Established by a former federal prosecutor · 20+ years prosecutorial experience · $12.5B lost to fraud in 2024 (FTC)
The Fraud CodexScam Intelligence
Live Threats
NewPig-butchering scams estimated to have stolen $75B globallyAlertIRS impersonation scams surge this 2026 filing seasonNewFake Coinbase support calls reported nationwide
Identity Theft·August 12, 2026

SIM Swap Attacks: How to Protect Yourself

SIM swap fraud cost U.S. victims nearly $26 million in 2024. Learn how the attack works, the warning signs, and how to stop SIM hijacking before it happens.

SIM Swap Attacks: How to Protect Yourself
● Interactive SimulationPhone call (then text)
U
Unknown Caller
+1 (555) 014-9823
Hi, this is Marcus from Verizon Account Security. We've detected a suspicious login attempt on your account and need to verify your identity before it's locked.

Your phone number is no longer just a way to make calls — it is a skeleton key to your entire digital life. SIM swap fraud, also known as port-out fraud or mobile account takeover, is one of the most financially devastating identity theft schemes in operation today. In 2024 alone, the FBI's Internet Crime Complaint Center tracked nearly $26 million in reported U.S. losses from SIM swapping — and that figure excludes lost wages, business disruption costs, and the countless cases that go unreported. Understanding how this attack works and how to stop it is no longer optional. It is essential.

What Is SIM Swap Fraud and How Does It Work?

SIM swap fraud occurs when a criminal convinces your mobile carrier to transfer your phone number to a SIM card they control, exploiting the legitimate feature of mobile number portability that exists for lost or damaged phones. Once the swap is complete, your phone loses all network connectivity, and the attacker begins receiving every call and text message intended for you — including one-time passwords and account verification codes used for two-factor authentication (2FA). From there, they can reset passwords, drain bank accounts, and empty cryptocurrency wallets in minutes.

What makes this attack so effective is its simplicity. The attacker typically begins by harvesting your personal details — full name, address, date of birth, and the last four digits of your Social Security number — through phishing campaigns, data breaches, or a quick scan of your social media profiles. Armed with that information, they call your carrier's customer support line or walk into a retail store and impersonate you. A Princeton University study found that major U.S. carriers had an 80% first-attempt success rate for fraudulent SIM swap requests, largely because carriers relied on weak, knowledge-based authentication that fraudsters could easily bypass. No coding skills or sophisticated malware are required — just a prepaid SIM card and a convincing story.

Warning Signs to Watch For

The attack often moves faster than victims can react, but there are clear signals that your number has been hijacked. The most immediate red flag is a sudden, unexplained loss of cellular service — your phone displays 'No Service' or 'SOS Only' even in an area with normal coverage. Shortly after, you may receive an alert from your carrier that your SIM card has been activated on a new device. You might also find yourself locked out of email, banking, or cryptocurrency accounts, or begin receiving password-reset notifications you did not initiate.

Before the swap even happens, attackers may probe you with social engineering calls or phishing texts designed to extract your account PIN or carrier security questions. Be especially alert if you receive an unsolicited call from someone claiming to be your mobile carrier asking to 'verify your account.' Legitimate carriers will not call you out of the blue to request your PIN or move your service to a new device. Additionally, if you notice unfamiliar charges on your mobile bill or discover that a port-out request has been submitted for your number, treat it as an emergency and act immediately.

How to Protect Yourself

Defense against SIM swap fraud requires action at multiple layers — your carrier, your online accounts, and your personal data hygiene.

**Lock Down Your Carrier Account.** Contact your mobile provider and set a unique, strong account PIN or passcode that must be verified in person or by phone before any SIM change or port-out request is approved. Many carriers also offer a 'port freeze' or 'number lock' feature that prevents any transfer of your number without your explicit, in-person authorization. Enable it. The FCC's 2024 Report and Order now requires wireless providers to use secure multi-factor authentication before any number reassignment and to immediately notify customers when a SIM change is requested — ask your carrier whether these protections are active on your account.

**Ditch SMS-Based Two-Factor Authentication.** Federal agencies including the FBI and CISA have explicitly advised against using SMS text messages as a second authentication factor, noting their lack of encryption and susceptibility to interception. Switch to an authenticator app — such as Google Authenticator, Authy, or Microsoft Authenticator — or better yet, use a hardware security key (like a YubiKey) for your most sensitive accounts. These methods are tied to a physical device, not your phone number, and cannot be hijacked through a carrier.

**Minimize Your Data Footprint.** Attackers fuel SIM swaps with personal data scraped from breaches and social media. Avoid posting your full birthdate, hometown, or phone number publicly. Opt out of data broker sites and use unique, complex passwords managed by a reputable password manager. Enable account alerts on all financial and email accounts so any login or change triggers an immediate notification.

What to Do If You're Targeted

Speed is everything. If your phone suddenly loses service or you suspect a SIM swap is in progress, take these steps immediately:

1. **Call your carrier from another device.** Use a landline, a family member's phone, or a Wi-Fi-based call to reach your carrier's fraud department. Demand that they reverse the unauthorized SIM swap and lock your account against further changes.

2. **Secure your critical accounts.** Change passwords on your email, banking, and any cryptocurrency accounts from a secure device. Remove your phone number as a recovery option where possible and replace SMS-based 2FA with an authenticator app immediately.

3. **Contact your financial institutions.** Alert your bank and any investment platforms. Request that they flag your account for suspicious activity and, if funds have been moved, initiate a fraud claim without delay.

4. **File reports with federal authorities.** Submit a complaint to the FBI's Internet Crime Complaint Center at IC3.gov and file a report with the FTC at ReportFraud.ftc.gov. These reports help investigators track fraud rings and may support any financial recovery efforts.

5. **Monitor for follow-on fraud.** SIM swapping is often a gateway crime — a precursor to broader identity theft. Place a fraud alert or credit freeze with all three major credit bureaus (Equifax, Experian, and TransUnion) and monitor your credit reports closely for months after the incident.

SIM swap fraud is not a niche technical threat — it is a mass-scale identity crime that strips victims of their financial accounts, personal data, and digital identity in a matter of minutes. The good news is that with the right carrier-level locks and a move away from SMS-based authentication, you can make yourself a much harder target.

SIM SwapIdentity TheftTwo-Factor AuthenticationAccount Takeover
SOURCES
  1. 01A deep dive into the growing threat of SIM swap fraudThomson Reuters Institute
  2. 02SIM swap scams can be devastatingU.S. PIRG Education Fund
  3. 03DA 23-1148 Enforcement Advisory No. 2023-03Federal Communications Commission (FCC)
  4. 04SIM Swap Scam Statistics 2025: Losses & PreventionDeepStrike