
You've probably got two-factor authentication set up on your email, your bank, maybe your crypto wallet if you have one. It feels like a solid layer of protection – until you realize that layer often depends entirely on one thing: your phone number. SIM swapping is the attack that exploits exactly that assumption, and it's a big reason security experts have spent the last few years pushing people away from SMS-based verification.

At its core, SIM swapping is a form of identity theft where an attacker convinces a mobile carrier to transfer your phone number to a SIM card they control. Once that transfer happens, calls and texts meant for you – including one-time password codes used for two-factor authentication – go straight to the attacker's device instead of yours.
This isn't a technical hack in the traditional sense. There's no malware involved, no exploited software vulnerability. It's a social engineering attack aimed at a company's customer service process rather than at your phone itself, which is exactly why it's so hard to fully prevent from the user side alone.
The attack succeeds because phone numbers were never really designed to be a security credential – they were designed to route calls. Carriers built account recovery processes around convenience, letting customers who lose a phone quickly get a replacement SIM without excessive friction. Attackers exploit that same convenience, often armed with personal details gathered from data breaches, social media, or previous phishing attempts, to impersonate the account holder convincingly enough to pass a support rep's identity checks.
Once the number is redirected, the attacker has access to the single weakest link in most people's security setup: SMS-based two-factor authentication. Many people still use their phone number as the primary recovery method for email, banking, and social media accounts, which means a successful SIM swap can cascade into a full account takeover within minutes.
The financial incentive has scaled the problem too. Cryptocurrency accounts, in particular, have become a major target because crypto transactions are largely irreversible once completed, making a successful SIM swap far more lucrative for an attacker than in the past.
SIM swap attacks have hit high-profile targets over the years, including tech executives and crypto investors who lost significant sums after their phone numbers were hijacked and used to bypass account recovery on financial platforms. The FBI's Internet Crime Complaint Center has flagged SIM swapping as a growing category of reported fraud, with losses running into the hundreds of millions of dollars in recent reporting periods.
It's not just a problem for high-net-worth targets, though those cases get the most attention. Ordinary people have had their phone numbers hijacked to reset banking app passwords, drain payment apps, or take over social media accounts used for identity verification elsewhere.
The single most effective step is moving away from SMS as your two-factor authentication method wherever an alternative exists. Authenticator apps like Google Authenticator, Authy, or a hardware security key generate codes independent of your phone number, so a SIM swap doesn't give an attacker anything usable.
Beyond that, most major carriers now offer an account PIN or passcode specifically designed to prevent unauthorized SIM transfers – it's worth calling your carrier directly and setting this up rather than assuming it's on by default. Being cautious about how much personal information you share publicly also matters, since attackers often build a profile from social media details before ever contacting your carrier.
For financial and email accounts, checking whether phone-based recovery can be replaced or supplemented with an authenticator app or backup codes closes off one of the more common paths attackers use once they've taken over a number.
Regulators and carriers have started responding. The FCC introduced rules requiring wireless carriers to adopt stronger customer authentication before processing SIM changes, and more platforms are pushing users toward authenticator apps and passkeys instead of SMS codes as a default. That said, the fix is gradual, and SMS-based verification remains common enough across smaller services that the underlying risk isn't going away soon.
How do I know if I've been SIM swapped? The clearest sign is a sudden and total loss of cell service – no calls, texts, or data – without explanation. If that happens, contact your carrier immediately through a separate device or landline.
Is SIM swapping the carrier's fault? It's a shared responsibility. Carriers control the account verification process that gets exploited, but users who rely solely on SMS-based two-factor authentication and share extensive personal details publicly make the attack easier to pull off.
Are eSIMs safer than physical SIM cards? eSIMs don't eliminate the underlying risk, since the vulnerability lies in the carrier's account verification process rather than the physical SIM itself, though some carriers have added extra verification steps for eSIM transfers specifically.
FBI Internet Crime Complaint Center – SIM swapping fraud alerts – https://www.ic3.gov/
Federal Communications Commission – rules on SIM swap and port-out fraud protections – https://www.fcc.gov/news-events/headlines/2023/10/fcc-adopts-rules-protect-consumers-sim-swapping-port-out-fraud
CISA – guidance on multi-factor authentication and phishing-resistant methods – https://www.cisa.gov/secure-our-world/turn-mfa




















