Morning Overview

A SIM-swap attack can drain your accounts without your phone ever ringing

A phone that suddenly shows “No Service” in a spot with perfect coverage is easy to shrug off as a glitch. In one particular kind of attack, that dead signal is the first and only visible sign that a criminal has already taken over the number and is using it to walk into bank and email accounts. The device never rings, no suspicious link gets clicked, and the victim often learns what happened only after the money is gone.

The technique is called SIM swapping, and it exploits a weakness that sits far from the victim’s own device. Instead of hacking a phone, the attacker convinces the mobile carrier to move a person’s number onto a SIM card the attacker controls. Once that transfer goes through, every call and text meant for the victim, including the security codes that protect their most sensitive accounts, lands in the criminal’s hands instead.

How the number gets stolen

The attack usually starts with homework rather than hacking. A fraudster gathers personal details about the target, sometimes through phishing, sometimes by buying data from criminal marketplaces, and sometimes by simply piecing together information a person has shared publicly. Armed with a name, address, and enough account details to sound convincing, the attacker contacts the carrier and impersonates the victim, often claiming a phone was lost or damaged and asking for the number to be moved to a new SIM. As documentation of the technique explains, this social-engineering step is the whole game, because carriers are built to help customers who genuinely do lose their phones.

The moment the port succeeds, the victim’s real SIM goes dark and the attacker’s phone inherits the number. Text messages and calls that were meant for the victim now route to the criminal, which is exactly why the trick is so quiet. There is no malware to detect and no breach of the victim’s own hardware. The failure happened at the carrier’s counter, and the customer finds out only when their service stops working.

Why a stolen number opens so many doors

The reason SIM swapping is so lucrative is that a phone number has quietly become a master key. Countless banks, email providers, and social platforms use text-message codes as a second layer of security, sending a one-time password by SMS to confirm that a login is legitimate. That system assumes the number belongs to the account holder. Once an attacker controls the number, they can request those codes and sail through the very checkpoint meant to stop them.

With text-based verification defeated, an attacker can reset passwords, log into banking apps, and authorize transfers, or lock the owner out of email and social accounts entirely. Consumer-security guidance from firms that track the fraud notes that criminals often move fast to drain accounts or sell access before the victim regains control. The financial toll is real: the FBI has documented hundreds of SIM-swap complaints in recent years with losses running into the tens of millions of dollars, and those totals capture only the cases people report.

The warning signs worth catching early

Because the attack unfolds off the device, the symptoms are indirect. The clearest is an abrupt, unexplained loss of cellular service, especially calls and texts failing in a place where coverage is normally fine. Unexpected notifications that a SIM or eSIM has been activated, or an email confirming account changes a person never requested, are also red flags. In some cases the first hint is being unable to log into an account whose password quietly changed.

Speed matters once those signs appear. The window between the port and the account takeover can be short, so a person who notices their phone go dead and cannot explain it should treat it as a possible attack rather than a technical hiccup. Contacting the carrier through another phone to confirm whether the number was moved can catch the fraud while there is still time to reverse it.

Building defenses the attack cannot reach

The strongest protection is to stop relying on text messages as a security backstop. Federal regulators have pushed carriers to tighten their procedures, and the Federal Communications Commission has published guidance urging customers to add a unique PIN or passcode to their wireless account so that no one can move the number without it. That single step blocks the casual version of the attack, because the impersonator no longer has the secret the carrier now demands.

Beyond the carrier PIN, the most meaningful upgrade is switching account security away from SMS. Authenticator apps generate codes on the device itself, and physical security keys go a step further, neither of which travels with a hijacked phone number. Locking down the email address used for password resets, limiting how much personal information is exposed publicly, and staying alert to phishing attempts all shrink the pool of data an attacker needs to impersonate a victim in the first place.

None of these measures require special expertise, and together they turn a number from an open door into a locked one. The uncomfortable truth of SIM swapping is that the victim can do everything right on their own phone and still be exposed by a decision made at a carrier’s service desk. That is precisely why the defense has to move to the parts of the system a person can actually control: the account PIN, the verification method, and the habit of treating a phone that goes silent as a signal worth investigating immediately.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview