Morning Overview

A SIM-swap scam hijacks your phone number and drains every linked account

A mobile phone number has quietly become one of the most valuable keys a person carries, because so many banks, email providers, and social platforms treat it as proof of identity. A SIM-swap scam exploits exactly that trust: a criminal persuades a wireless carrier to move a victim’s number onto a device the criminal controls, then uses the hijacked line to reset passwords and intercept the one-time codes that guard everything from checking accounts to cryptocurrency wallets. The victim often notices nothing until the phone abruptly loses signal and the money is already gone.

Federal investigators have tracked the technique for years, and the pattern rarely changes even as the losses climb. The attack does not require breaking any encryption or planting malware on the target’s handset. It relies instead on the weakest link in the chain, the human process a carrier uses to decide who is allowed to control a phone number.

How a number gets stolen without a break-in

The mechanics are deceptively simple. In a public warning about the scheme, the FBI’s Internet Crime Complaint Center describes SIM swapping as a technique in which criminals target mobile carriers to gain access to victims’ bank accounts, virtual currency accounts, and other sensitive information. The bureau explains that attackers most often rely on social engineering, an insider at the carrier, or phishing to trigger the swap. In the social-engineering version, the criminal simply calls the carrier while impersonating the customer, recites stolen personal details, and asks to move the number to a new SIM. In the insider version, a bribed employee performs the switch directly. In the phishing version, carrier staff are tricked into installing malware that hands over control of the systems that manage numbers.

Because the request appears to come from a verified account holder, the transfer can be approved in minutes. The information used to pass those verification checks, including Social Security numbers, birthdates, and home addresses, is frequently bought from the same data breaches that circulate on criminal marketplaces, so the attacker often knows enough to sound convincing.

Why one hijacked line unlocks the rest

Once the number is ported, the victim’s calls and texts flow to the criminal’s phone instead. That single change is enough to cascade through a person’s entire digital life. The FBI notes that with the number in hand, an attacker can send “forgot password” or account-recovery requests to the victim’s email and other services, then receive the reset links and verification codes by text. Many banks and exchanges still rely on SMS-based two-factor authentication, which was designed to prove that a login attempt comes from the account owner’s phone. When the phone is the criminal’s, that safeguard works in reverse, confirming the intruder rather than the owner.

The result is that a stolen number functions less like a finish line and more like a master key. After seizing an email inbox, an attacker can reset the passwords for every account tied to that address, drain balances, open new lines of credit, and lock the real owner out. Victims sometimes report the downstream damage, such as identity theft or a cleaned-out investment account, without realizing the takeover began with their phone number.

The losses regulators have documented

The scale has grown sharply as more money moved online. The FBI recorded 320 SIM-swap complaints between January 2018 and December 2020, with adjusted losses of roughly $12 million. In 2021 alone, the same center logged 1,611 complaints and more than $68 million in reported losses, a jump that reflected both rising awareness and the spread of digital wallets holding large sums. Those figures almost certainly undercount the problem, because many victims never connect the theft to the phone-number swap that enabled it, and because a share of losses are folded into broader identity-theft or fraud reports.

Consumer regulators treat the underlying vulnerability as a known weakness in how phone accounts are secured. The Federal Trade Commission’s consumer guidance on SIM-swap scams describes how a thief convinces a carrier to issue a new SIM tied to the victim’s number, then exploits the hijacked line to reach financial and online accounts. The agency’s advice centers on making the carrier account itself harder to hijack.

Warning signs and defensive steps

The clearest signal that a swap has happened is an abrupt, unexplained loss of cellular service, since the legitimate SIM stops working the instant the number is reassigned. A phone that suddenly shows no signal in a place where it normally works, or notifications about account changes the owner never made, warrants an immediate call to the carrier from another line. The FBI advises contacting the mobile provider first to reclaim the number, then changing passwords and alerting banks to watch for suspicious logins and transactions.

Prevention focuses on two fronts. On the carrier side, most major providers now let customers add a separate PIN or passcode that must be given before any change to the account, a step regulators recommend precisely because it blocks a caller who lacks it. Federal regulators have moved to harden that process as well: rules adopted by the Federal Communications Commission require wireless carriers to use secure methods of authenticating a customer before moving a number to a new device or provider and to notify customers immediately of any SIM change or port-out request. On the account side, security specialists advise moving away from text-message codes wherever a stronger option exists, favoring authentication apps or physical security keys that stay bound to a device rather than a phone number. The FBI also recommends against advertising cryptocurrency holdings or other financial details on social media, since those posts help attackers pick and profile targets. None of these measures is foolproof on its own, but together they remove the easy path that makes a SIM swap so quick to pull off.

This article was produced with AI assistance and reviewed by Morning Overview editors.


More from Morning Overview