Skip to content
Breachfolio
A phone number being silently reassigned from one device to another — SIM swap and port-out fraud
CYBERSECURITY · FUNDAMENTALS

SIM swap attacks, explained.

How port-out and eSIM-transfer fraud actually works, why phone numbers became the weak link in account recovery, and how to lock a number down.

July 22, 202611 min read

Nobody hacks your phone to pull off a SIM swap. They convince your carrier to hand your phone number to them instead — no malware, no cracked encryption, just a well-told story to a support agent or a few clicks in a self-service portal. Once that transfer completes, every call and text meant for you, including the one-time codes half the internet uses to prove it's really you, goes straight to the attacker. This article explains the actual mechanism behind SIM swap and port-out fraud, why the phone number became such a heavily relied-upon identity anchor in the first place, how attackers get carrier support to cooperate, and what meaningfully reduces the risk.

SIM swap vs SIM cloning: a distinction worth making precisely

These get confused constantly, and the difference matters. SIM cloning is the older, largely obsolete attack: physically extracting the cryptographic keys from an older-generation SIM card and copying them onto a second card, which requires hands-on access to the physical SIM and specialized equipment. It doesn't scale, and modern SIM security (particularly with eSIM and current-generation authentication) has made it far harder to pull off. A SIM swap — sometimes called port-out fraud when it moves the number to a different carrier, or SIM-jacking — is a completely different attack surface: it requires no physical access to your card or device at all. It's a fraudulent administrative change made at the carrier level, initiated remotely by convincing a human or a self-service system that the attacker is you. That's what makes it dangerous at scale — it's a social and process attack, not a cryptographic one.

How a SIM swap actually works, step by step

The mechanism is straightforward once you see it laid out, which is exactly why it remains effective:

  1. Reconnaissance. The attacker collects enough of your personal information to sound convincing — full name, date of birth, billing address, the last four digits of an ID, and answers to common security questions. This comes from data breaches, OSINT on social media, or a prior phishing message that harvested it directly.
  2. Contact with the carrier. The attacker calls support, uses live chat, or — increasingly — simply logs into the carrier's own self-service app or website, impersonating you with the details gathered in step one.
  3. The transfer request. They request either a SIM replacement ("I lost my phone, activate this new SIM"), a port-out to a different carrier, or, on modern networks, an instant eSIM transfer to a device they control — no physical SIM card ever needs to change hands.
  4. Deactivation and handover. The carrier deactivates your SIM and activates the attacker's. Your phone silently loses cellular service — calls fail, texts stop arriving — while the attacker's device now receives everything addressed to your number.
  5. The account-takeover cascade. With your number in hand, the attacker triggers "forgot password" flows on email, banking, cryptocurrency exchanges, and social media, intercepting the SMS one-time codes or callback verifications those services send to confirm identity. Each account taken over can unlock the next — email access alone often cascades into dozens of other services.

The eSIM piece is worth calling out specifically because it changes the friction profile of the whole attack: many carriers now allow a customer to activate a new eSIM instantly via an app or a QR code, with no need to visit a store or wait for a physical card to ship. That convenience is exactly what an attacker who has already social-engineered their way past identity verification benefits from — the entire transfer can complete in minutes, end to end, without ever touching a physical SIM tray.

Why phone numbers became the weak link in account recovery

None of this would matter much if phone numbers weren't load-bearing for so much of online identity. SMS one-time passcodes became the default second factor for a simple reason: nearly everyone already has a phone number, and texting a code required no app download, no hardware purchase, and almost no user education. That ubiquity is exactly what turned the phone number into a near-universal identity anchor — the same number often verifies your bank, your email, your social media, and your exchange account, all independently trusting that whoever controls that SIM is you.

The problem is that a phone number was never designed to function as a cryptographic secret. It's a service address your carrier can reassign on request, by design — that's precisely what happens every time someone legitimately switches carriers or replaces a lost phone. SMS OTP quietly borrowed the convenience of that reassignable address and treated it as proof of identity, which means the security of dozens of unrelated accounts now rests on the weakest link in that chain: a support process at a company whose job is customer service, not identity assurance. Compromise the number once, and you inherit the recovery path for everything downstream that trusts it.

How attackers socially engineer carrier support

The exploitation step is a straightforward application of the pretexting and vishing techniques covered in our broader social engineering explainer: the attacker adopts the identity of the account holder and leans on urgency ("I'm about to board a flight and need this fixed now") and authority (a confident, prepared caller who already has "your" account details ready) to move a support agent past careful verification. Weak knowledge-based authentication makes this easier than it should be — security questions like a mother's maiden name or the last four digits of a Social Security number are frequently answerable from a data breach, a public records search, or a prior phishing haul, which means the "secret" the carrier is checking against was never secret at all. In a smaller number of documented cases, attackers have gone further and directly bribed or colluded with carrier or retail-store employees to push the transfer through, bypassing customer-facing verification entirely.

The scale of the risk was demonstrated publicly in August 2019, when Twitter's own CEO at the time, Jack Dorsey, had his personal Twitter account taken over via a SIM swap against his mobile carrier — a real, well-documented case that made clear the technique works regardless of how technically sophisticated the target is, because it doesn't attack the target's technical defenses at all. It attacks the process standing between "I say I'm you" and "the carrier believes it."

Who attackers target, and why

SIM swapping is labor-intensive per victim — it requires research and a live social engineering interaction, not a mass-mailed link — so attackers are selective about targets. Cryptocurrency holders are a frequent target because crypto exchange accounts, once accessed, often allow irreversible transfers with no chargeback mechanism, unlike a credit card dispute. High-profile individuals — executives, journalists, and public figures — are targeted both for direct financial access and for the value of hijacking a recognizable social media account. And anyone whose email address is discoverable alongside a leaked phone number in a prior data breach becomes a plausible target simply because the reconnaissance step is already half-done for the attacker. None of this means low-profile individuals are safe; it means the attacker's economics favor targets where the payoff clearly outweighs the manual effort of a live pretext call.

Mitigations: carrier-side and individual

Regulators have started treating this as a carrier accountability problem rather than purely a consumer-awareness one. In November 2023, the US Federal Communications Commission adopted rules requiring wireless carriers to use secure methods to verify a customer's identity before processing a SIM swap or a number port-out, and to notify the account holder immediately when such a request is made — a direct response to how often weak carrier-side verification was the actual point of failure. That regulatory pressure reinforces what security-conscious users can already do for themselves:

  • Set a carrier PIN or passcode. Most major carriers let you add a separate passcode that must be provided, in person or verified independently, before any SIM swap, port-out, or account change — ask specifically, since it is often opt-in rather than default.
  • Enable a port-freeze or number-lock feature if your carrier offers one, which blocks porting or SIM changes entirely until you explicitly disable it.
  • Avoid security questions with discoverable answers. Treat "security question" answers as passwords — use unrelated, unguessable strings, not real biographical facts that can be researched or pulled from a breach.
  • Watch for a sudden loss of signal. An unexpected "no service" or "SOS only" indicator, especially right after unrelated account-recovery emails, is one of the few real-time warning signs a swap is in progress.
  • Decouple critical accounts from your number. Use a recovery email that doesn't itself rely only on SMS recovery, so losing your number doesn't cascade into losing your email too.

Moving away from SMS-based 2FA

The most durable fix isn't hardening the phone number — it's removing it from the authentication chain entirely wherever possible. An authenticator app generates time-based one-time codes (TOTP) locally on your device using a shared secret established at setup; nothing travels over the cellular network, so a SIM swap has nothing to intercept. A hardware security key goes further, using public-key cryptography and a physical challenge-response step that can't be phished or redirected at all, even if an attacker has your password and your phone number both. NIST's digital identity guidelines (SP 800-63B) reflect this shift directly: they restrict SMS as an out-of-band authenticator precisely because of scenarios like SIM swapping, and recommend authenticator apps or hardware keys instead. For the underlying cryptographic mechanics that make TOTP codes and hardware-key challenge-response resistant to this kind of interception, see our cryptography basics article.

If a swap has already happened

The signs are usually unmistakable once you know to look for them: your phone suddenly shows no service or "SOS only" with no obvious cause, you stop receiving any calls or texts, or you receive unexpected password-reset or login notifications on email you can still access from another device. The response sequence that limits damage fastest runs in a specific order, because sequence matters here: first, contact your carrier through an independent channel — a different phone, a computer, or in person — to report the fraud and request the number be locked or reversed immediately. Second, and in parallel if possible, secure your email account from another device, since email is usually the pivot point for everything else; change its password and revoke active sessions. Third, work outward from email to every other account that trusted the compromised number or email — banking, exchanges, social media — checking recent activity and rotating credentials as you go. Finally, replace any SMS-based two-factor authentication you find along the way with an authenticator app or hardware key, so the same number can't be used against you again.

Comparing the second factors

Not all "two-factor authentication" carries the same resistance to this attack, and the difference comes down entirely to what the second factor is actually bound to:

Second factorWhat it's bound toResistant to a SIM swap?
SMS one-time codeYour phone number, which the carrier can reassignNo — this is the exact attack surface a SIM swap targets
Voice-call callback codeYour phone number, same as SMSNo — equally vulnerable once the number is reassigned
Authenticator app (TOTP)A secret stored locally on your specific device at setupYes — the cellular network is never involved in generating the code
Hardware security key (FIDO2/WebAuthn)A private key that never leaves the physical deviceYes — also resistant to real-time phishing, not just SIM swaps

The pattern is consistent: anything that ultimately depends on "can this person receive something at this phone number" inherits every weakness of the carrier's identity-verification process, no matter how the code itself is generated or how many digits it has. Anything bound instead to a specific device or cryptographic key sidesteps the carrier entirely — which is exactly why moving critical accounts off SMS is the single highest-leverage step available to an individual, more impactful than almost any other password hygiene habit.

The takeaway

A SIM swap is not a hack of your phone — it's a successful social engineering attack against your carrier's support process, exploiting the fact that a phone number was never built to be a secure identity anchor in the first place. The fix that actually holds is twofold: make the swap itself harder by locking the account at the carrier level with a PIN or port-freeze, and make the swap worthless to an attacker by moving your important accounts off SMS-based recovery and onto an authenticator app or hardware key that a stolen phone number can't touch.

Frequently asked questions

What is a SIM swap attack?
A SIM swap attack is when someone convinces your mobile carrier to transfer your phone number to a SIM card or eSIM they control, usually by impersonating you through social engineering rather than any technical hack of your phone. Once the transfer completes, your real SIM stops working, and every call and text meant for your number — including one-time passcodes used to reset passwords — now goes straight to the attacker, who uses that access to take over email, banking, and other accounts tied to the number.
How do attackers get a carrier to transfer my number?
Mostly through pretexting and social engineering aimed at carrier support staff or self-service portals: attackers gather your personal details from data breaches, OSINT, or a prior phishing attempt, then call or message support impersonating you, supplying just enough correct information (name, address, last four of an ID, answers to weak security questions) to pass identity checks. Some attacks also target the carrier's own employees directly, or exploit weak online account-recovery flows that require less verification than a phone call would.
Is SIM swapping the same as SIM cloning?
No, and the distinction matters. SIM cloning is a largely obsolete technical attack that physically duplicates an older SIM card's cryptographic keys, requiring hands-on access to the card and specialized equipment against outdated authentication schemes. A modern SIM swap involves no physical card cloning at all — it is a fraudulent, remotely executed account change at the carrier level, initiated through social engineering or a compromised support process, which is exactly why it scales so much better for attackers than cloning ever did.
How do I protect myself from SIM swap fraud?
Set a unique carrier PIN or passcode that is required before any SIM swap, port-out, or account change, and ask specifically whether your carrier offers a port-freeze or number-lock feature. Move critical accounts — email, banking, cryptocurrency exchanges — away from SMS-based one-time codes toward an authenticator app or a hardware security key, since those aren't affected if your number is stolen. Watch for a sudden, unexplained loss of cellular signal or "no service" indicator as a possible live warning sign, and use a recovery email that is not itself protected only by your phone number.
Why is SMS-based two-factor authentication considered weak?
SMS one-time codes rely entirely on the assumption that only you control your phone number, but a phone number is a service your carrier can reassign on request — it was never designed as a cryptographic secret. A successful SIM swap defeats SMS-based MFA completely, without the attacker needing your password's second factor to be technically strong at all. NIST's digital identity guidelines (SP 800-63B) restrict SMS as an out-of-band authenticator for this reason and recommend authenticator apps or hardware security keys, which bind the second factor to a specific device or cryptographic key rather than a number a carrier can move.