SIM swap protection: how the attack works, and what actually stops it
SIM swapping steals your phone number by persuading your operator to move it — no malware, no password required. Here is how it works, and the defences worth your time.
What a SIM swap actually is
A SIM swap is not a hack of your phone. Nobody breaks your encryption, installs anything, or touches your handset. Someone contacts your mobile operator, claims to be you, and asks for your number to be moved to a SIM they control. If the operator believes them, your phone loses signal and every call and text meant for you arrives on their device instead.
The attack is social, not technical, and that is exactly what makes it hard to defend against with better software. The weak point is a support agent who can be persuaded, and the persuading is done with details about you that are usually easy to find: your date of birth, your address, the last four digits of a card, the name of your first pet posted in a quiz eleven years ago.
In some cases the agent is not fooled at all but bribed. Prosecutions in the UK and the US have involved telecom staff paid per swap. You cannot audit your operator's staff, which is the honest reason this is not a problem you can fully solve from your side.
Why your phone number is the master key
Over the past decade the mobile number quietly became the recovery mechanism for everything else. Bank logins send a code to it. Email providers offer it as an account-recovery route. Exchanges, marketplaces and social platforms treat possession of the number as proof of identity.
That means a stolen number is rarely the end of the attack — it is the beginning. With your texts arriving on their SIM, an attacker walks through the password-reset flow of your email, takes the mailbox, and from there resets everything the mailbox can reach. The order matters: they go for email first, because email is what everything else defers to.
This is why SIM swap losses are so disproportionate to the effort involved. The attacker does not need your password. They need one support agent and twenty minutes.
The defences that genuinely help
There is no single switch, but the measures below meaningfully reduce your exposure, roughly in order of how much they buy you for the effort:
- Move every account you can off SMS two-factor and onto an authenticator app or a hardware security key. A code generated on your device cannot be redirected by a swap at all.
- Ask your operator for a port-out PIN or account lock. Most carriers offer one; most customers have never been told it exists. It is not perfect — an insider can bypass it — but it stops the straightforward impersonation attempt.
- Remove your phone number from accounts that do not truly need it, especially as a recovery option on email. An unused number is not a key.
- Keep your high-value accounts on a number that is not publicly attached to you — not the one on your invoices, your marketplace listings, or your social profiles.
- Separate the roles. The number people can reach you on and the number your bank knows do not have to be the same number.
Where an anonymous eSIM changes the maths
Most advice stops at 'use an authenticator app', which is correct but incomplete: some accounts still insist on a number, and you still need mobile data that is not tied to your identity.
A prepaid eSIM bought without ID changes what an attacker has to work with. There is no account at the operator holding your name, address and date of birth, because none of that was ever collected — so there is no support conversation in which someone convincingly impersonates you. The details a social-engineering attack depends on do not exist in the first place.
It is worth being precise about the limits, because overselling this would be the same dishonesty the product exists to avoid. An anonymous eSIM does not make the number unswappable in principle, and it does not protect accounts you have already tied to your main number. What it does is remove the identity file that makes impersonation easy, and give you a second, separate line for the accounts that matter most.
The other half is a device that is not leaking the information used to profile and target you in the first place. A hardened phone will not stop a swap at the carrier, but it does reduce how much of your life is available to the people planning one.
What to do if it happens to you
Speed matters more than anything else, because the attacker is racing through password resets while you are still working out why your phone says No Service.
Sudden loss of signal that does not come back after a reboot, in a place where you normally have coverage, is the signal to act rather than wait. Call your operator from another phone and say the words 'I think my number has been ported without authorisation' — that phrase routes you to the team that can act. Then, from a device that is still trusted, change your email password and revoke active sessions before touching anything else. Contact your bank directly on the number printed on your card. Report it to the police: in the UK that is Action Fraud, and elsewhere your national cybercrime unit. Keep a written timeline, because recovering funds usually depends on demonstrating when you reported it.