Skip to main content

Morning Overview

A SIM-swap attack can drain accounts by stealing the phone number tied to your logins

Losing cell service for a few minutes might look like a network glitch, but for a growing number of victims it is the first sign that a criminal has just taken control of their phone number. The technique, known as a SIM swap, does not require breaking into a phone at all; it targets the mobile carrier instead, tricking an employee or the carrier’s own systems into moving a victim’s number onto a SIM card the attacker controls. Once that happens, every text message and phone call meant for the victim, including the one-time codes banks and email providers send to confirm a login, goes straight to the criminal.

How Fraudsters Convince a Carrier to Port a Number

A SIM swap, also known as a port-out scam or simjacking, is a form of account takeover fraud that targets the weak link in text-message-based two-factor authentication rather than the phone itself. The scheme starts with a fraudster gathering enough personal information about a target, through phishing emails, data purchased from other criminals, direct social engineering, or details pulled from a previous breach, to convincingly impersonate that person. Armed with those details, the fraudster contacts the victim’s mobile carrier and persuades an employee to port the phone number onto a SIM card the fraudster controls, sometimes by claiming the original phone was lost, and in documented cases by bribing telecom employees directly rather than relying on social engineering at all. In some countries, fraudsters have even convinced victims to approve the swap themselves by pressing a confirmation key on their own phone. A number of high-profile hacks have relied on exactly this technique rather than any technical break-in: Twitter’s then-chief executive Jack Dorsey had his own account hijacked through a SIM swap in 2019, and a 2020 lawsuit accused a group of teenagers of using the method to steal $23.8 million in cryptocurrency from a single digital-currency investor, resulting in prison time for one defendant and a multimillion-dollar repayment order for another.

A Text Message Becomes the Attacker’s Key

Once the number moves, the victim’s phone loses network connection entirely, and every call and text meant for that person, including one-time passcodes, routes to the attacker’s device instead. Because so many banks, email providers and social media platforms allow a password reset with nothing more than access to a recovery phone number, a successful swap can hand a criminal the keys to nearly every account tied to that number within minutes. Microsoft’s Digital Defense Report found SIM swapping accounts for less than one-third of one percent of identity attacks, far behind the 99 percent driven by breach replay, password spraying and phishing, but the technique remains attractive precisely because it defeats the specific defense, SMS-based two-factor authentication, that many people still treat as sufficient protection on its own. The problem is not confined to the United States: reports of SIM swaps to the United Kingdom’s National Fraud Database rose more than 1,000 percent between 2023 and 2024, and Kenya’s Safaricom recorded a 327 percent jump in swapping cases over roughly the same period, even though such cases still represent a small fraction of overall fraud reports in each country.

The FBI Tracked Tens of Millions in Losses

The financial toll has climbed sharply. The FBI’s Internet Crime Complaint Center reported that from January 2018 through December 2020, it logged 320 SIM-swapping complaints with adjusted losses of about $12 million; in 2021 alone, that jumped to 1,611 complaints and more than $68 million in reported losses. The bureau’s advisory ties the surge specifically to attacks on cryptocurrency holders, whose exchange accounts often rely on a phone number as the sole recovery method and whose transactions, once completed, cannot be reversed the way a disputed credit card charge can. Complaint volume did not keep climbing in a straight line after that spike: FBI figures referenced in later tracking show 2022 complaints rising further before falling back over the two years that followed, a decline researchers attribute in part to carriers rolling out port-validation PINs and other account-level protections that made a swap harder to complete without raising a red flag.

Warning Signs of a Swap in Progress

The clearest signal is also the simplest: a phone that suddenly shows no service, no signal bars, or an “SOS only” status when nothing else has changed, especially if it follows an unexpected text about an account change. The FBI recommends against posting details about cryptocurrency holdings or other financial assets on social media, since that information helps a fraudster build a profile convincing enough to pass a carrier’s identity checks. Carriers can be asked to add a PIN or passcode requirement before any number can be ported, and shifting account recovery away from SMS toward an authenticator app or a physical security key removes the phone number from the equation entirely, so that even a successful swap no longer hands over access to the accounts it was meant to protect. Most major carriers now offer a free port-validation PIN or an equivalent account lock that must be provided before any number can be moved to a new SIM, a step that takes only a few minutes to set up through a carrier’s app or a call to customer service but closes off the single point of failure that every version of this fraud depends on.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview