A phone number feels like a harmless string of digits, but in the wrong hands it can become a skeleton key to a person’s financial life. In a SIM-swap attack, a criminal convinces a wireless carrier to move a victim’s number onto a SIM card the criminal controls, seizing control of that person’s calls and text messages. Once the number is hijacked, the attacker can intercept the one-time security codes that banks and other services send by text, reset passwords, and drain accounts, often before the victim realizes their phone has gone dark.
The attack is dangerous precisely because it exploits the very system meant to protect people. Text-message verification codes were widely adopted to make accounts safer, but they route through the phone number, and whoever controls the number receives the codes.
How a phone number gets hijacked
The mechanics are more social than technical. In a SIM-swap scam, the attacker gathers personal details about the target and then contacts the mobile carrier posing as that customer, claiming a lost or damaged phone and requesting that the number be transferred to a new SIM. If the carrier’s identity check relies on information the criminal has already collected, the request succeeds and the victim’s number activates on the attacker’s device.
That personal information comes from familiar places. According to the FBI, criminals conducting SIM swaps often gather a victim’s details through phishing, malware, or data bought on the dark web, then use that data to impersonate the customer to the carrier or to answer security questions. Some schemes go further, bribing or tricking a telecom employee into performing the swap directly. Either way, the outcome is the same: the number lands on hardware the attacker holds.
Why the phone number is the master key
Control of a number is powerful because so many accounts are anchored to it. Many services offer password resets by text, and many use SMS as a second factor of authentication. Once a criminal receives those messages, they can walk through the “forgot password” flow on email, banking, and cryptocurrency accounts, capture the confirmation code, and lock the real owner out. Email is often the first target, because whoever controls the inbox can then reset almost everything else.
The financial damage can be immediate and large. The FBI has reported that SIM-swap victims collectively lose tens of millions of dollars in a single year, with individual losses frequently running into the tens of thousands. Cryptocurrency holders are a favored target because those transfers are fast and effectively irreversible, but conventional bank and brokerage accounts are hit as well.
The signs of a takeover in progress
A SIM swap tends to announce itself, if the victim knows what to watch for. The clearest signal is a sudden loss of cellular service on a phone that is otherwise working, no ability to place calls, send texts, or use mobile data, because the number now lives on another device. Other warning signs include a notification that the number has been activated elsewhere, unexpected security codes arriving without any login attempt, or being locked out of email and financial accounts.
Speed matters after those signs appear. The window between losing service and losing money can be short, so contacting the carrier from another phone to report the swap, and alerting banks to freeze accounts, is the difference between a scare and a catastrophe.
New federal rules on carriers
Regulators have moved to close the gap that lets a stranger claim someone else’s number. The Federal Communications Commission adopted rules requiring wireless providers to use secure customer-authentication methods before transferring a number to a new device or a new carrier. The rules also require carriers to notify customers immediately whenever a SIM change or a port-out request is made on their account, giving people a chance to intervene before an unauthorized swap completes.
Those requirements carry a compliance timeline, and the commission set a firm date for carriers to have the protections in place. The FCC has stated the industry-wide obligations took effect in 2024, standardizing safeguards that some carriers previously offered only on request. The rules do not make an account swap-proof, but they raise the difficulty and shorten the time an attacker can operate unnoticed.
Locking down a number
Individuals can add their own layers on top of the carrier rules. Most major carriers now offer a number-lock or port-freeze feature that blocks any transfer until the customer removes the lock, and setting a separate PIN or passcode on the wireless account makes impersonation harder. Security experts also recommend moving away from text-message codes where possible, favoring an authenticator app or a physical security key for two-factor authentication, since those are tied to a device rather than to a phone number.
Reducing the personal data available to attackers helps as well: being cautious with phishing messages, limiting what is shared publicly, and using strong, unique passwords so that a single leaked credential does not open the door. Anyone who suspects a SIM swap is urged to contact their carrier and financial institutions immediately and to report the crime to the FBI’s Internet Crime Complaint Center, which tracks the schemes and the networks behind them.
This article was produced with AI assistance and reviewed by Morning Overview editors.
More from Morning Overview
- A Colorado wildfire has exploded past 87,000 acres with no containment
- A wildfire near Ouray swelled past 18,000 acres, putting Colorado towns on alert
- The Pentagon’s newest UFO files describe a fish-scaled, potato-shaped object on camera
- Scientists spotted a rare tusked whale alive at sea for the first time, then fired a crossbow at it.