Morning Overview

In a SIM-swap scam a thief hijacks your phone number and drains your accounts

A SIM-swap attack turns a person’s own phone number into the weapon used against them. Instead of stealing a password directly, the thief tricks a mobile carrier into moving the victim’s number onto a SIM card the criminal controls, and from that moment every call, text, and security code meant for the victim flows to the attacker instead. Because so many banks and email providers still verify identity with a text message, control of the number can quickly become control of the money.

The FBI has treated SIM swapping as a serious and persistent threat, publishing consumer guidance and repeated alerts as reported losses climbed into the tens of millions of dollars. The scheme is dangerous precisely because it exploits a defense many people trust the most: the one-time code sent to a phone.

How a carrier gets tricked into moving a number

The attack usually begins with research rather than hacking. A criminal gathers enough personal detail about a target, often scraped from data breaches, social media, or earlier phishing, to sound convincing on a call to the victim’s wireless provider. According to the FBI’s explanation of SIM swapping, the fraudster then impersonates the account holder and persuades a customer-service representative to port the number to a new SIM, sometimes by claiming the original phone was lost or damaged.

In other cases the weak point is not the script but a person on the inside. The FBI has noted that some swaps are carried out with the help of bribed or complicit employees who can reassign a number directly, bypassing the usual verification questions entirely. Either way, the result is the same: the victim’s handset silently loses service while the attacker’s device lights up with the stolen number.

Why a stolen number unlocks the rest of an account

Once the number is in the criminal’s hands, the second stage moves fast. The attacker heads to a bank, email, or cryptocurrency account and clicks “forgot password,” triggering a reset code sent by text. As the FBI’s Internet Crime Complaint Center warned in a public advisory, intercepting those SMS-based two-factor codes lets criminals reset passwords and seize accounts tied to the phone number, then move funds before the victim understands what has happened.

The same advisory quantified how quickly the problem grew. The IC3 reported receiving 320 SIM-swap complaints with roughly $12 million in losses across the three years from January 2018 through December 2020, then 1,611 complaints with more than $68 million in losses in 2021 alone. Cryptocurrency holders have been frequent targets because those transactions are fast and effectively irreversible, but ordinary bank and brokerage accounts are squarely in the crosshairs as well.

The warning signs that a swap is under way

The clearest symptom is sudden, unexplained loss of cellular service. A phone that abruptly shows “no service” or “SOS only” in a place with normal coverage, and cannot make calls or send texts, may indicate the number has been ported away. A rundown of the FBI’s smartphone-scam guidance points to other red flags too, including notifications about account changes the owner did not request and being locked out of email or financial logins shortly after service drops.

Speed matters because the attacker’s window is narrow but productive. Every minute the number stays hijacked is time to reset another account, so recognizing the pattern early can be the difference between a scare and a cleaned-out balance.

Cutting the phone number out of the security chain

The most effective defense is to stop relying on text messages as a second factor wherever a stronger option exists. Authenticator apps that generate codes on the device itself, and physical security keys, cannot be intercepted by someone who merely controls the phone number, because the secret never travels over the cellular network. Moving high-value accounts, especially email, banking, and crypto, onto those methods removes the payoff a SIM swap is designed to capture.

Carrier-level protections add another layer. Most major providers now let customers set a separate account PIN or port-freeze that must be supplied before a number can be transferred, and the FBI encourages using them along with not oversharing personal details that make impersonation easier. Keeping a phone’s recovery options current, and treating any unexpected “your SIM has been updated” message as an emergency, further shrinks the attacker’s opening.

Anyone who suspects a swap in progress should contact the mobile carrier immediately to reclaim the number, then change passwords from a secure device and alert their bank. The FBI directs victims to report the crime to the IC3, which feeds the case data that agencies use to track the networks behind these attacks.

This article was researched and drafted with the assistance of AI and reviewed before publication.


More from Morning Overview