Skip to main content

Morning Overview

A SIM-swap attack can drain a bank account by stealing your phone number

A phone number was originally just a way to make calls, but banks, email providers and social media platforms have spent the past decade turning it into a security credential, using it to verify identity and deliver password-reset links. That shift created an opening that criminals have learned to exploit without ever touching the phone itself, by convincing a wireless carrier to hand the number over to a device they control. The scam has grown alongside the broader habit of tying financial accounts to a single mobile number, which raises the stakes of a successful takeover far beyond a lost text message.

Why a Phone Number Became a Security Credential

Two-factor codes, account-recovery links and fraud alerts are all commonly routed through text messages, which made a phone number a practical stand-in for identity verification long before most services adopted stronger alternatives. That convenience is precisely what makes the number valuable to steal, since gaining control of it can unlock a cascade of other accounts that all treat it as proof of who is asking. A single successful takeover can therefore cascade across email, banking, cryptocurrency and social media accounts that were never directly targeted, simply because each one leaned on the same phone number as a fallback identity check. The more services a person has tied to one number over the years, the larger that blast radius becomes, since each additional linked account is one more door the same stolen number can potentially open.

How an Attacker Convinces a Carrier to Move a Number

A SIM-swap attack begins with an attacker gathering enough personal information, often pulled from data breaches, social media profiles or a prior phishing attempt, to convincingly impersonate a victim during a call or chat with the victim’s wireless carrier. Posing as the account holder, the attacker requests that the number be transferred, or ported, to a new SIM card already in their possession, sometimes by claiming a phone was lost or a SIM card damaged. If the carrier’s verification process is thin enough, the transfer goes through without the real account holder ever being contacted. Some attackers have also been known to recruit or bribe carrier employees directly, skipping the impersonation step entirely by paying someone with access to the account system to make the change from the inside.

What Happens in the Minutes After the Swap

Once the port completes, the victim’s original phone loses service entirely, showing no signal or an emergency-calls-only message, while every call and text meant for that number now arrives on the attacker’s device. From there, the attacker can request password resets on email and financial accounts, intercept the verification codes needed to complete those resets, and move funds or lock the real owner out entirely, often within minutes of gaining control of the number. Cryptocurrency accounts have been a particularly common target, since transactions on many blockchain networks cannot be reversed once they clear, unlike a fraudulent bank transfer that a financial institution may still be able to claw back. Victims frequently discover what happened only when their own phone stops working, by which point the attacker may already have accessed multiple accounts.

New FCC Rules Aimed at Slowing the Scam

The Federal Communications Commission has adopted rules requiring wireless carriers to use stronger methods to verify a customer’s identity before processing a SIM swap or a number port, and to immediately notify the account holder whenever such a request is made. Carriers are also required to offer account locks at no cost, a setting that blocks any SIM swap or port request until the customer removes the lock directly, closing off the exact customer-service pathway that many of these attacks depend on.

Steps That Make an Account Harder to Take Over

Setting a PIN or passcode directly with a wireless carrier, separate from any password used on the carrier’s website, adds a check that a script-following call-center impersonation attempt is less likely to pass. Moving two-factor authentication away from text messages and onto an authenticator app or a hardware security key removes the specific advantage a stolen phone number provides, since neither method depends on which device currently holds the SIM. Banks and email providers that offer a security-alert option not tied to text messages give account holders an independent way to notice a takeover attempt even if a number has already been compromised, and checking for an unexpected loss of cell signal is often the earliest warning sign available before any account has actually been drained. Limiting how much personal information sits publicly on social media also narrows what an attacker has available to work with when trying to talk a customer-service representative into approving a swap, since many of the identity questions used to verify an account can be answered from a public profile alone.

This article was produced with the assistance of AI and reviewed by Morning Overview editors.


More from Morning Overview