A stolen password is bad enough, but there is a quieter form of theft that can hand a criminal the keys to a victim’s entire digital life without ever touching their phone. In a SIM swap, a fraudster convinces a wireless carrier to move someone’s phone number onto a device the criminal controls. From that moment, the calls, texts and security codes meant for the victim flow straight to the attacker, who can use them to reset passwords and empty bank and cryptocurrency accounts, often before the target realizes anything is wrong.
The attack is insidious precisely because it exploits the phone number, a piece of identity that most people treat as permanent and that countless online services use to verify who is logging in. Turning that trust against the account holder is the whole point.
How a SIM swap actually works
The mechanics are more about manipulation than hacking. The FBI’s Internet Crime Complaint Center has warned that criminals typically pull off SIM swaps through social engineering, insider help or phishing. In the most common version, the attacker gathers personal details about a target, then calls the carrier posing as that customer and claims a lost or damaged phone, persuading a representative to transfer the number to a new SIM card. In other cases, criminals bribe carrier employees to make the switch directly, or trick staff into installing malware that lets them alter accounts. However it is done, the result is the same: the victim’s phone abruptly loses service while the number goes live on the criminal’s device.
Why intercepting text messages is so dangerous
Control of the number matters because so much of online security still runs through it. Once texts are diverted, the attacker triggers “forgot password” and account-recovery flows on email, banking and investment services, then receives the one-time codes those services send by SMS. With the codes in hand, the criminal resets passwords and locks the real owner out. The FBI has documented substantial losses from the scheme, with reported thefts running into the tens of millions of dollars in a single year, and cryptocurrency holdings a favorite target because transfers are fast and effectively irreversible. The speed is what makes it devastating; by the time a victim notices the dead phone and investigates, funds may already be gone.
The federal rules meant to slow it down
Regulators have moved to make the underlying transfer harder to abuse. In 2023 the Federal Communications Commission adopted new consumer-protection requirements, and the rule protecting consumers from SIM-swap and port-out fraud directs wireless carriers to use secure methods of verifying a customer’s identity before moving a number to a new device or a new provider. It also requires carriers to notify customers immediately whenever a SIM change or port-out is requested, giving a potential victim a chance to intervene before the switch completes. An accompanying FCC summary of the adopted rules framed the measures as baseline safeguards for cell phone accounts across the industry, though officials acknowledged the rules reduce the risk rather than eliminate it.
Steps that make an account harder to steal
Individuals can add protection the carrier rules do not cover on their own. The FBI recommends replacing text-message codes with stronger multi-factor authentication wherever possible, such as authenticator apps, hardware security keys or biometrics, since those cannot be intercepted by hijacking a phone number. It also advises setting a unique PIN or passcode on the mobile account so a stranger cannot authorize changes, using distinct passwords across services, and not broadcasting personal or financial details, including cryptocurrency ownership, on social media where attackers harvest the information they need to impersonate a target.
What to do the moment service disappears
Recognizing an attack in progress can limit the damage. A phone that suddenly shows no signal for no clear reason, or an unexpected alert that account details have changed, can be the first sign of a swap. The FBI advises contacting the mobile carrier immediately to reclaim the number, then changing passwords on important accounts and alerting banks and other financial institutions to watch for suspicious logins and transfers. Victims are also urged to report the crime to law enforcement and to the Internet Crime Complaint Center, both to seek help and to feed the data that shapes future defenses. Acting within minutes rather than hours is often the difference between a frightening scare and a drained account.
The scam also illustrates a broader weakness in how digital identity is verified. For years, companies leaned on the phone number as a convenient stand-in for proof of identity, sending confirmation codes by text because nearly everyone has a mobile phone. SIM swapping exposes the flaw in that assumption: a phone number is not a person, and control of it can be transferred by a persuasive phone call. Security specialists increasingly urge moving high-value accounts off text-based verification entirely, favoring app-based codes or physical keys that stay tied to a device rather than a number. Until that shift is widespread, the phone number will remain a tempting single point of failure that determined criminals know how to exploit.
This article was produced with AI assistance and reviewed by the Morning Overview editorial team.
More from Morning Overview
- Hunters pulled a 19-foot python from the Everglades at 1 a.m., the longest ever recorded in Florida
- Ancient DNA suggests Neanderthals and humans mixed for reasons that had nothing to do with attraction.
- Rare footage shows an orca tearing open a whale shark to feast on its liver
- A slab of a Hawaiian volcano is slowly sliding toward the sea