SIM Swap Scams Explained: Warning Signs and How to Protect Yourself

Criminals can hijack your phone number to intercept SMS codes and raid your accounts. Here is how SIM swapping works, the warning signs, and how to lock your number down.

A person holding a smartphone, illustrating mobile phone account security.
Image: Federal Trade Commission.

A SIM swap attack is when a scammer tricks or bribes your mobile carrier into moving your phone number onto a SIM card they control, so every call and text meant for you — including the one-time codes banks and email providers send to verify your identity — lands in the attacker's hands instead. It is one of the few scams that can unlock your bank account, your email, and your crypto wallet in a single afternoon, because so many "forgot my password" and two-factor login flows still trust a text message as proof that you are you. The good news is that carriers and regulators have built specific defenses against it in the last few years, and setting them up takes about ten minutes.

SIM swap fraud: the essentials
  • What it is: A criminal convinces your carrier to activate your phone number on a SIM card they own, cutting off your phone and redirecting your calls and texts to them.
  • Biggest warning sign: Your phone suddenly shows "No Service" or "SOS only" with no explanation, especially right after you get an odd text about your SIM or account being updated.
  • Why it's dangerous: Attackers use the hijacked number to intercept SMS one-time codes and reset passwords on email, banking, and cryptocurrency accounts.
  • Best defense: Set a carrier account PIN or "number lock"/port freeze, and move two-factor authentication off SMS and onto an authenticator app or passkeys.
  • If it happens: Call your carrier immediately from another phone to shut down the fraudulent SIM, then change passwords on your email and financial accounts.

What is a SIM swap, exactly?

Every phone number is tied, behind the scenes, to a specific SIM card (or eSIM profile) in a specific device. A SIM swap is a fraudulent change to that link: the scammer gets your carrier to point your number at a new SIM card — one sitting in a phone they control — instead of the one in your pocket. The Federal Trade Commission describes the scam as scammers contacting a victim's cell phone provider and impersonating the account holder, often claiming their phone was lost or damaged, to get a new SIM activated on a device they own.

The Federal Communications Commission, in the fact sheet accompanying its 2023 rulemaking on the subject, separates this into two related frauds that both end with someone else controlling your number: "SIM swapping," where a bad actor convinces your existing carrier to move your service to a new SIM, and "port-out fraud," where the bad actor instead opens an account at a different carrier and arranges to have your number transferred, or "ported," there. Both rely on the same weakness — a carrier employee or automated system being persuaded that the fraudster is you — and both give the attacker the same prize: your phone number.

How criminals actually pull it off

SIM swaps rarely start with sophisticated hacking. They usually start with information gathering and a phone call. Criminals collect personal details about a target — a full name, date of birth, address, the last four digits of a Social Security number, or answers to common security questions — from data breaches, phishing messages, or things people post publicly online. They then call the carrier's customer service line, or use a compromised or bribed insider, and use that information to convince a representative they are the account holder who needs a new SIM activated because their phone was "lost, stolen, or broken."

If the carrier does not require stronger verification, the representative activates the new SIM, and the victim's phone instantly loses signal. From that point, every text and call meant for the victim — including SMS login codes, password-reset links sent by voice call, and notifications from banks — goes to the attacker's device instead. The FCC's fact sheet on the practice notes that cell phone numbers are widely used to authenticate identity across wireless providers, email and social media accounts, financial institutions, and healthcare and retail websites, which is exactly what makes a hijacked number so valuable to a criminal: it is often the master key to a person's other accounts, not just their phone service.

What a stolen phone number lets an attacker do

Once a criminal controls your number, they typically move fast, before you notice the outage and get it fixed. With your number in hand, they can:

  • Receive SMS one-time passcodes and use them to log into or reset passwords on your email, social media, and shopping accounts.
  • Pass "call or text this number to verify it's you" checks at banks and brokerages, then drain linked accounts or open new lines of credit.
  • Take over cryptocurrency exchange accounts that rely on SMS-based two-factor authentication, where transfers are often irreversible.
  • Lock you out of your own accounts by changing passwords and recovery phone numbers before you can react.

This is precisely why the FTC's guidance singles out text-message verification as an unreliable safety net during a SIM swap: if the scammer controls the number that codes get sent to, SMS-based two-factor authentication is no longer protecting you — it is protecting the attacker.

The real warning signs of a SIM swap in progress

SIM swap attacks tend to announce themselves, if you know what to watch for. Act quickly if you notice any of the following:

  • Sudden loss of service. Your phone shows "No Service," "SOS only," or won't send or receive texts and calls, with no outage reported in your area and no obvious cause like a missed bill.
  • An unexpected "your SIM has been updated" or "new device added" text or email from your carrier that you did not request.
  • Login or password-reset notifications for accounts you didn't touch, especially ones that normally verify by text message.
  • A carrier confirmation of account changes — a new line, a new device, a port-out request — that you never authorized.
  • Friends or contacts reporting strange messages sent "from you," which can happen if an attacker pivots from your number into a messaging or social account.

The FTC's advice is blunt about the first sign in particular: if your phone suddenly stops working for calls and texts and you haven't changed plans or missed a payment, treat it as a potential SIM swap and contact your carrier right away rather than assuming it's a glitch.

How to protect yourself before it happens

Two federal moves in recent years have made SIM swap defenses much stronger than they used to be. In October 2023 the FCC adopted rules under WC Docket No. 21-341, "Protecting Consumers from SIM Swap and Port-Out Fraud," requiring wireless carriers to use secure methods to authenticate customers before redirecting a phone number to a new device or provider, to immediately notify customers whenever a SIM change or port-out request is made on their account, and to offer every customer — prepaid or postpaid — a free option to lock their account against SIM changes and number ports. Carriers were also required to investigate and remediate fraud reports promptly. Every major U.S. carrier now offers some version of that free lock. Here's how to turn it on:

CarrierFeature nameHow to turn it on
AT&T Wireless Account Lock Open the myAT&T app, sign in, tap the person icon, select Wireless account lock, then swipe to lock the account. Prepaid customers set it under Profile & Settings > Account Info & Preferences using a one-time SMS validation code. See AT&T's Wireless Account Lock support article.
Verizon Number Lock & SIM Protection In the My Verizon app or account, go to the Security page, find Number Lock, toggle it on for the number(s) you want protected, and save. SIM Protection is a separate toggle just below it. You can also call or dial *611 from your device. Details on Verizon's port-out and transfer freeze FAQ.
T-Mobile Port Validation / SIM Protection passcode Call 611 from your T-Mobile phone (or the number listed on T-Mobile's port-out scam protection page) and set a 6-to-15-digit port validation passcode, which must be provided before any port-out or SIM change is processed. See T-Mobile's port-out scam protection notice.

Beyond the carrier lock itself, a handful of habits close most of the remaining gaps:

  • Set a PIN or password on your wireless account separate from your regular login password, so a caller can't simply talk their way past a support rep using your name and address alone. The FTC specifically recommends this as a baseline step.
  • Move away from SMS-based two-factor authentication where you can. The FTC explicitly warns that text-message verification codes may not stop a SIM swap, and recommends using an authentication app or a physical security key instead. If you haven't set one up, this guide to setting up an authenticator app for two-factor authentication walks through it step by step.
  • Switch to passkeys on accounts that support them. Passkeys are tied to your device and biometrics rather than anything a carrier can reroute, which makes them immune to SIM swap interception entirely — see this walkthrough for setting up passkeys on iPhone, Android, and Windows.
  • Limit what you share publicly. Full names, birthdates, addresses, and phone numbers posted on social media give scammers raw material to pass a carrier's identity questions. It's also worth periodically checking what data brokers have compiled and opting out of data broker and people-search sites.
  • Stay alert to phishing. Many SIM swaps start with a phishing email or text that harvests the personal details an attacker later uses on the phone with your carrier; knowing how to spot phishing emails and what to do about them cuts off that pipeline early.

Carrier-specific notes worth knowing

AT&T's Wireless Account Lock, when turned on, blocks a broad set of high-risk changes at once — SIM and eSIM swaps between devices, number port-outs, device upgrades billed to the account, and changes to billing information or authorized users — rather than just one type of change, and it notifies the account's primary email and all active lines whenever the lock status changes. Verizon splits the protection into two separate toggles: Number Lock, which stops your number from being ported to a different carrier, and SIM Protection, which stops your number from being moved to a different device on Verizon's own network; both are free, and Verizon notes you'll need to temporarily turn SIM Protection off yourself when you legitimately upgrade or swap devices. T-Mobile's port validation passcode has to be read out to a representative — or entered through verified self-service channels — before any port-out or SIM change goes through, and T-Mobile has also supported a separate Number Transfer PIN, generated on demand by dialing #PORT# (#7678#), that is required specifically for postpaid number transfers to another carrier and expires after a set number of days for extra safety.

What to do if it happens to you

If your phone suddenly loses service or you get an unexpected SIM-change notification, treat it as an active emergency rather than a glitch:

  1. Contact your carrier immediately — from a different phone, a landline, or a friend's device, since yours may no longer work — and report suspected SIM swap or port-out fraud so they can shut down the fraudulent SIM and restore service to your legitimate device.
  2. Change the passwords on your email and financial accounts right away, prioritizing anything that used your phone number for password recovery, since that's the path an attacker is most likely to exploit next.
  3. Review recent account activity on banking, brokerage, and cryptocurrency accounts for unauthorized logins, transfers, or new linked devices.
  4. Turn on (or switch to) an authenticator app or passkeys for any account still relying on SMS codes, so a repeat attack can't succeed the same way.
  5. File a report with the FTC at IdentityTheft.gov if personal information was exposed or misused, and consider a police report if money was stolen, since some banks and carriers require one to process fraud claims.
  6. Ask your carrier to set (or reset) your account PIN and enable the lock/port-freeze feature described above, so the same gap can't be used against you twice.

SIM swap fraud works because it targets a weak link most people don't think about: the assumption that whoever has your phone number must be you. Carriers are now required to offer free tools that close that gap, and moving your own two-factor authentication off SMS closes the rest. Neither takes long to set up, and both are worth doing before you ever see a mysterious "No Service" message rather than after.

Frequently asked questions

What is a SIM swap attack?

A SIM swap attack is when a scammer convinces your mobile carrier to activate your phone number on a SIM card they control, usually by impersonating you and claiming your phone was lost or damaged. Once it works, your calls and texts — including SMS login codes — go to the attacker instead of you.

How do I know if I've been SIM swapped?

The clearest sign is your phone suddenly showing "No Service" or "SOS only" with no explanation, often right after an unexpected text saying your SIM or account was updated. You may also see login or password-reset notifications for accounts you didn't touch.

Can a SIM swap happen even with a strong password?

Yes. SIM swapping bypasses your password by intercepting the SMS codes used for two-factor authentication or account recovery, which is why the FTC recommends using an authenticator app or security key instead of text-message verification.

How do I lock my number against SIM swapping?

Contact your carrier and enable its free account lock or PIN feature: AT&T's Wireless Account Lock (myAT&T app), Verizon's Number Lock and SIM Protection (My Verizon app or *611), or T-Mobile's port validation passcode (dial 611). FCC rules require carriers to offer this at no cost.

What should I do immediately if I think I've been SIM swapped?

Contact your carrier right away from another phone to shut down the fraudulent SIM, then change the passwords on your email and financial accounts, review those accounts for unauthorized activity, and report the incident at IdentityTheft.gov if personal information was compromised.

Are carriers required to protect against SIM swapping?

Yes. The FCC adopted rules in 2023 (WC Docket No. 21-341) requiring wireless carriers to use secure customer authentication before redirecting a number, notify customers of SIM change and port-out requests, and offer a free account lock to all customers.

Sources

More on SIM Swap →SIM SwapPhone SecurityTwo-Factor AuthenticationIdentity TheftMobile Carriers
Sana Qureshi
Written bySana Qureshi

Sana Qureshi runs the security and privacy desk. She reports on actively exploited vulnerabilities, vendor patches and data breaches, and covers the password managers, VPNs and authentication tools readers use to protect themselves. Her alerts cite vendor advisories, CISA and the CVE record directly.

More from Security & Privacy

See all