A SIM swap is an account takeover that starts at your phone carrier, not your bank: the attacker convinces or tricks the carrier into activating your number on a SIM card in their possession, and within minutes every call and text aimed at you reaches them instead — including the login codes that banks, email providers, and crypto exchanges send by SMS. U.S. regulators have pressed carriers into adopting specific defenses, and the individual protections that matter are a carrier port-out PIN, an authenticator app instead of SMS codes, and a carrier account password that exists nowhere else.
How does the attack work?
The scam has two phases. First, the attacker gathers the raw material: your name, phone number, email address, and enough personal detail — birthdate, address, the last four digits of an ID — to pass a carrier's identity check. This information comes from data-broker sites, prior breaches, and social media, which is why the people-search cleanup problem and this crime are connected. Second, the attacker contacts the carrier posing as you, claims a lost or damaged phone, and asks for the number to be moved to a new SIM — or initiates a port to a different carrier entirely. Some attacks use bribed insiders at carrier stores or shops; the FBI's Internet Crime Complaint Center has repeatedly warned about the scale of the losses, which have reached hundreds of millions of dollars annually in reported figures.
The moment the swap completes, your phone shows No Service — often dismissed as a coverage hiccup — while the attacker receives password-reset links for your email, then your bank, then everything the email account unlocks. Crypto exchange accounts are a favorite target because those transfers are irreversible.
What are the warning signs?
The earliest signal is your phone unexpectedly losing signal in a place where coverage is normally fine — calls and texts fail, mobile data stops. If that happens, treat it as a possible account takeover in progress, not a network glitch: call your carrier from another phone immediately. Other signs include password-reset emails you did not request, a carrier account showing an unauthorized SIM change, and email or banking alerts arriving while your phone sits silent.
How do you protect yourself before it happens?
Four settings, in order of impact:
- Set a carrier port-out PIN or number-lock. Every major U.S. carrier offers a code that must be provided before your number moves to another carrier or SIM. Add it in your account security settings or by calling support, and store it in your password manager — not in your phone's notes.
- Move two-factor authentication off SMS. Use an authenticator app or passkeys for email, banking, and anything valuable; an authenticator generates codes on your device and survives a number transfer. At minimum, your primary email must not be recoverable by text message.
- Harden the carrier account itself. Unique password, and a PIN or security question the carrier requires for changes. Attackers rehearse carrier scripts; make the answers unknowable from public data.
- Watch the No Service moment. Agree now on the reflex: signal gone without reason means call the carrier from another line, then check email for reset attempts.
What did regulators require of carriers?
The Federal Communications Commission adopted rules effective in 2024 that force carriers to adopt secure methods of authenticating customers before porting numbers — the framework is built to make the blind SIM swap much harder, with uniform verification practices across carriers. The FCC has continued enforcement activity against carriers over port-out fraud since. The rules raise the floor, but a determined attacker with enough of your personal data still tries; your port-out PIN remains the personal lock the regulation assumes you will set.
What if it already happened to you?
Act in this order: call the carrier to regain the number and reverse the swap; change the password of your primary email first, then banking and financial accounts; review recovery emails and phone numbers on every important account, since the attacker may have planted their own; and file a report with the FBI's IC3 at ic3.gov, plus local police if your bank requires a report number for fraud claims. Banks treat SIM-swap fraud variably — faster reporting improves recovery odds — and anyone whose number was used to drain exchange or wallet funds should expect that money to be unrecoverable, which is the argument for doing all of the above before, not after.
For more context, read Vishing and business email compromise: when the call is from 'IT' and the invoice is real-looking.
For more context, read infostealer malware.
For more context, read deepfake voice scam.

