Skip to main content

Morning Overview

A sudden loss of cell signal can mean your phone number has been stolen

A phone that suddenly drops out, no bars, no texts, no calls, while sitting in a normal coverage area, is one of the clearest signs that someone has taken over the number attached to it. That is the mechanism behind SIM swapping, a fraud the Federal Communications Commission describes in its consumer guide on cell phone fraud: a scammer gathers enough of a victim’s personal information to convince the victim’s own carrier that the request to move the number is legitimate.

Once the transfer goes through, the scammer’s device starts receiving the victim’s calls and texts instead, including the one-time codes banks and email providers send to confirm someone’s identity. From there the fraud usually accelerates fast.

How carriers get talked into the switch

The FCC’s guide lays out two versions of the same theft: a scammer can convince a mobile carrier’s staff that a fake request is coming from the real account holder, or, less often now, physically steal a SIM card and move it into another device. The commission’s language is direct about what happens next: the scammer “can gain control over the victim’s private texts and calls, and may then try to reset credentials for the victim’s financial data and social media accounts.” A stolen phone number becomes a skeleton key for whatever else is tied to it.

The Federal Trade Commission’s own consumer alert describes the same con from the caller’s side: someone phones the carrier claiming the real customer’s phone was lost or damaged and asks that the number be activated on a new SIM, one the fraudster controls. If the request succeeds, the FTC warns, the criminal receives every text and call meant for the real owner, including the two-factor codes that were supposed to keep those accounts safe.

FBI complaint counts and losses from SIM swaps

This is not a rare or marginal scam. The FBI’s Internet Crime Complaint Center found that SIM-swap complaints and losses jumped sharply in a single year: about $12 million in losses across 320 complaints for the three years from January 2018 through December 2020, versus more than $68 million in losses from 1,611 complaints in 2021 alone, according to the bureau’s public service announcement on the trend. The FBI’s Phoenix field office has separately warned that cryptocurrency owners are a favored target, because criminals research social media first to find people likely to be holding large digital-asset balances before ever calling a carrier.

Carriers are not powerless in this fight, and the industry’s own trade group says so. The wireless trade association CTIA points to account PINs, freeze options and one-time verification codes sent before any SIM change is processed as tools most carriers already offer, alongside employee training meant to catch a fraudulent request before it goes through. None of that works, though, if a customer has never set the PIN or ignores an alert that a change is in progress.

The FCC guide adds a partial technical fix that has nothing to do with vigilance: eSIM technology. Because an eSIM is “hardwired inside the phone, so they’re not removable, eliminating some of the security risk for physical SIM swaps,” a phone that never had a removable card cannot be swapped by hand, though a fraudulent port-out request to the carrier can still move the number away from it electronically.

Recovering after a number is taken

Both the FCC and the FBI describe the same first moves once someone loses signal without explanation: contact the carrier immediately to reclaim the number, then treat every linked account as compromised until proven otherwise. The FCC guide specifically recommends filing a police report with local law enforcement, submitting an identity theft report to the FTC, and placing a fraud alert with one of the three major credit bureaus, Equifax, Experian or TransUnion, to slow down anyone trying to open new credit in the victim’s name.

Speed matters more than most people assume. The gap between a phone going silent and a criminal draining a bank account or hijacking an email inbox is often measured in minutes, not days, which is why every agency involved, the FCC, FTC and FBI alike, frames the dead phone itself as the warning worth acting on immediately rather than waiting to see if service comes back on its own.

None of these agencies frame two-factor codes sent by text as safe once a number can be moved this easily. The FCC guide and CTIA’s carrier-side page both point toward the same alternative: authentication apps or physical security keys that do not rely on the cellular network at all, so that even a successful SIM swap does not automatically hand over access to email, banking or social accounts layered behind that second factor.

The pattern the FBI describes also explains why some victims do not notice right away. A criminal who has already gathered enough personal details to fool a carrier’s verification process typically works fast once the swap goes through, changing account passwords and security questions before the real owner has finished troubleshooting what looks, at first, like an ordinary network outage. By the time service is restored on a replacement SIM, the damage to other accounts may already be underway, which is the reasoning behind the agencies’ shared advice to treat a sudden, unexplained loss of signal as an incident to investigate immediately rather than a glitch to wait out.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview