Skip to main content

Morning Overview

SIM-swap thieves can hijack your phone number and drain accounts in minutes

A phone that suddenly shows “No Service” for no clear reason is sometimes the first sign that a phone number has been stolen out from under its owner. SIM-swap fraud lets a criminal talk, bribe, or trick a mobile carrier into moving a target’s number onto a SIM card the criminal controls, and once that happens, every verification code meant to protect a bank or email account starts arriving on the thief’s device instead. The takeover can unfold in well under an hour, long before most victims realize their phone has gone silent, and by the time they notice, several accounts may already be compromised.

How Carriers Get Tricked Into Porting a Number

The attack rarely involves cloning a physical chip or any special hardware at all. Instead, a scammer gathers enough personal details, such as a birth date, a home address, or the last four digits of a Social Security number, usually harvested from a data breach, a phishing message, or information sold on criminal forums. The fraudster then calls or messages a carrier’s support line posing as the account holder and claims a phone was lost, stolen, or damaged, and that the number needs to be activated on a new SIM.

Some versions of the scheme skip the phone call entirely and instead bribe or recruit an employee inside a call center or retail store, since a cooperative insider can approve a swap in seconds without triggering standard identity checks. Carriers have tightened verification steps over the past several years by adding callback confirmations and photo-ID requirements, but the human step in the process remains the weakest link in an otherwise automated system.

Why a Phone Number Guards So Many Accounts

Phone numbers became an accidental master key because so many services lean on text-message codes for two-factor authentication, a practice that spread quickly because it was cheaper and simpler for companies to implement than dedicated authentication apps. According to Wikipedia’s overview of SIM-swap scams, a password reset, a new-device login, and a wire-transfer approval often all route through the same six-digit text sent to the same number, which means whoever controls that number effectively controls the reset process for every linked account.

A captured email account tends to unlock everything else in turn, since email is the fallback recovery method for banking apps, cryptocurrency exchanges, and social media logins. The damage compounds further because most people reuse one phone number across dozens of separate accounts built up over years, so a single successful swap can cascade into a full identity takeover rather than one stolen login, often within the same sitting.

The Minutes That Matter Once the Swap Happens

Once the number moves, the original phone loses signal immediately, which is often the only warning a victim gets before money starts moving elsewhere. Attackers work quickly precisely because that dead-zone window is short: carriers and banks eventually flag unusual account activity, and a victim who still has internet access through Wi-Fi can sometimes log into a banking app and freeze transfers before serious damage is done, provided the alert comes fast enough.

Cryptocurrency accounts are especially exposed in this window because digital-asset transfers are typically irreversible once confirmed on a blockchain. That irreversibility is part of why crypto holders have been disproportionately targeted in a string of widely reported SIM-swap cases over the past decade, including lawsuits filed by investors against major carriers after attackers drained wallets within minutes of gaining control of a number.

Who Ends Up in the Crosshairs

Attackers tend to prioritize targets who are visibly active on social media discussing cryptocurrency holdings, hold recognizable usernames on trading platforms, or work in roles with access to valuable accounts, since research into a victim’s public footprint makes the impersonation call to a carrier easier to pull off convincingly. Ordinary account holders are not exempt, however, since large batches of stolen personal data from unrelated breaches get tried against carriers indiscriminately, with no advance research required for a scammer working through a purchased list.

Older adults and people who rely heavily on a single phone number for banking, medical portals, and government benefit accounts face a particular version of the risk, since the number of interconnected accounts tied to that one number tends to be larger and more consequential to lose access to all at once.

Warning Signs Before and During an Attack

A sudden loss of cell signal with no explanation, an unexpected SIM-update notification from the carrier, or password-reset emails that were never requested are the clearest signals an attack is already underway. Any of these should prompt an immediate call to the carrier from a different phone or landline, followed by a check of financial accounts for unauthorized logins or pending transfers that need to be stopped.

Delaying that call tends to be the costliest mistake, since attackers frequently move through several accounts back to back once a number is under their control, working down a list of services tied to the same email address before the original owner regains access or a bank flags anything unusual.

Carrier Locks and Authenticator Apps That Blunt the Attack

Most major carriers now offer a port-out PIN or an account-level lock that must be provided before any SIM change is approved, and enabling that setting closes off the easiest version of the scam. It will not stop an insider-assisted swap, but it removes the simplest social-engineering path that most attackers rely on when targeting a random or opportunistic victim rather than a specifically chosen one.

Replacing text-message codes with an authenticator app or a physical security key removes the phone number from the equation almost entirely, since those codes generate locally on a device rather than traveling over the cellular network. The broader lesson tracks with how identity theft has evolved over time: criminals gravitate toward whatever single point of failure protects the most accounts at once, and for a growing number of people, that point of failure is the ten-digit number everyone assumes is safe.

This article was produced with the assistance of AI and reviewed by Morning Overview editors.


More from Morning Overview