What is a SIM swap scam, and how do you protect your accounts?
A SIM swap moves your phone number onto a criminal's device. Your phone goes dead, their phone starts receiving your calls, texts and verification codes - and the codes are the point. US carriers must now offer a free lock that blocks it.
The short answer
- A SIM swap transfers your phone number to someone else's device. They then receive your SMS verification codes, which is how bank and email accounts get taken over.
- The first sign is almost always your phone losing service for no reason - no bars, SOS only, or calls failing while wifi still works.
- US carriers must offer a free account lock and port-out freeze under FCC rules. Turning both on is the single most effective step you can take.
- Move your important accounts off SMS codes. An authenticator app or a passkey stays with you even if your number does not.
- If it happens, call your carrier from another phone first, then secure your email before your bank - email is what resets everything else.
Your phone stops working. No bars, no calls, no texts — but wifi is fine. Half an hour later, someone else is reading your password reset emails.
Quick answer
A SIM swap is when a criminal convinces your mobile carrier to move your phone number onto a SIM card they control. Your phone loses service. Their phone starts receiving your calls and text messages, including the verification codes banks and email providers send by SMS.
The number is not the target. The codes are.
How a SIM swap works
Everything about your phone number lives with the carrier, not the plastic card. A number can be reassigned to a new SIM or eSIM in minutes — which is the feature that makes replacing a lost phone easy, and the feature criminals abuse.
The FBI's public service announcement on SIM swapping describes three routes in:
- Impersonating you. Calling the carrier and answering the security questions using details gathered from data breaches, social media, or an earlier phishing message.
- Paying a carrier employee. The FBI describes criminals who "pay off a mobile carrier employee to switch a victim's mobile number".
- Attacking the carrier's systems, by phishing staff into installing malware that gives access to internal tools.
Only the first depends on anything you did, which is worth saying plainly. The other two happen entirely inside a company you do not control.
What happens next
Once the number moves, the attacker works fast:
- Go to your email provider and click forgot password.
- Receive the SMS code — on their phone now.
- Reset the email password and lock you out.
- Use that email to reset everything else: bank, exchange, social media, cloud storage.
- Move money, or sell the accounts on.
This is why email comes first in the response below. Email is not one account among many; it is the reset route into all of them.
Warning signs
- Sudden loss of cellular service — "No Service", "SOS Only" or "Searching" where you normally have signal, while wifi still works
- A message from your carrier saying a SIM or eSIM was activated, a port-out was requested, or account details were changed
- Password reset emails or codes you did not ask for
- Being locked out of an account that worked yesterday
- Calls and texts stopping while data continues, or the other way round
- A friend saying they got a strange message from you and it never appeared on your phone
What to do in the first hour
- Use a different phone or a laptop. Yours cannot make the call.
- Call your carrier's fraud line. Say you believe your number has been moved without authorisation and ask for it to be returned and the account locked. Ask what changes were made and when.
- Secure your email first. New password, then sign out of all devices — that second step is what removes an attacker who is already inside. Check for forwarding rules, filters and recovery addresses you did not create.
- Then banks and financial accounts. Call the number on your card. Ask them to review recent activity and flag the account.
- Change any account that used SMS codes, and switch it to an authenticator app while you are there.
- Report it — in the US, to IC3.gov and ReportFraud.ftc.gov. Elsewhere, your national cybercrime body. How to report an online scam covers what each agency does.
The sequence for locking down an already-compromised account, including the sign-out step people skip, is in I gave a scammer my password.
How to prevent a SIM swap
1. Lock the carrier account
The FCC's rules require wireless providers to authenticate customers properly before transferring a number, notify you when a SIM change or port-out is requested, and offer a free account lock and port freeze. Two separate protections are worth asking for by name:
- SIM change lock — blocks moving your number to a new SIM or eSIM
- Port-out freeze — blocks moving your number to a different carrier
Set them both. They are found in the account security section of most carrier apps, or by calling customer service.
2. Set a real account PIN
Add a PIN or passcode required for account changes. Do not use your date of birth, house number, or the last four of anything — those are the details an impersonator already has. Store it in your password manager.
3. Make the number worthless
This is the part that actually ends the problem. A stolen number is only valuable because of what it unlocks:
| Second factor | Survives a SIM swap? |
|---|---|
| SMS code | No — this is the target |
| Voice call code | No — calls move with the number |
| Authenticator app code | Yes — the app lives on the device |
| Push approval in an app | Yes, if it is tied to the app rather than the number |
| Hardware security key | Yes |
| Passkey | Yes |
Move your email, bank, and any cryptocurrency accounts off SMS. NIST's digital identity guidelines have discouraged SMS as an authentication channel for years for exactly this reason. Which second factor to use compares them all in detail.
4. Remove the phone number as a recovery method
Adding an authenticator app is not enough if the account will still send a code to your number when someone clicks "try another way". Check the account recovery settings and remove the number where the service allows it.
5. Reduce what is public about you
The FBI's guidance includes not publicising financial holdings — particularly cryptocurrency — on social media, and not posting personal identifying information that could answer a carrier's security questions. Public detail is what makes impersonating you possible. Protecting personal information online covers the wider cleanup.
6. Use unique passwords
A SIM swap gets someone the codes. Reused passwords get them the other half. The FBI lists unique passwords among its SIM-swap recommendations for that reason, and password reuse explains how one leaked password becomes many break-ins.
Who gets targeted
SIM swaps are more targeted than most fraud. Effort goes where the return is, which historically has meant people with visible cryptocurrency holdings, high-value social media handles, or public roles that make them identifiable. IC3's reporting showed SIM swap complaints jumping from 320 across 2018 to 2020 to 1,611 in 2021, with losses above $68 million in that single year.
That does not make it a celebrity problem. Anyone whose bank uses SMS codes is reachable by the same method, and the carrier lock costs nothing whether or not you are a target.
Key takeaways
- A SIM swap moves your phone number to someone else's device so they receive your codes.
- The first symptom is your phone losing service while wifi keeps working.
- US carriers must offer a free account lock and port-out freeze. Turn both on.
- SMS codes are the weak factor. An authenticator app or a passkey is not affected.
- If it happens, call the carrier from another phone, then secure email before banking.
- Remove your phone number as a recovery option once a stronger factor is in place.
Lock down the accounts that matter
SafeSurf IQ walks you through securing email, banking and social accounts step by step, in the order that actually matters.
Try it freeFrequently asked questions
- Can someone really steal my phone number?
- Yes. In a SIM swap, a criminal contacts your mobile carrier pretending to be you and asks for your number to be moved to a SIM card they control. If the carrier accepts the request, your phone loses service and theirs starts receiving your calls and texts. The FBI has described three routes - impersonating the customer, paying off a carrier employee, and phishing carrier staff to get into internal systems.
- How do I know if I have been SIM swapped?
- The clearest sign is sudden, unexplained loss of cellular service - no bars, SOS only, or Searching, in a place you normally have signal, while wifi still works. Other signs are a message saying your SIM or eSIM was activated on a new device, password reset emails you did not request, and being locked out of accounts. The FBI's own advice is to be alert to unexplained service lapses.
- How can I stop a SIM swap from happening?
- Turn on your carrier's account lock and port-out freeze, which US carriers must offer free under FCC rules that took effect in 2024. Set a separate account PIN that is not your date of birth or address. Then reduce what the number is worth - move your important accounts from SMS codes to an authenticator app or a passkey, so a stolen number no longer unlocks anything.
- Does two-factor authentication still protect me during a SIM swap?
- It depends entirely on the type. SMS codes are the factor a SIM swap is designed to defeat, so they offer little protection. Authenticator app codes live on your device, not your number, and survive a SIM swap. Passkeys and hardware security keys are stronger still, because there is no code to intercept. Any second factor beats none, but they are not equivalent.
- What should I do first if my phone suddenly loses service?
- Rule out the ordinary causes - flight mode, a network outage, an unpaid bill. If those are clear, use another phone or a laptop and call your carrier's fraud line straight away to report a possible unauthorised SIM change and get the number returned. Then secure your email account before anything else, because email is the reset route into everything else you own.
- Why do criminals want my phone number?
- Because so many services still treat a phone number as proof of identity. A number that receives SMS verification codes is a master key to bank accounts, email, cryptocurrency exchanges and social media. The FBI's advice not to publicise financial holdings online exists for this reason - visible assets make a number worth the effort of stealing.
Sources
- Criminals Increasing SIM Swap Schemes to Steal Millions of Dollars from US Public — FBI Internet Crime Complaint Center, 2022
- FCC Adopts Rules to Protect Consumers' Cell Phone Accounts — Federal Communications Commission, 2023
- Protecting Consumers from SIM-Swap and Port-Out Fraud — Federal Register, 2023
- FCC Announces Effective Compliance Date for SIM Swapping Item — Federal Communications Commission, 2025
- NIST SP 800-63B: Digital Identity Guidelines — National Institute of Standards and Technology, 2025
- 2025 Internet Crime Report — FBI Internet Crime Complaint Center, 2026
About the author
Cybersecurity & Digital Literacy
Subash Poudel builds SafeSurf IQ, a digital literacy platform that teaches people to recognise scams by putting them in front of real ones. He writes the online-safety reference material here, working from primary reporting — FBI IC3, the FTC, Verizon's DBIR, NCSC and Ofcom — rather than secondhand summaries.
- Founder and engineer, SafeSurf IQ
- Writes and reviews the platform's phishing, scam and privacy curriculum
- Works from primary incident and fraud reporting, cited on every article
Last reviewed . Figures are checked against the primary sources listed above at each review.
Read next
- Password Security
Two-factor authentication: which second factor should you use?
Any second factor is a large improvement over none, but they are not equivalent. SMS codes can be intercepted, app codes can be relayed by a live phishing proxy, and only hardware keys and passkeys resist phishing outright.
- Password Security
What are passkeys, and should you use them?
A passkey is a cryptographic key your device holds instead of a secret you know. Because there is nothing to reveal, there is nothing to phish — which makes it the first authentication method that removes the problem rather than managing it.
- Phishing
I gave a scammer my password. What should I do?
Change the password on that account first, then sign out every device. That second step is the one people miss, and it is the one that actually removes the attacker. Here is the full order, and what changes if you also gave a code.