Morning Overview

A SIM-swap attack can drain your accounts without ever touching your phone

Most people picture account theft as a hacker breaking into a device, but one of the more damaging techniques never requires physical access to a phone at all. In a SIM-swap attack, a criminal convinces or manipulates a mobile carrier into moving a victim’s phone number to a SIM card the attacker controls.

Once the number is transferred, the attacker begins receiving the victim’s calls and text messages, including the one-time security codes many banks and services send by text. That single move can hand over the keys to email, financial accounts, and more, while the victim’s own handset quietly loses service.

What a SIM actually controls

A SIM card is the small chip that ties a phone number to a specific device on a carrier’s network. The number is not permanently welded to the hardware, which is why a carrier can move a customer to a new phone by activating a new SIM.

That flexibility is normal and useful, but it also means a phone number can be reassigned by anyone who can persuade the carrier to do it. The attack exploits a legitimate customer-service function rather than a flaw in the phone itself. The same process that lets a customer keep a number after losing a handset or upgrading to a new device is the one an attacker turns against the account holder, which is what makes the technique so hard to shut down entirely.

How attackers pull off the swap

Fraud advisories describe two main routes. In one, the attacker uses stolen personal information, gathered from data breaches, phishing, or social media, to impersonate the victim and pass a carrier’s identity checks.

In the other, the attacker relies on social engineering or, in some cases, a bribed or tricked employee to authorize the transfer. Either way, the goal is the same: get the carrier to point the victim’s number at a SIM the attacker holds. The personal details needed to pass an identity check are often surprisingly easy to assemble, since a date of birth, an address, and answers to common security questions can be pieced together from breached databases and public social-media profiles.

Why intercepted texts are so dangerous

The real payoff comes from text-based security codes. Many services use a text message as a second step to verify identity or to approve a password reset, on the assumption that only the account owner has the phone.

When the number is under the attacker’s control, that assumption collapses. The codes meant to protect an account instead arrive on the attacker’s device, allowing password resets and logins that can lead straight to a victim’s funds. Email accounts are a common first target, because seizing an inbox often unlocks a cascade of other services that use it for password recovery, giving an attacker a path from one hijacked number to a whole cluster of accounts.

The warning signs of a live attack

A SIM swap often announces itself through a sudden loss of service. A phone that abruptly cannot make calls, send texts, or use cellular data, with no outage in the area, may be a sign the number has been moved.

Other signals include being locked out of accounts that normally rely on text codes, or receiving notifications about changes a person did not make. Recognizing these signs quickly matters, because the window between the swap and the account takeover can be short. An unexpected message from a carrier confirming a SIM change or a device activation that the account holder never requested is one of the clearest early warnings, and it warrants an immediate call to the provider rather than a wait-and-see response.

How to make an account harder to hijack

Security guidance stresses reducing reliance on text messages for protection. Using an authenticator app or a physical security key for two-factor verification keeps the second step tied to a device or token rather than to a phone number that can be reassigned.

Guidance also points to strengthening the carrier account itself, since that is where the swap happens. Many carriers allow a customer to add a separate PIN or passcode required before any number transfer, and avoiding the reuse of passwords across accounts limits how much an attacker can do with stolen credentials.

What to do when it happens

Speed is the priority once an attack is suspected. Contacting the carrier immediately to report the loss of service and regain control of the number can cut off the attacker’s access, and alerting banks and email providers helps stop further damage.

Documenting what happened also helps, since a record of the timeline and any unauthorized transactions supports disputes with financial institutions and any report filed with law enforcement. Acting on all fronts at once, the carrier, the banks, and the email provider, gives the best chance of containing the damage before an attacker can move further.

Federal fraud guidance on SIM-swap schemes, published in an FBI public service announcement, lays out both the mechanics of the attack and the steps that make an account harder to seize. The central lesson is that a phone number is a weaker identity anchor than many people assume, and protecting the accounts behind it means not trusting a text message as the last line of defense.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview