A phone number is more than a way to place calls; for millions of people it is the key that unlocks bank logins, email accounts and social media through text-message verification codes. That is exactly why criminals target it. In an attack known as SIM swapping, a thief convinces a wireless carrier to move a victim’s number onto a SIM card the thief controls, hijacking every code and reset link that follows and, in the worst cases, draining financial accounts within minutes.
How a SIM swap hands a number to a stranger
The attack exploits the carrier’s own account-recovery process. Posing as the legitimate customer, a scammer contacts the wireless provider and claims the phone was lost or the SIM damaged, then asks that the number be activated on a new SIM in the attacker’s possession. To pass the provider’s identity checks, the criminal often draws on personal details gathered from data breaches, social media or earlier phishing messages.
Once the switch takes effect, the victim’s own handset loses service while calls and texts begin flowing to the attacker’s device. The Federal Trade Commission describes how, armed with a hijacked number, a thief can then receive the verification codes needed to log into accounts, change passwords and lock the rightful owner out entirely.
Why text-message codes are the weak link
The damage is possible because so many services treat a phone number as proof of identity. When a bank or email provider sends a one-time code by text to confirm a login or a password reset, whoever controls the number receives that code. A SIM swap quietly redirects the entire second factor that was supposed to keep intruders out.
The financial stakes are what make the attack so lucrative. Criminals frequently seize a number specifically to reach bank, brokerage and cryptocurrency accounts, where a captured code can authorize a transfer that clears before the owner realizes service has dropped. Targets known to hold digital assets have lost substantial sums in the narrow window between a swap and its discovery, which is why the tactic has drawn organized criminal interest.
That dependence turns a single point of failure into a cascade. After capturing codes for an email account, an attacker can often reset the passwords for other services linked to that address, moving from the phone number to the inbox to bank and investment accounts. Because the tactic can defeat security that consumers assume is protecting them, regulators treat it as a serious and fast-moving threat.
Warning signs that a number has been hijacked
The clearest signal is a sudden, unexplained loss of cellular service. If a phone abruptly shows no signal, cannot make calls or send texts, and a restart does not restore it, the number may have been ported to another device. Notifications about account changes the owner did not request, or messages saying a SIM change is being processed, are further red flags.
Speed matters once those signs appear. The FTC advises anyone who suspects a swap to contact the wireless carrier immediately to reclaim the number, then change the passwords on email, banking and other sensitive accounts. Reviewing recent activity on financial statements for unauthorized charges or transfers helps limit the fallout while control is restored.
Steps that make an account harder to steal
Several defenses reduce the odds of a successful swap. The FTC recommends setting a separate PIN or passcode on the wireless account itself, a barrier a caller must clear before any number transfer, and limiting the personal information shared publicly online, since attackers assemble those details to impersonate customers. Treating unsolicited calls, emails and texts requesting personal data as potential phishing is part of the same discipline.
Perhaps the most effective change is moving away from text messages for account security. Because text verification can be redirected by a SIM swap, security experts urge consumers to protect important logins with an authentication app or a physical security key instead, methods that stay tied to a device rather than a phone number. Regulators have also pushed the industry itself to help: under rules the Federal Communications Commission adopted to curb SIM-swap and port-out fraud, wireless carriers must use more secure methods to authenticate customers before moving a number and must notify account holders whenever a SIM change or transfer is requested.
Acting quickly to contain the damage
Even with precautions, no safeguard is absolute, so knowing the recovery steps ahead of time is valuable. Regaining the number through the carrier is the first priority, because it cuts off the attacker’s stream of incoming codes. From there, resetting passwords, enabling stronger authentication and alerting banks to watch for fraud reestablishes control over the accounts the number was protecting.
Reporting the crime also helps. Victims can notify their financial institutions, file reports with law enforcement, and alert the credit bureaus so that fraudulent accounts opened with stolen information can be flagged. For consumers, the underlying lesson is that a phone number deserves the same guarding as a password, because in the wrong hands it can open nearly everything else.
Preparation blunts the panic if it happens. Setting a carrier account PIN in advance, knowing the provider’s fraud-line number, and keeping alternate contact methods for critical accounts all shorten the time it takes to respond. The faster a hijacked number is reclaimed and its linked passwords reset, the less a thief can accomplish with it.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview