Established by a former federal prosecutor · 20+ years prosecutorial experience · $12.5B lost to fraud in 2024 (FTC)
The Fraud CodexScam Intelligence
Live Threats
NewPig-butchering scams estimated to have stolen $75B globallyAlertIRS impersonation scams surge this 2026 filing seasonNewFake Coinbase support calls reported nationwide
Identity Theft·July 12, 2026

SIM Swap Attack Prevention: Stop Hijackers Cold

SIM swap attacks cost U.S. victims $26M in 2024. Learn how criminals hijack your phone number, the warning signs, and proven steps to prevent SIM swapping.

SIM Swap Attack Prevention: Stop Hijackers Cold
● Interactive SimulationText message
"
"Verizon Support"
+1 (555) 014-9982
VERIZON ALERT: We detected unusual activity on your account. Your SIM card will be deactivated in 30 minutes unless you verify your identity. Reply VERIFY now.

Your phone number is more than a way for friends to reach you — it is the master key to your entire digital life. Bank accounts, email inboxes, cryptocurrency wallets, and corporate VPNs all rely on it to verify your identity. SIM swap fraud exploits that trust with devastating efficiency. According to the FBI's Internet Crime Complaint Center (IC3), U.S. victims reported nearly $26 million in losses from SIM swapping in 2024 alone — an average of more than $26,400 per victim. Globally, the picture is even grimmer: the UK's fraud prevention service Cifas recorded a staggering 1,055% surge in unauthorized SIM swap cases in the same year. This is not a niche cybercrime. It is an industrialized, high-margin attack that is accelerating — and every person with a phone number is a potential target.

What Is a SIM Swap Attack and How Does It Work?

A SIM swap attack — also called SIM hijacking or SIM splitting — occurs when a criminal convinces your mobile carrier to transfer your phone number to a SIM card under their control. The attack exploits a completely legitimate feature of the telecommunications industry: mobile number portability. Fraudsters begin by harvesting your personal information. They may purchase your data from dark-web breach marketplaces (more than 7 billion credentials were exposed in 2024 alone), scrape details from your social media profiles, or use phishing emails to trick you into surrendering your account PIN or security answers. Armed with your name, address, date of birth, and the last four digits of your Social Security Number, an attacker calls your carrier's customer service line and claims to be you — perhaps reporting a lost or damaged phone and requesting a new SIM card. Once the swap is approved, your real phone loses all network service immediately. The attacker's device begins receiving every call and text message intended for you — including the one-time passcodes that guard your bank account, email, and crypto exchange. Within minutes, they can reset passwords, drain accounts, and lock you out of your entire digital identity. Increasingly, attackers are also bribing carrier store employees directly, cutting out the social engineering step entirely. The rise of eSIM technology has made things worse: carriers now allow number activation via QR code, which industry analyses from early 2025 show has slashed the attack cycle from hours to under five minutes.

Warning Signs to Watch For

The earliest and most reliable warning sign of a SIM swap in progress is sudden, unexplained loss of cell service — no calls, no texts, no mobile data — on a device that was working moments before. This happens because your number has just been moved to the attacker's SIM card. A second alert to watch for is an unexpected notification from your carrier stating that your SIM card has been activated on a new device. Other red flags include: receiving alerts that your account password or email address was changed when you made no such request; being locked out of online banking or email accounts without explanation; seeing unfamiliar login attempts or authentication codes arrive on secondary devices; and noticing charges or transfers on your financial accounts you did not authorize. Because 90% of SIM swap attacks in some jurisdictions occur without any direct contact with the victim, many people have no warning at all until the damage is done. High-value targets — cryptocurrency investors, business executives, and anyone with significant digital assets — are disproportionately singled out, but anyone can be victimized.

How to Protect Yourself

Prevention requires action on multiple fronts — from your carrier account to your authentication habits. First and most critically, contact your mobile carrier today and enable every available account security feature. Major U.S. carriers offer dedicated anti-SIM-swap protections: Verizon's 'Number Lock,' AT&T's 'Extra Security,' and T-Mobile's 'SIM Protection' all require in-person verification or a special PIN before any SIM change can be processed. Ask your carrier to add a port freeze or transfer PIN to your account. Second, eliminate SMS-based two-factor authentication wherever possible. CISA has explicitly advised consumers not to use SMS as a second factor for authentication, citing its lack of encryption and vulnerability to interception. Replace SMS codes with an authenticator app (such as Google Authenticator or Authy) or, better yet, a hardware security key (such as a YubiKey or Titan Key). These physical tokens cannot be replicated by a SIM swap — an attacker would need to physically steal the device. Third, minimize your public digital footprint. Avoid posting your phone number, birthday, or other personal identifiers on social media, as attackers routinely harvest this data to pass carrier identity checks. Use unique, strong passwords for every account and store them in a password manager, so a single compromised credential cannot cascade into a full account takeover. Finally, consider moving critical accounts — especially email and financial services — to authentication methods that are entirely independent of your phone number. If your email password can be reset via an SMS code, you remain vulnerable even on platforms that don't use SMS directly.

What to Do If You're Targeted

Speed is everything. If your phone abruptly loses service or you receive an unexpected SIM-change notification, act immediately. Call your carrier's fraud line from a different phone — a landline, a family member's cell, or a VoIP app — and report a potential SIM swap. Ask them to reverse the swap and freeze your account against further changes. Simultaneously, log in to your email, bank, and cryptocurrency accounts from a computer (not your compromised phone) and change your passwords. Move to app-based or hardware-key authentication on every account. Contact your bank's fraud department to place a hold on transactions and dispute any unauthorized withdrawals. File a complaint with the FBI's Internet Crime Complaint Center at ic3.gov and report the fraud to the FTC at ReportFraud.ftc.gov. If your Social Security Number was involved, place a credit freeze with all three major credit bureaus (Equifax, Experian, and TransUnion) to prevent new accounts from being opened in your name. Document everything: screenshots of alerts, call logs, and account activity will be essential if you need to pursue restitution. Remember that while the FCC adopted a landmark 2023 Report and Order requiring carriers to use secure authentication methods before processing any SIM change or port-out request, the compliance deadline was delayed, leaving enforcement timelines uncertain. Regulatory protections are improving, but consumer vigilance remains the most reliable line of defense.

SIM SwapIdentity TheftTwo-Factor AuthenticationPhone Fraud
SOURCES
  1. 01SIM Swap Scam Statistics 2025: Losses & PreventionDeepStrike (citing FBI IC3 2024 Internet Crime Report)
  2. 02SIM swap scams can be devastatingU.S. PIRG Education Fund
  3. 03FCC Announces Effective Compliance Date for SIM Swapping ItemFederal Communications Commission (FCC)
  4. 04A deep dive into the growing threat of SIM swap fraudThomson Reuters Institute