SIM Swapping: How Hackers Steal Your Phone Number (And Your Accounts with It)
%201.avif)
Key Takeaways
Your phone number matters more than you think. It's tied to your bank account, your email, your crypto wallet, your social media, and in many cases, it is your second factor of authentication. Lose control of it, and you could lose everything else along with it.
That's exactly what happens in a SIM swapping attack. And it's happening far more often than most people realize.
What is SIM swapping?
SIM swapping (also called SIM hijacking or port-out fraud) is a type of account takeover attack where a cybercriminal convinces your mobile carrier to transfer your phone number to a SIM card they control.
Once they pull that off, your calls and text messages, including one-time passcodes (OTPs) sent via SMS, start going to the attacker's device. You go dark. They go live, inside your accounts.
The attack itself doesn't require hacking into a network. It exploits the people and processes at your carrier, not the technology itself. That's what makes it so dangerous: there's no software patch that can fully stop it.
By the numbers: the scale of the problem
SIM swapping is not a niche threat. The numbers tell a stark story:
- The FBI investigated 1,075 SIM swap incidents in 2023, resulting in losses approaching $50 million, up sharply from just 320 cases in 2018. (Thomson Reuters Institute)
- In the U.K., nearly 3,000 SIM swap cases were reported in 2024, a staggering 1,055% surge from just 289 incidents the prior year. (Proofpoint)
- A single hacker group targeting U.S. celebrities and influencers was arrested after stealing over $100 million across a string of SIM swap attacks. (The Record)
These figures almost certainly undercount the real scope. Many victims never realize what happened until their accounts are already drained.
How does a SIM swap attack actually work?
Let's walk through it step by step, the way an attacker would.
Step 1: Gather your personal information
Before calling your carrier, the attacker needs ammunition. They'll collect your name, phone number, home address, account number, and the last four digits of your Social Security Number, the kind of information used to verify your identity on a customer service call.
Where do they get it? From:
- Data breaches, your info has likely been exposed in at least one breach already
- Phishing emails and fake websites meant to harvest your credentials
- Social media, public profiles often reveal your birthday, hometown, employer, and more
- Dark web marketplaces where stolen data is bought and sold in bulk
Step 2: Call your carrier
Armed with your personal details, the attacker calls your mobile carrier's customer support line, or visits a retail location, and impersonates you. They claim they've lost their phone, or that they need to switch to a new device, and request that your number be transferred to their SIM card.
Carrier verification processes vary widely in quality. Some use challenge questions easily answered with publicly available data. The attacker may attempt multiple calls until they reach a representative who approves the transfer.
Step 3: Your number is now theirs
Once the carrier processes the swap, your phone loses service. No calls, no texts. You might think it's a temporary outage. By the time you realize what happened, it may be too late.
The attacker's phone is now receiving everything sent to your number.
Step 4: Account takeover begins
With your phone number in hand, the attacker triggers "Forgot Password" on your email, bank, crypto exchange, or any account that uses SMS-based two-factor authentication (2FA). The password reset code goes straight to them. They change your password, lock you out, and start draining what they find.
This is the core danger: SMS-based 2FA, which was supposed to make your accounts more secure, becomes the master key that hands them everything.
Real-world SIM swap attacks
SIM swapping isn't theoretical. It has affected high-profile individuals and everyday users alike.
The 0ktapus / Scattered Spider ring
One of the most prolific SIM-swapping criminal networks, known as "0ktapus" and later "Scattered Spider," used SIM swaps as a launchpad to breach dozens of companies and individuals. Members were charged with wire fraud, aggravated identity theft, and stealing cryptocurrency through coordinated SIM swap campaigns. (NJ Cybersecurity & Communications Integration Cell)
The $100 million celebrity attack
In 2021, Europol and international law enforcement arrested ten hackers linked to a coordinated SIM swapping campaign that targeted U.S. celebrities and influencers. The group stole an estimated $100 million in cryptocurrency and other assets. (Europol)
Everyday victims
You don't need to be famous to be targeted. Anyone who uses their phone number as a recovery method or 2FA channel, which is most smartphone users, is a potential target. Attackers often scan breached databases and cross-reference phone numbers with financial account activity, looking for the highest-value targets they can verify.
Why SMS two-factor authentication is your weakest link
It feels secure. You type in a code sent to your phone, surely that proves it's you, right?
Not when someone else has your phone number.
SMS-based 2FA was built on the assumption that your phone number is inherently tied to you. SIM swapping destroys that assumption. Once an attacker controls your number, every SMS code, every "security" text, goes to them instead of you.
This is why cybersecurity experts and the FTC have warned consumers to stop relying solely on SMS-based 2FA for sensitive accounts and switch to app-based authenticators or hardware security keys. (FTC Consumer Alert)
Warning signs you've been SIM swapped
Act fast if you notice any of these:
- Your phone suddenly loses service (no calls, no texts, no data) without explanation
- You're locked out of email or other accounts unexpectedly
- You stop receiving 2FA texts that you were expecting
- You receive a notification from your carrier about a SIM change you didn't request
- Unusual activity in your bank or crypto account shortly after losing service
If you see these signs, call your carrier immediately from a landline or a different phone. Every minute counts.
How to protect yourself from SIM swapping
The good news: there are concrete steps you can take today to dramatically reduce your risk.
1. Set a carrier account PIN or passphrase
Contact your mobile carrier and set a dedicated PIN or passphrase on your account, separate from your device PIN. This makes it significantly harder for an attacker to impersonate you on a customer service call. Major U.S. carriers (AT&T, Verizon, T-Mobile) all offer this feature.
2. Enable a SIM lock or port freeze
Some carriers allow you to lock your SIM or prevent port-outs (transfers to another carrier) without in-person verification. Ask your carrier about "SIM protection," "number lock," or "port freeze" options.
3. Ditch SMS 2FA for an authenticator app
Replace SMS-based two-factor authentication with an app-based authenticator (Google Authenticator, Authy, Microsoft Authenticator) or a hardware security key (like a YubiKey). Authenticator apps generate codes locally on your device; they aren't delivered via SMS and can't be intercepted through a SIM swap.
4. Use a strong, unique password for every account
If your email password is the same as your bank password, a SIM swap gives an attacker access to everything at once. Use a password manager to generate and store unique passwords for every account.
5. Limit what personal information you share online
Attackers build their profiles from public data. Review your social media privacy settings, avoid posting your phone number publicly, and be cautious about what personal details you share in forms, apps, and online forums.
6. Monitor your accounts and identity in real time
Waiting to discover you've been attacked is too late. Real-time identity monitoring can alert you the moment your personal data shows up in a breach, on the dark web, or in suspicious activity, giving you a head start before attackers can act.
Guardio's Identity protection watches for your personal information across dark web sources, data breach databases, and malicious sites, alerting you instantly when your data is at risk. Paired with Guardio's phishing and scam protection across your browser and phone, you get an always-on defense layer that helps stop the phishing and scam attacks that often precede a SIM swap.
SIM swapping and your business
SIM swapping isn't only a personal threat. For small business owners and employees, it can be a corporate breach waiting to happen.
If an attacker SIM-swaps a business owner's number, they can:
- Access company email accounts and internal tools
- Reset passwords on business banking and payment platforms
- Impersonate the owner in communications to employees or clients
- Bypass corporate account security tied to mobile verification
Small businesses are especially vulnerable because they often rely on a single phone number for everything, from email recovery to bank account verification. Strong account hygiene, authenticator-based 2FA, and real-time monitoring are essential business security practices, not just personal ones.
Conclusion
Your phone number isn't just how people reach you, it's a skeleton key to your digital life. SIM swapping attackers know that, and they're exploiting carrier systems and human error to steal it.
The defense isn't complicated, but it is urgent:
- Lock down your carrier account with a PIN
- Switch from SMS 2FA to an authenticator app
- Use strong, unique passwords across all accounts
- Monitor your identity and accounts in real time
These steps only take a few minutes, and each one closes off a path SIM swapping relies on. The sooner you set them up, the sooner you're covered.
FAQs
What is SIM swapping?
SIM swapping is an attack where a criminal convinces your mobile carrier to transfer your phone number to a SIM card they control. Once they have your number, they receive your calls and texts, including SMS verification codes, and use them to reset passwords and take over your accounts. It doesn't require any technical hacking, it exploits your carrier's customer service process.
How do I know if I've been SIM swapped?
The most immediate sign of a SIM swap is your phone suddenly losing all service with no explanation, no calls, no texts, no data. You may also find yourself locked out of email or financial accounts, stop receiving expected 2FA texts, or get a carrier notification about a SIM change you didn't make. If this happens, call your carrier immediately from another phone.
Can SIM swapping happen to anyone?
Yes. SIM swapping can happen to anyone whose phone number is tied to a financial, email, or social media account, which describes most smartphone users. Attackers scan breached data to find high-value targets, but ordinary individuals are targeted too. Anyone who uses SMS-based two-factor authentication is at risk.
How do I stop SIM swapping from happening?
The most effective defenses are: setting a dedicated PIN or passphrase on your carrier account, enabling a SIM lock or port freeze, and replacing SMS-based 2FA with an authenticator app (like Google Authenticator or Authy) or a hardware security key. Using unique passwords and monitoring your identity in real time adds additional protection layers.
Is SMS two-factor authentication safe?
SMS-based two-factor authentication is better than no 2FA, but it's vulnerable to SIM swapping. If an attacker controls your phone number, they receive your SMS codes and can reset passwords on any account that relies on them. The FTC and cybersecurity experts recommend switching to an authenticator app or hardware security key for sensitive accounts.
What should I do immediately after a SIM swap attack?
Call your mobile carrier immediately from a different phone or landline and report the unauthorized SIM swap. Ask them to reverse it and add a PIN lock to your account. Then change passwords on any accounts that may have been accessed, starting with email and banking. Contact your bank directly if you suspect financial fraud. File a report with the FTC at reportfraud.ftc.gov.







%201.avif)
