Skip to main content

Morning Overview

A SIM-swap attack can steal your phone number and unlock your bank in minutes

A phone that suddenly loses service is usually just an inconvenience, a dead battery or a dropped tower connection that resolves itself within minutes. But for a growing number of people, that same symptom has turned out to be the first sign of a fraud scheme capable of draining a bank account before the victim even realizes what happened. The attack, known as SIM swapping, does not require breaking into a phone at all. It works by convincing a wireless carrier to hand a victim’s phone number over to a criminal, and once that handoff happens, every text message meant to protect an account starts arriving on someone else’s device instead.

The scheme has been around for years, but its effectiveness has only grown as more banks, brokerages, and email providers lean on text messages as a security backstop. That reliance is precisely what makes the attack so damaging once it succeeds.

How a Fraudulent Port Request Hijacks a Phone Number

A SIM swap begins with a call, email, or in-person visit to a victim’s wireless carrier, where a scammer impersonates the account holder and claims a phone was lost, damaged, or needs a new SIM card activated. According to the Federal Communications Commission’s guide to SIM-swap scams, a bad actor who successfully convinces a customer service representative of that story can get the victim’s number reassigned to a SIM card the criminal controls, at which point calls, texts, and data that once reached the real owner’s phone are rerouted to the attacker’s device. The original phone typically loses service entirely within minutes of the switch, often the first outward sign anything has gone wrong.

Why Text-Message Verification Becomes a Liability

The real damage happens after the number changes hands, because so many financial and email accounts rely on text-message codes as a second layer of login security. Once a scammer controls the phone number, any service using SMS-based multi-factor authentication will send its one-time verification code directly to the criminal, effectively handing over the second lock on an account the attacker has already learned the password to through separate phishing or data-breach information. The Federal Trade Commission’s consumer alert on the scam describes exactly this pathway, warning that a hijacked number can let a criminal log into a bank account and steal money, take over email or social media accounts, or lock the real owner out entirely by changing passwords the moment access is gained.

The Difference Between Authenticator Apps and Text Codes

Not every form of two-factor protection is equally vulnerable to this attack, which is why regulators keep drawing a distinction between text-based codes and app-based ones. Multi-factor authentication that relies on an authenticator app, a physical security key, or a biometric scan does not depend on the phone network at all, so a SIM swap that reroutes calls and texts has no effect on those credentials. Guidance from the National Institute of Standards and Technology on multi-factor authentication basics explains that authenticator apps generate their one-time codes locally on the device itself, independent of the carrier, which is why federal consumer-protection agencies increasingly recommend switching away from text-message codes for any account holding money or sensitive personal data.

The Carrier-Side Safeguards Regulators Have Pushed For

Because the attack exploits weaknesses in how carriers verify a customer’s identity before making account changes, much of the fix depends on the wireless providers themselves. Federal regulators have pushed carriers to tighten those verification procedures and to notify customers immediately whenever a SIM change or number port-out request is processed, giving victims a chance to catch a fraudulent transfer before real damage occurs. Consumers can also add a dedicated account PIN or password directly with their carrier, a step that creates an additional identity check a scammer would need to defeat before any SIM change goes through, though victims who have experienced the attack report mixed success depending on how strictly individual carrier representatives enforce that requirement.

The Federal Communications Commission moved beyond relying on voluntary carrier practice in 2023, adopting rules that require wireless providers to use a secure method of authenticating a customer’s identity before completing a SIM change or a number port-out request, and to send an immediate notification to the account holder whenever either action takes place. Carriers that fail to follow those authentication and notification requirements can face regulatory enforcement, giving federal oversight a role that had previously been left almost entirely to each company’s own internal fraud-prevention policies.

Racing the Clock in the First Minutes After a Number Goes Dark

Speed matters once a SIM swap is suspected, since every minute a criminal controls a phone number is another minute of potential access to linked accounts. The recommended first step is contacting the wireless carrier immediately, through a secondary phone or another person’s device if necessary, to report the unauthorized change and request the number be restored. After regaining control, the next priority is changing passwords on every account tied to that phone number, starting with email and banking logins, since a scammer who briefly held the number may have already used it to reset credentials elsewhere. Reviewing recent bank and credit card statements for unauthorized charges, and reporting any identity theft to federal authorities, rounds out the response that consumer-protection agencies recommend for anyone who has been targeted.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview