What a SIM swap is
A SIM-swap scam occurs when someone persuades or compromises a mobile carrier into moving a victim’s phone number to another SIM or eSIM. Calls and text messages may then reach the attacker’s device.
Why the number matters
Phone numbers are often used for password resets, login codes and identity checks. Losing control of the number can therefore affect accounts beyond the mobile service itself.
Warning signs
- The phone unexpectedly loses cellular service
- A carrier message says a SIM or eSIM changed
- Password-reset or login alerts appear for unrelated accounts
- Calls or messages stop arriving while Wi-Fi still works
Reduce dependence on text messages
For important accounts, use passkeys, security keys or authenticator apps when available. Text-message codes can still be better than no MFA, but they depend on continued control of the phone number.
Protect the carrier account
Use a unique password and add an account PIN or port-out lock where the carrier offers one. Keep the account email secure and be cautious with personal details that could help someone impersonate you.
Respond quickly
Contact the carrier through an official number or app, then review primary email, financial and platform accounts. Change compromised credentials, sign out unfamiliar sessions and check recovery details.
Further reading
The U.S. Federal Trade Commission explains common SIM-swap warning signs and protective steps in SIM Swap Scams: How to Protect Yourself.
Phone-number privacy
A phone number is often treated as an identity signal even though numbers can be reassigned, ported or displayed falsely. Avoid publishing a primary recovery number unnecessarily, and do not assume an incoming caller is genuine merely because the displayed number looks familiar.
Plan a fallback before travel or replacement
When changing devices, carriers or countries, verify that important accounts have another authentication route. Keep backup codes and recovery email current before the old SIM stops working. This prevents a routine phone change from turning into an account-recovery crisis.
What text-message MFA can still do
Text-message verification is not useless. It can stop many password-only attacks and may be the only option a service offers. The limitation is that the factor depends on the mobile account and carrier process. Use it when it is the available improvement, while preferring phishing-resistant or app-based methods for the most important accounts.
Carrier-account checklist
- Unique carrier-account password
- Account PIN or passcode
- Port-out or number-transfer protection where available
- Current email and billing contact details
- A written official support number kept outside the phone