Accounts & Identity

SIM-Swap and Phone-Number Security

How phone-number takeover can affect text messages and account recovery, plus practical steps for carrier-account and authentication safety.

What a SIM swap is

A SIM-swap scam occurs when someone persuades or compromises a mobile carrier into moving a victim’s phone number to another SIM or eSIM. Calls and text messages may then reach the attacker’s device.

Why the number matters

Phone numbers are often used for password resets, login codes and identity checks. Losing control of the number can therefore affect accounts beyond the mobile service itself.

Warning signs

  • The phone unexpectedly loses cellular service
  • A carrier message says a SIM or eSIM changed
  • Password-reset or login alerts appear for unrelated accounts
  • Calls or messages stop arriving while Wi-Fi still works

Reduce dependence on text messages

For important accounts, use passkeys, security keys or authenticator apps when available. Text-message codes can still be better than no MFA, but they depend on continued control of the phone number.

Protect the carrier account

Use a unique password and add an account PIN or port-out lock where the carrier offers one. Keep the account email secure and be cautious with personal details that could help someone impersonate you.

Respond quickly

Contact the carrier through an official number or app, then review primary email, financial and platform accounts. Change compromised credentials, sign out unfamiliar sessions and check recovery details.

Further reading

The U.S. Federal Trade Commission explains common SIM-swap warning signs and protective steps in SIM Swap Scams: How to Protect Yourself.

Phone-number privacy

A phone number is often treated as an identity signal even though numbers can be reassigned, ported or displayed falsely. Avoid publishing a primary recovery number unnecessarily, and do not assume an incoming caller is genuine merely because the displayed number looks familiar.

Plan a fallback before travel or replacement

When changing devices, carriers or countries, verify that important accounts have another authentication route. Keep backup codes and recovery email current before the old SIM stops working. This prevents a routine phone change from turning into an account-recovery crisis.

What text-message MFA can still do

Text-message verification is not useless. It can stop many password-only attacks and may be the only option a service offers. The limitation is that the factor depends on the mobile account and carrier process. Use it when it is the available improvement, while preferring phishing-resistant or app-based methods for the most important accounts.

Carrier-account checklist

  • Unique carrier-account password
  • Account PIN or passcode
  • Port-out or number-transfer protection where available
  • Current email and billing contact details
  • A written official support number kept outside the phone
Educational scope: This page provides general information, not personalized incident response, legal advice, compliance advice or a guarantee of security.

Related reading