Skip to content
NordSecure
Identity & account privacy

SIM-swap risk self-assessment

In a SIM-swap attack, someone convinces your carrier to move your number to a SIM they control — then uses it to intercept your login codes and take over accounts. This quick self-assessment weighs the factors that raise or lower your exposure and gives you a plain risk score, with the specific steps that would help most. Nothing you answer is stored or sent anywhere.

  1. 1. Do you use SMS text codes for two-factor authentication on important accounts?

  2. 2. Is your real phone number publicly linked to you (social media, listings, data-broker sites)?

  3. 3. Can high-value accounts (bank, crypto, email) be reset using your phone number?

  4. 4. Have you set a PIN or passcode on your mobile carrier account?

  5. 5. Have you enabled number-lock / port-out protection with your carrier?

  6. 6. Do you use an authenticator app or hardware key instead of SMS wherever possible?

  7. 7. Do you use your main number to sign up for lots of websites and services?

How a SIM swap actually happens

An attacker collects enough about you — often from public profiles and data-broker sites — to convince your carrier they're you. They request a "replacement SIM" or a port to a new carrier, and your number goes silent as it moves to their device.

From there, every account that sends a login or reset code by SMS is reachable. That's why the biggest risk factors are SMS-based two-factor authentication and a number that's easy to tie back to you.

The two changes that help most

  • Move important accounts off SMS codes to an authenticator app or a hardware security key — those can't be swapped away with your number.
  • Set a PIN or passcode on your carrier account, and keep your real number off public sign-ups — a separate number for everyday use keeps your main one out of reach.

SIM-swap risk quiz — common questions

What is a SIM-swap attack?
An attacker gathers enough of your personal details to impersonate you to your mobile carrier, then persuades the carrier to transfer your number to a SIM in their possession. Once they control your number, any account that sends login or reset codes by SMS is theirs to take over.
Why is SMS two-factor authentication a weak point?
Because a text code goes to whoever controls the number — and after a SIM swap, that's the attacker, not you. SMS 2FA is better than no second factor, but an authenticator app or a hardware security key can't be swapped away with your number, which is why they're far stronger.
How do I lower my SIM-swap risk?
Set a PIN or passcode on your carrier account, switch important accounts from SMS codes to an authenticator app or hardware key, and keep your main number off public profiles and sign-up forms. Using a separate number for everyday sign-ups keeps your real one out of attackers' reach in the first place.
Does this quiz store my answers?
No. The scoring happens entirely in your browser. Nothing you select is sent to a server, logged, or tied to any account — you can share the score, but only if you choose to.
Would a second number actually help?
Yes, as a compartmentalisation step. If your real number isn't the one attached to your public sign-ups and profiles, an attacker has far less to work with — and a separate number, especially one not registered in your name, breaks the link between your identity and the number carrying your codes.

Related free tools

All free privacy tools

What NordSecure does about it

A free test tells you what's leaking. Fixing it usually means changing the device or the connection, not just the browser tab — which is exactly what NordSecure sells, without a name or an account.