The victim does not need to click a link, install malware, or hand over a password. If an attacker convinces a carrier to move the victim’s number to a new SIM or eSIM, every SMS code, every voice-call verification, and many “forgot password” flows tied to that number start arriving on the attacker’s device. The phone goes silent, and the account takeover clock starts.
TL;DR
- SIM swapping transfers your phone number to an attacker’s SIM or eSIM, silently redirecting every SMS code and voice-call verification you rely on.
- It doesn’t require hacking your phone — it requires convincing a telecom employee or self-service portal that the attacker is you, using PII that’s often already for sale from other breaches.
- The FCC adopted rules requiring US wireless carriers to authenticate customers before SIM changes or port-outs, offer account locks, and notify customers about SIM-change requests, with implementation dates handled through the FCC’s compliance process.
- Carrier-side controls help, but they do not change the core lesson: a phone number is a weak identity credential when it can be reassigned through a support workflow.
- SMS-based 2FA is the actual target. If your only second factor is a text message, a successful SIM swap defeats it completely — the fix is moving to an authenticator app or hardware key, not just “better phone security.”
Why This Matters to You
Your phone number is quietly load-bearing infrastructure for your digital identity: it’s the password-reset path for your email, the SMS 2FA code for your bank, and often the account-recovery mechanism of last resort for services that have nothing to do with your phone carrier. An attacker who takes over your number doesn’t need to breach any of those services individually — they just need your phone number to become theirs for twenty minutes.
Table of Contents
- How SIM Swapping Works
- Three Attack Paths: Social Engineering, Self-Service, and SS7
- The Numbers: A Declining But Still Real Threat
- What the FCC Actually Requires
- Recognizing an Attack in Progress
- MITRE ATT&CK Mapping
- What You Can Do Today
How SIM Swapping Works
SIM swapping (also called SIM hijacking, SIM splitting, or port-out fraud) transfers control of a phone number to a device the attacker controls — either by porting the number to a new carrier, issuing a replacement physical SIM, or converting it to an eSIM the attacker provisions remotely. Once complete, every call and SMS meant for the victim arrives on the attacker’s device instead, invisibly, until the victim notices their own phone has gone dead.
1. Attacker gathers victim PII — often already available from prior breaches (name, DOB, address, last 4 of SSN, account PIN if it was ever reused or leaked)2. Attacker contacts the carrier (phone support, retail store, or self-service app/portal) claiming to be the victim, reporting a "lost phone" or requesting a new eSIM3. Attacker provides enough matching PII to pass identity verification — or simply persists/escalates until an agent grants an exception4. Carrier ports the number or issues the new SIM/eSIM5. Victim's phone loses service entirely; attacker's device now receives all SMS and calls to that number6. Attacker uses SMS-based password resets and 2FA codes to take over email, banking, exchange, and other accounts in rapid succession before the victim regains the numberThe critical design flaw being exploited isn’t technical — it’s that a phone number was never meant to be a strong identity credential, but decades of “text us a code to verify it’s you” turned it into one anyway.
Three Attack Paths: Social Engineering, Self-Service, and SS7
Social engineering the carrier (most common). The attacker calls support or visits a retail store, armed with enough PII to pass identity checks, and claims their old device was lost, stolen, or damaged. Technology does not have to fail here; a human support workflow that allows exceptions can be enough.
Self-service portal / app abuse. Many carriers let customers convert a physical SIM to an eSIM or initiate a port entirely through their mobile app, sometimes with weaker verification than a live agent would apply. This path can be executed entirely remotely, at scale, without ever speaking to another human — a meaningful shift in attacker economics.
SS7 / Diameter signaling exploitation (rarer, more sophisticated). Rather than social-engineering a carrier at all, some attackers exploit weaknesses in SS7 and Diameter — the decades-old signaling protocols carriers use to route calls and texts between each other globally. With access to (or rented access on) these signaling networks, an attacker can silently intercept or redirect SMS and voice traffic without the victim’s carrier account ever being touched, making this path largely invisible to carrier-side fraud controls entirely.
The Numbers: A Declining But Still Real Threat
US federal data shows a smaller but still costly category: the FBI’s IC3 recorded 971 SIM swap complaints in 2025 with $17.37 million in reported losses, down from 982 complaints and $25.98 million in 2024. That is a real decline in reported US losses, likely reflecting improved carrier controls and public awareness following years of high-profile cases.
But the picture outside the US is worse, not better. The UK’s Cifas fraud database recorded nearly 3,000 unauthorized SIM swaps in 2024 — a 1,055% year-over-year surge. Australia saw a 240% increase in people seeking help for phone porting and SIM swap fraud in 2024 versus 2023, with 90% of cases occurring without the victim ever interacting with the attacker directly — meaning most victims had no idea an attack was even underway until their phone went silent. The threat isn’t solved; it’s shifted geography and moved toward jurisdictions with weaker carrier-side controls.
What the FCC Actually Requires
The FCC’s rules (FCC 23-95, adopted in 2023 with effective and compliance dates handled through the FCC process) require US wireless carriers to:
- Authenticate customers with a secure method before any SIM change or port-out — not just knowledge-based questions that can be answered from breached PII
- Offer a free account lock or port-out block to every customer, not as a paid add-on
- Immediately notify customers of any SIM change or port-out request, before the change is completed, in clear language
- Train employees specifically on SIM swap and port-out fraud recognition, and restrict access to customer account data (CPNI) until the customer is authenticated
The operational takeaway for 2026 is that carrier controls reduce risk, but users and organizations should still assume SMS and voice-call verification can fail if the number itself is reassigned.
Recognizing an Attack in Progress
SIM swap attacks have a narrow window where fast action limits the damage, so knowing the warning signs matters as much as prevention:
- Sudden, unexplained loss of cell signal — no bars, “SOS only,” or “no service” with no obvious cause (not in a dead zone, phone otherwise functions normally). This is the single most reliable early indicator, since the moment the port completes, your SIM stops being registered on the network.
- Unexpected “your SIM has been updated” or “welcome to your new device” texts/emails from your carrier that you didn’t request — if these arrive and you do still have signal, you may be catching the attack mid-execution.
- Password reset emails you didn’t request, especially for high-value accounts, arriving in a burst — a strong sign an attacker has already gained control of your number and is working through the account list.
- Being unable to log into accounts that use your number for verification, when nothing else about your credentials should have changed.
If any of these happen, the priority order is: contact your carrier through a channel that doesn’t depend on your compromised number (a different phone, a friend’s line, or the carrier’s web chat) to halt the port and regain the number, then immediately rotate credentials and re-enable MFA (ideally app-based, not SMS) on email first, since email is usually the pivot point to everything else.
MITRE ATT&CK Mapping
| Tactic | Technique | ID |
|---|---|---|
| Reconnaissance | Phishing for Information | T1598 |
| Credential Access | Multi-Factor Authentication Interception | T1111 |
| Impact | Financial Theft | T1657 |
What You Can Do Today
- Enable your carrier’s port-out/account lock feature today if it is available. It is one setting and directly blocks a common attack path.
- Move off SMS-based 2FA wherever an alternative exists. Use an authenticator app (TOTP) or a hardware security key (FIDO2/passkey) for any account that supports it — these aren’t tied to your phone number at all, so a SIM swap doesn’t touch them.
- Set a PIN or passcode on your carrier account that’s distinct from anything reused elsewhere, and never one derivable from public PII (birthdate, last 4 of a well-known number).
- Treat “urgent” carrier support calls or texts as a signal to verify independently — call your carrier back on a number you already have, not one provided in the message you received.
- Reduce how much PII about you is findable or purchasable. SIM swap attacks depend on identity data that’s often already circulating from unrelated breaches — the “Your Data on the Dark Web” piece linked below covers how to check your own exposure.
- For high-value accounts (crypto exchanges, banking), avoid SMS recovery entirely if the platform allows it — use an authenticator app, and where possible, a dedicated recovery email that isn’t itself protected only by SMS 2FA in a circular dependency.
- If your phone suddenly loses signal with no explanation, treat it as an active incident, not an inconvenience. Contact your carrier through an alternate channel immediately and start locking down high-value accounts (email, banking, exchanges) in parallel rather than waiting to confirm what happened first.
Related Posts
- Passkeys and FIDO2: The End of Passwords — and What Attackers Do Next — the strongest practical replacement for SMS-based verification.
- AitM Phishing: How Attackers Bypass MFA and How to Stop Them — a different MFA-bypass path worth understanding alongside this one.
- LSHIY Password Spray: ROPC and MFA Gaps in Microsoft 365 — another case study in how “MFA enabled” doesn’t always mean “MFA effective.”
- Your Data on the Dark Web: How to Find It Without Ever Opening Tor — checking the PII exposure that SIM swap attacks are built on.
Sources
- Efani — SIM Swap Fraud Statistics 2026
- Group-IB — The Evolution of SIM Swapping Fraud: How Fraudsters Bypass Security Layers
- FCC — Cell Phone Fraud
- FCC — Announces Effective Compliance Date for SIM Swapping Item
- Federal Register — Protecting Consumers from SIM-Swap and Port-Out Fraud
- FBI IC3 — 2025 Internet Crime Report
- PIRG — SIM swap scams can be devastating
- Proofpoint — What Is SIM Swapping?
- MITRE ATT&CK — T1598 Phishing for Information
- MITRE ATT&CK — T1111 Multi-Factor Authentication Interception
- MITRE ATT&CK — T1657 Financial Theft