardware security keys like YubiKey provide even stronger protection for high-value accounts. Many banks and financial institutions now support authenticator apps — check your account security settings and switch away from SMS verification wherever possible.

View Security Key on Amazon View Security Key on eBay

What to Do If You Are Targeted

If your phone suddenly loses service — showing "No Service" or "SOS Only" — and you have not changed anything, act immediately. Contact your carrier from another phone and report a potential unauthorized SIM swap. Ask them to reverse the swap and lock your account. Change passwords on your email, banking, and cryptocurrency accounts immediately, starting with the email address linked to your most sensitive accounts. File a report with the FCC at fcc.gov/consumers/guides/protect-your-phone-account and with the FBI's Internet Crime Complaint Center. Contact your bank and financial institutions to freeze accounts if unauthorized transactions have occurred. Document everything with timestamps for potential legal proceedings.

For a comprehensive overview of how to lock down your carrier account, see our Complete Guide to SIM Swap Protection.

Red Flags That Someone Is Gathering Your Information

SIM swap attacks require preparation — the attacker needs your personal data before contacting your carrier. Watch for these warning signs: unexpected password reset emails for accounts you did not initiate, unusual login attempts on your email or banking accounts, phishing texts or emails asking you to "verify" your identity or click a link, calls from someone claiming to be your carrier asking for your PIN or account details (carriers will never call you and ask for your full PIN), or discovering your personal information on data broker websites. If you notice any of these, immediately strengthen your carrier account security and change passwords on critical accounts. The period between data collection and the actual SIM swap can be days or weeks — early detection gives you time to lock down your accounts before the attack occurs.

The FCC's Response to SIM Swap Fraud

In response to the surge in SIM swap attacks, the FCC adopted new rules in 2024 requiring wireless carriers to use secure authentication methods before processing SIM changes or port-out requests, offer customers the ability to lock their accounts against unauthorized transfers, and immediately notify customers when a SIM change or port-out request is made on their account. These rules represent significant progress, but implementation varies across carriers. T-Mobile has been the most proactive, offering both SIM Protection and Port Out Protection as free, self-service features. Verizon and AT&T have strengthened verification procedures but offer fewer self-service lock options. Enforcement of these rules continues to evolve, and consumers should not rely solely on carrier compliance — take the protective steps outlined above regardless of what your carrier requires.

Frequently Asked Questions

What is a SIM swap attack?

A SIM swap attack is when a criminal convinces your mobile carrier to transfer your phone number to a SIM card they control, allowing them to intercept your calls, texts, and two-factor authentication codes.

How do I know if I have been SIM swapped?

The most common sign is your phone suddenly losing cellular service and showing No Service or SOS Only. You may also receive unexpected account alerts, password reset emails you did not request, or notifications of new device logins.

How can I protect myself from SIM swap attacks?

Set a carrier account PIN, enable SIM Protection and Port-Out Lock features, switch critical accounts from SMS-based to app-based two-factor authentication, and minimize personal information available online.

Are SIM swap attacks common?

The FBI reported over 2,000 SIM swap complaints with losses exceeding 72 million dollars in a single recent year. The actual number is likely higher due to underreporting. Attacks are increasing as more financial services rely on phone-based authentication.