Skip to content
NordSecure

SIM swap protection: how the attack works, and what actually stops it

SIM swapping steals your phone number by persuading your operator to move it — no malware, no password required. Here is how it works, and the defences worth your time.

What a SIM swap actually is

A SIM swap is not a hack of your phone. Nobody breaks your encryption, installs anything, or touches your handset. Someone contacts your mobile operator, claims to be you, and asks for your number to be moved to a SIM they control. If the operator believes them, your phone loses signal and every call and text meant for you arrives on their device instead.

The attack is social, not technical, and that is exactly what makes it hard to defend against with better software. The weak point is a support agent who can be persuaded, and the persuading is done with details about you that are usually easy to find: your date of birth, your address, the last four digits of a card, the name of your first pet posted in a quiz eleven years ago.

In some cases the agent is not fooled at all but bribed. Prosecutions in the UK and the US have involved telecom staff paid per swap. You cannot audit your operator's staff, which is the honest reason this is not a problem you can fully solve from your side.

Why your phone number is the master key

Over the past decade the mobile number quietly became the recovery mechanism for everything else. Bank logins send a code to it. Email providers offer it as an account-recovery route. Exchanges, marketplaces and social platforms treat possession of the number as proof of identity.

That means a stolen number is rarely the end of the attack — it is the beginning. With your texts arriving on their SIM, an attacker walks through the password-reset flow of your email, takes the mailbox, and from there resets everything the mailbox can reach. The order matters: they go for email first, because email is what everything else defers to.

This is why SIM swap losses are so disproportionate to the effort involved. The attacker does not need your password. They need one support agent and twenty minutes.

The defences that genuinely help

There is no single switch, but the measures below meaningfully reduce your exposure, roughly in order of how much they buy you for the effort:

  • Move every account you can off SMS two-factor and onto an authenticator app or a hardware security key. A code generated on your device cannot be redirected by a swap at all.
  • Ask your operator for a port-out PIN or account lock. Most carriers offer one; most customers have never been told it exists. It is not perfect — an insider can bypass it — but it stops the straightforward impersonation attempt.
  • Remove your phone number from accounts that do not truly need it, especially as a recovery option on email. An unused number is not a key.
  • Keep your high-value accounts on a number that is not publicly attached to you — not the one on your invoices, your marketplace listings, or your social profiles.
  • Separate the roles. The number people can reach you on and the number your bank knows do not have to be the same number.

Where an anonymous eSIM changes the maths

Most advice stops at 'use an authenticator app', which is correct but incomplete: some accounts still insist on a number, and you still need mobile data that is not tied to your identity.

A prepaid eSIM bought without ID changes what an attacker has to work with. There is no account at the operator holding your name, address and date of birth, because none of that was ever collected — so there is no support conversation in which someone convincingly impersonates you. The details a social-engineering attack depends on do not exist in the first place.

It is worth being precise about the limits, because overselling this would be the same dishonesty the product exists to avoid. An anonymous eSIM does not make the number unswappable in principle, and it does not protect accounts you have already tied to your main number. What it does is remove the identity file that makes impersonation easy, and give you a second, separate line for the accounts that matter most.

The other half is a device that is not leaking the information used to profile and target you in the first place. A hardened phone will not stop a swap at the carrier, but it does reduce how much of your life is available to the people planning one.

What to do if it happens to you

Speed matters more than anything else, because the attacker is racing through password resets while you are still working out why your phone says No Service.

Sudden loss of signal that does not come back after a reboot, in a place where you normally have coverage, is the signal to act rather than wait. Call your operator from another phone and say the words 'I think my number has been ported without authorisation' — that phrase routes you to the team that can act. Then, from a device that is still trusted, change your email password and revoke active sessions before touching anything else. Contact your bank directly on the number printed on your card. Report it to the police: in the UK that is Action Fraud, and elsewhere your national cybercrime unit. Keep a written timeline, because recovering funds usually depends on demonstrating when you reported it.

SIM swap questions, answered

Can a SIM swap happen if I have a strong password?
Yes. A SIM swap does not involve guessing your password — it redirects the codes used to reset it. Password strength is worth having for other reasons, but it is not a defence against this attack.
Does an eSIM prevent SIM swapping?
It removes the easiest route rather than closing the door entirely. Most swaps succeed by persuading a support agent using personal details held on your account, so an eSIM bought with no name, ID or account gives an impersonator nothing to work with. Accounts already tied to your existing number stay exposed until you move them.
Is SMS two-factor authentication better than nothing?
Yes — it still stops the large volume of attacks that rely only on a leaked password. But it is the weakest of the common second factors, and where an account offers an authenticator app or a security key, that is the better choice.
How do I know my number has been swapped?
The usual first sign is losing signal entirely and not getting it back after a restart, while other devices on the same network work normally. You may also receive an unexpected message about a SIM or plan change. Treat a sudden, unexplained loss of service as urgent rather than a network glitch.
Should I use a separate number for banking?
It is one of the more effective steps available, yes. Keeping the number your bank knows separate from the number attached to your public life means an attacker who finds one has not found the other.
Can I keep my existing number and still reduce the risk?
Yes. Set a port-out PIN with your operator, move every account you can off SMS codes, and strip your number from accounts that do not need it — especially as an email recovery option. Those three changes cost nothing and remove most of the easy paths.

Reduce your exposure

Two of these cost a few euros and take minutes. None of them require an account with us.