A phone number can feel like one of the more disposable pieces of personal information, freely printed on business cards and shared with strangers. Yet in the hands of a determined criminal, control of that number can become the master key to a victim’s financial life. A fraud known as SIM swapping lets an attacker take over a target’s mobile number without ever touching the phone, and from there hijack the text-message codes that guard bank accounts, email and cryptocurrency wallets.
The technique has drawn repeated warnings from law enforcement because it defeats a security measure that millions of people rely on: the one-time codes sent by text to confirm logins. When those codes arrive on a phone the criminal now controls, the protection they were meant to provide collapses.
How a SIM swap works
A SIM swap begins not with hacking but with impersonation. The attacker first gathers personal details about the target — name, address, date of birth and sometimes a Social Security number — often assembled from data breaches, public records or phishing messages. Armed with that information, the criminal contacts the victim’s mobile carrier posing as the account holder and requests that the phone number be moved to a new SIM card or device that the attacker controls. Once the carrier makes the switch, calls and texts for that number stop reaching the real owner and start arriving on the criminal’s phone. The SIM swap scam hinges entirely on convincing a carrier’s staff, or exploiting weak account security, to authorize that transfer.
From the victim’s side, the first sign is often a phone that suddenly loses service for no clear reason. That silence is the danger window: while the number is under the attacker’s control, password-reset links and login codes can be redirected at will.
Why text-message codes are the weak point
The reason a hijacked number is so powerful is that so many accounts use text messages as a second layer of security. When a bank or email provider sends a one-time code by text to confirm identity, it is trusting that the phone number belongs to the account holder. A SIM swap breaks that assumption at its foundation, because the code is tied to the number rather than to a specific physical device.
With the codes flowing to the criminal’s phone, the attacker can reset passwords and walk through the very verification steps meant to keep intruders out. Security specialists note that SMS-based two-factor authentication is exactly what this fraud is built to bypass, which is why they increasingly recommend app-based authenticators or physical security keys — methods that stay bound to a device the criminal does not hold.
What law enforcement has warned
Federal authorities have flagged SIM swapping as a growing threat. The FBI has publicly cautioned that criminals use the technique to drain bank accounts and steal from cryptocurrency holdings, and it has urged the public to strengthen how their mobile and financial accounts are secured. The bureau accepts reports of such crimes through its Internet Crime Complaint Center, and consumer-protection agencies encourage victims to report losses so investigators can track the schemes.
The financial stakes can be severe. Because the fraud can unlock banking, brokerage and crypto accounts in a single sweep, individual victims have lost large sums in a matter of hours, and the crime has been linked to organized rings that target people known to hold valuable digital assets.
Reducing the risk
Security guidance points to several concrete defenses. Carriers typically allow customers to add a separate PIN or passcode to their mobile account, making it harder for an impostor to authorize a transfer, and consumers are advised to set one. Moving away from text-message codes toward authenticator apps or hardware keys removes the single point of failure that SIM swaps exploit, and being cautious with phishing messages limits the personal data criminals need to pose as the account holder. Cybersecurity advisories on preventing SIM swapping emphasize that layering these steps makes an account far less attractive to attackers.
Financial institutions have their own role to play, and some have moved away from relying solely on text-message codes toward stronger verification methods that are harder to hijack. Regulators have pressed mobile carriers to tighten the procedures around transferring a number, since the fraud ultimately depends on a carrier employee or system being tricked into authorizing the swap. Those industry changes matter because they attack the problem at its source rather than leaving the entire burden on individual customers.
Anyone who suddenly loses cell service unexpectedly, especially alongside alerts about password changes, is urged to contact their carrier and financial institutions immediately. Acting quickly during that window can be the difference between a foiled attempt and an emptied account — a reminder that in an age of digital banking, a phone number is worth guarding as carefully as a password.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview
- A California supervolcano has bulged upward about two and a half feet since 1978
- The FTC is warning about a scam quietly draining thousands from victims
- The NSA is again telling phone owners to switch off one location setting
- A handful of car transmissions are so tough mechanics say they almost never fail