Morning Overview

Thieves can hijack your phone number in minutes and drain accounts with a SIM swap

A phone number has quietly become a master key to a person’s digital life, which is exactly why criminals target it. In a scheme known as SIM swapping, a thief convinces or tricks a mobile carrier into transferring a victim’s number to a device the thief controls. Once the number moves, the attacker can intercept the security codes that guard email, banking, and other accounts, and the takeover can unfold in a matter of minutes.

How a SIM swap takes over a number

Every mobile number is tied to a subscriber identity that a carrier can reassign from one device to another, a normal process used when someone upgrades a phone or replaces a lost one. SIM swapping abuses that legitimate function. An attacker contacts the carrier posing as the victim, often armed with personal details gathered from data breaches or social media, and requests that the number be ported to a new SIM card or device.

If the carrier is persuaded, the victim’s phone abruptly loses service while the attacker’s device begins receiving all calls and texts meant for that number. The transfer is invisible to the victim until they notice their phone has gone dead, by which point control has already changed hands. The mechanics rely less on breaking technology than on convincing a human representative to complete an ordinary request for the wrong person.

Why capturing a number unlocks accounts

The reason a stolen number is so damaging lies in how account security is commonly built. Many services send a one-time code by text message as a second factor of authentication, a step meant to prove that a login attempt comes from the account’s real owner. When an attacker controls the phone number, those codes arrive on the attacker’s device instead.

Federal guidance from the FBI on common frauds and scams describes how seizing a phone number lets criminals bypass the very protections designed to stop unauthorized access. With the codes in hand, an attacker can reset passwords and walk into email, financial, and other sensitive accounts one after another, turning a security feature into a doorway.

The speed and the damage

What makes SIM swapping alarming is how quickly a single successful transfer can cascade. Email is often the linchpin, because control of an inbox allows password resets across nearly everything else linked to it. From there an attacker can move to bank and investment accounts, draining balances before the victim realizes what has happened. The sequence tends to run fastest where accounts are chained together, because each captured login supplies the leverage to seize the next.

The window to react is short. Because the takeover often begins with a phone silently losing service, the earliest sign may be missed calls, texts that never arrive, or a device that suddenly reads no signal. Recognizing that a dead phone can be a security emergency rather than a technical glitch is part of the defense, and the difference of a few minutes can determine how many accounts are reached.

Why a phone number became so valuable

The premise of the whole scheme is that the humble phone number now sits at the center of online identity. Services adopted text-message codes because nearly everyone carries a phone, making the method convenient and close to universal. That convenience is also its weakness: a factor tied to a number is only as secure as the carrier’s ability to keep that number with its rightful owner.

As more accounts leaned on text codes for verification, the payoff for stealing a number grew accordingly. A single phone line can be the gateway to email, banking, social media, and more, which is why criminals invest effort in impersonating a customer to a carrier. The value concentrated in one number is what justifies, from a thief’s perspective, the work of engineering a swap. And because the same handful of carriers guard numbers for millions of customers, a technique that reliably fools a support desk can be repeated against target after target, which is what turns an individual con into a scalable crime.

Steps that make a swap harder

There are ways to raise the barrier. Many carriers offer an account PIN or port-freeze that must be provided before a number can be transferred, which blocks the casual impersonation SIM swappers rely on. On the account side, replacing text-message codes with an authentication app or a physical security key removes the phone number from the login process, so a stolen number no longer yields the second factor.

Limiting the personal information available publicly also matters, since attackers assemble the details they use from breaches and social profiles. The less a stranger can learn about a target, the harder it is to convince a carrier they are the account holder. Because the impersonation leans on details a person may have shared without a second thought, tightening privacy settings and thinking twice before posting identifying information both narrow the opening.

What to do when a number goes dark

If a phone unexpectedly loses all service, the recommended response is to treat it as a possible SIM swap and contact the carrier immediately through another line to confirm whether the number has been transferred. Acting fast can shorten the time an attacker has to exploit intercepted codes.

The broader lesson from the guidance is that a phone number deserves the same protection as a password. Because so many accounts trust a text message as proof of identity, the number itself has become a security asset worth defending. Treating a sudden loss of service as a red flag, rather than a carrier glitch to shrug off, can be the difference between catching a swap in progress and discovering it only after the accounts are emptied.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview