SIM Swapping: How It Works and How to Stop It

Your phone number has become a master key to your digital life. Banks send login codes to it. Password reset links go through it. Two-factor authentication relies on it. That makes it a high-value target — and SIM swapping attacks are how criminals steal it.
A SIM swap can strip you of access to your email, banking, and social accounts within minutes. The attack does not require malware, sophisticated hacking tools, or physical access to your device. In most cases, all it takes is a phone call and some personal data your attacker already found online.
Here is exactly how it works, and what you can do to stop it.
What Is a SIM Swapping Attack?
A SIM swapping attack — sometimes called SIM hijacking or port-out fraud — is when an attacker convinces your mobile carrier to transfer your phone number to a SIM card they control.
Once the number is theirs, every SMS sent to you goes to them instead. That includes one-time passcodes, account verification texts, and banking authentication codes. With those in hand, an attacker can reset passwords and log in to any account tied to your phone number — often within the same hour the swap occurs.
The attack exploits a genuine feature of mobile networks: the ability to transfer a number to a new SIM when you lose a phone or upgrade a device. Carriers need a way to do this quickly. Attackers need a way to abuse it.
Why Your Phone Number Is a Target
Somewhere along the way, the mobile phone number became the de facto identity anchor of the internet. This was a convenience decision, not a security one.
Consider what your phone number unlocks:
- SMS two-factor authentication — still the default 2FA method at most banks, exchanges, and social platforms
- Account recovery — many services will reset your password via a text if you claim to have lost access
- Identity verification — telecoms and financial institutions often use your number to confirm who you are
If an attacker controls your number, they control the recovery path for most of your accounts. Email, banking, cryptocurrency wallets, work accounts — all of it becomes accessible with enough patience.
This is why high-profile SIM swap cases have resulted in losses of hundreds of thousands of euros. The attack is simple, scalable, and effective.
How a SIM Swap Actually Happens
Understanding the mechanics helps you see where the vulnerabilities are.
Step 1: Information gathering. Before calling your carrier, the attacker collects data on you. Your full name, address, account number, and the last four digits of a linked payment card are often enough to pass carrier security checks. This information comes from data breaches, social media, phishing emails, or purchased data sets from criminal markets.
Step 2: Social engineering the carrier. The attacker calls your mobile operator’s customer support, claims to be you, and says their SIM was lost or damaged. They answer the security questions using the data collected in step one.
Some attackers bribe carrier employees directly. Others use automated tools that test stolen credentials against carrier portals. The method varies, but the goal is the same: get the number transferred.
Step 3: The takeover. Once the swap completes, your phone loses signal — you see “No service” or “SOS only.” The attacker now receives all calls and texts meant for you. They immediately start requesting password resets and intercepting the 2FA codes that arrive.
By the time you realise what has happened, significant damage is often already done.
Warning Signs You Have Been SIM Swapped
The clearest early signal is sudden loss of mobile service when you have not changed anything yourself. Your phone shows no signal, and calls go directly to voicemail.
Other signs include:
- Unexpected emails or notifications about account changes you did not make
- Being locked out of email, banking, or social accounts
- Your mobile carrier’s app showing an unfamiliar device linked to your account
- Contacts telling you they received strange messages from your number
If you see any of these, act immediately.
How to Protect Yourself
Replace SMS 2FA with an authenticator app
This is the most impactful change you can make. Authenticator apps like Aegis (open source, Android) or Ente Auth generate time-based codes on your device, not via SMS. An attacker who has your phone number gets nothing useful from these accounts.
Work through your important accounts — email, banking, password manager, social media — and switch 2FA from “text message” to “authenticator app” wherever the option exists.
Set a SIM PIN or account transfer lock with your carrier
Most carriers let you set a PIN or passphrase required for any account changes, including SIM transfers. This is separate from your phone’s PIN. Contact your operator directly and ask what they offer. Some carriers in certain markets also allow you to freeze number portability entirely.
Audit what uses your phone number
Go through your accounts and remove your phone number wherever it is not strictly required. Where you have set it as an account recovery option, replace it with an authenticator app or hardware key instead. Reducing the number of accounts tied to your phone number limits the blast radius if a swap does occur.
Use a hardware security key for critical accounts
For high-value accounts — email, password manager, financial services — a hardware key such as a YubiKey provides the strongest available protection. These physical devices are required to authenticate and cannot be phished or intercepted over SMS.
Be cautious about what you share online
The data an attacker needs to impersonate you to a carrier is usually public or semi-public. Oversharing on social media, using real personal details on forums, or leaving old accounts active creates a larger data surface for attackers to work with.
What to Do If You Have Already Been SIM Swapped
Move quickly.
- Call your carrier from a different phone immediately. Report the unauthorised transfer and ask them to reverse it and lock your account.
- Lock your critical accounts. Use a trusted device to change passwords on your email and banking accounts before the attacker does. Use your password manager if you have one.
- Notify your bank. If any financial accounts are linked to the compromised number, alert them directly and ask about suspicious activity.
- File a report. Many countries have telecoms regulators and fraud reporting bodies. A report creates a paper trail and may help with account recovery disputes.
Recovery is possible, but it takes time. Prevention is significantly cheaper.
The Takeaway
SIM swapping is a low-tech attack with a high success rate because it exploits carrier processes, not software flaws. The protections that actually work are straightforward: remove SMS 2FA from your critical accounts, lock your carrier profile, and audit what your phone number is used for.
A phone number is a convenience, not a credential. Treat it accordingly, and your attack surface shrinks considerably.
Keep reading
Ready to act on this? keep your real number private with a separate number.
Written by
The NordSecure team · Privacy & security
Written by the people who flash, harden and support the devices and private connectivity NordSecure sells — so what you read here comes from the same hands that build the product.
Read next
Is Using an SMS Verification Service Safe and Legal?
An SMS verification service gives you a temporary, real mobile number to receive a one-time sign-up code, so you can register for something without handing over your personal number. The number is single-use and expires, usually within…
How to Pay Online Without Revealing Your Identity
“Anonymous payment” is a spectrum, not a switch — and the gap between feeling private and being private is where most people get caught. Understanding where each method sits is the difference between real privacy and a comfortable illusion…
How to Use an eSIM Anonymously While Travelling
An eSIM is a SIM card built into your phone as software instead of a plastic chip. You install one by scanning a QR code, it activates the first time it connects to a network, and it runs alongside your normal SIM — so you keep your usual…
Ready for a phone that's private by default?
Skip the setup — we flash, harden, and verified-boot re-lock it for you. Travelling instead? Grab an anonymous data eSIM.


