← New search

Other meanings of SIM swapping

CYBERSECURITY

SIM swapping

SIM swapping is a social-engineering attack that transfers a victim’s phone number to an attacker-controlled SIM card. Once the transfer succeeds, the attacker may receive calls and text messages intended for the victim, including one-time passcodes used for account access and recovery.1

Social engineering
Primary mechanism
Attack type
Phone number
Asset transferred
Identity
SMS and calls
Common interception channel
Telephony
1

How the attack works

SIM swapping begins when an attacker persuades a mobile carrier to move a subscriber’s number to a different SIM or eSIM. The attacker may assemble personal information from data breaches, public profiles, phishing, or previous fraud, then impersonate the customer through a carrier shop, telephone channel, or online account. The carrier’s change of service is the pivotal event: the victim’s device loses cellular connectivity while the attacker’s device begins receiving the number’s calls and messages.

The transferred number can become a gateway to other accounts because many services treat SMS as a second factor or as a password-reset route. An attacker may then target email, cryptocurrency, financial, or social-media accounts, often changing recovery details before the victim understands what has happened. SIM swapping does not require breaking the cryptography of a SIM; it exploits weaknesses in identity verification and account-recovery procedures.

2

Consequences and warning signs

The most immediate warning sign is unexplained loss of cellular service, especially when a phone displays no network connection while nearby services appear normal. Other indicators include carrier notifications about a SIM or account change, unexpected password-reset messages, unfamiliar logins, and inability to receive authentication codes. The Federal Trade Commission advises treating an unexpected loss of phone service together with suspicious account activity as a possible SIM-swap scam.

Consequences range from temporary communications disruption to account takeover, identity theft, financial loss, and exposure of private messages or contacts. The risk is not limited to famous individuals or cryptocurrency holders: any account that relies on a phone number for authentication can be affected. A successful swap may also defeat SMS-based multifactor authentication without revealing the victim’s password.

3

Prevention and recovery

Reducing dependence on SMS for account security is the strongest general defense against SIM swapping. Where available, users can choose a passkey, a hardware security key, or an authenticator application; NIST identifies phishing-resistant and cryptographic authentication methods as stronger options than manually entered, out-of-band codes.1 Carrier account PINs, port-out locks, SIM-change alerts, and restrictions on changes made through customer service can add useful barriers, although their availability varies by provider.2

If a swap is suspected, contact the mobile carrier immediately through an official channel and request restoration of the number. Change passwords beginning with the email account, revoke unfamiliar sessions, contact financial institutions, preserve carrier messages and transaction records, and report the incident to relevant authorities. Recovery is more effective when the victim can still access trusted devices, backup codes, or hardware-based authenticators.

4

Lesser-known aspects

SIM swapping is one form of number-porting and subscriber-account fraud, and it is not identical to ordinary phone theft. A stolen handset may expose locally stored data, whereas a swap can redirect the number even while the physical phone remains in its owner’s possession. The attack can also involve an eSIM, which changes the subscriber profile digitally rather than by inserting a conventional plastic card.

Phone-number possession is an especially fragile identity signal because numbers are reassigned, recycled, shared through family or business plans, and administered by organizations whose verification practices differ. Security guidance therefore treats a telephone number as a useful contact channel but a weak sole authenticator.1 The Federal Communications Commission has adopted rules addressing customer notification and authorization for SIM changes and number ports, reflecting the institutional nature of the problem rather than placing all responsibility on individual users.3

Glossary

SIM
A subscriber identity module, physical or embedded, that authenticates a mobile subscription to a carrier network.
eSIM
An embedded SIM that can be provisioned digitally without inserting a removable card.
Port-out fraud
Unauthorized transfer of a telephone number from one mobile provider to another.
Phishing-resistant authentication
Authentication designed to prevent captured credentials or codes from being reused on an impostor site or service.

Carrier controls and account-security options vary by country, provider, device, and service. A phone number should not be treated as the sole proof of identity.