Share this article
How to Prevent a SIM Swap Scam
Learn how SIM swapping works, the warning signs, and simple steps to protect yourself.
Share this article
You’ve probably deleted a shady text message or two without a second thought and blocking spam email from strangers feels second nature by now. But would you recognize the signs of a SIM swap scam? Also called SIM hijacking, this form of account takeover is more common than ever.
The scale isn’t small, either. In 2025, authorities charged a cybercrime ring with stealing more than $800,000 in cryptocurrency from victims through SIM swapping.1
“Customers have become more mindful with what they’re clicking, where they’re going online, and who they’re speaking to, but it’s the small things that may seem harmless, such as your phone suddenly losing a signal,” says Roxane Adams, fraud expert at Forbright Bank. “If your security is not top of mind, then you’re vulnerable.”
When you understand how the scam works, and what you can do to stop it, you’re in a stronger position to protect your phone number and the money tied to it. There’s a lot you can do to lower your risk. Here’s what to know.
What Is a SIM Swap Scam?
In a SIM swap scam, a criminal tricks your mobile carrier into moving your phone number onto a SIM card the criminal controls. Once that happens, they can receive your calls and texts, including the security codes meant to verify your identity.
Not every SIM swap is fraud. You go through a legitimate version any time you switch phones or request a replacement SIM yourself. The fraudulent version looks different: an attacker armed with your stolen personal details poses as you and convinces the carrier to hand your number to them. From that point, they’re positioned to reset your passwords, capture verification codes, and take over your accounts one by one.
What Is a SIM, Exactly?
Your SIM is the small chip inside your phone that phone carriers use to confirm your identity and route your calls, texts, and data to the right device. Consider it the anchor of your mobile identity, since it’s what links your number to things like SMS two-factor codes and account-recovery processes. That’s exactly why criminals go after it, because whoever controls the SIM controls the gateway to a lot of your sensitive accounts – even ones with additional security protection.
Newer eSIM technology is more secure, since it’s built directly into the phone rather than sitting on a removable card that can be physically swapped. Even so, an eSIM is still tied to your phone number, so it isn’t immune to the digital version of this attack.
How Does a SIM Swap Attack Happen?
The scam relies on gaps in how carriers verify who’s on the other end of the line. It typically plays out in four stages.
First, the criminal gathers your personal details, often through phishing emails, oversharing on social media, or straightforward social engineering. “It’s easier than ever to find personal information online, such as birthdays, previous addresses, and Social Security numbers,” Adams says. “The data is there and the fraudsters are leveraging that.”
Next, they call your mobile carrier pretending to be you.
Then they ask the carrier to move your number to a new SIM, often claiming your phone was lost or damaged.
Finally, with your number in hand, they intercept the one-time codes sent by text, reset your account passwords, and work their way into whatever systems those accounts protect.
Why a SIM Swap Scam Can Be Costly
SIM swapping causes so much harm because it defeats SMS-based two-factor authentication, one of the most widely used security tools out there. Once an attacker owns your number, they can:
- Drain bank accounts by intercepting the verification texts needed to approve transfers.
- Empty crypto wallets by resetting logins tied to your number.
- Lock you out of email and cloud storage while quietly pulling your personal or business data.
- Open new credit lines or otherwise impersonate you using the accounts they’ve already taken over.
How to Protect Yourself from a SIM Swap Scam
Phone carriers are improving their defenses, but you shouldn’t count on that alone. A handful of habits can reduce your risk:
- When available, use multi-factor authentication to access your apps, especially those with financial information.
- Ask your carrier for a PIN or port-lock on your account. Most carriers let you require a separate code before any transfer request goes through, which adds a barrier for anyone trying to impersonate you.
- Turn on SIM protection through your phone carrier. This feature, free of charge, locks your SIM in place so no transfer request can go through until you unlock it yourself.
- Be conservative with sharing personal details online. Attackers build convincing impersonations out of publicly available information, so the less you post about your phone number, birthday, or address, the harder you are to imitate.
- Give every account its own strong password. Reusing passwords, or using close variations across accounts, means one breach can cascade into several. A password manager makes this easier to maintain.
- Keep an eye on your accounts. Turn on login alerts where you can and check in periodically for anything that looks off. Identity-monitoring services can also flag you if your information turns up in a breach or on the dark web.
- Treat unexpected contact with suspicion. Legitimate banks will never call or text you asking for a password, PIN, Social Security number, or payment. If something feels off, hang up and call the institution back using a number you already know is legitimate—don’t use a callback number a caller gives you. And never hand over personal information to an unsolicited call, email, or text.
Signs You May Have Been SIM Swapped
The sooner you catch it, the less damage it does. If your phone suddenly loses a signal, with calls and texts no longer coming through, that’s a warning sign.
Also watch for login notifications or password-reset emails for accounts you didn’t touch, or a message from your carrier about a SIM activation or number transfer you never requested. If you’re locked out of your email, social media, or banking apps without warning, you may have been a victim of a SIM swap scam.
What to Do If It Happens to You
If you think you’ve been SIM swapped, speed matters more than almost anything else. Follow these steps as quickly as you can, Adams says.
- Get your number back first. Call your carrier right away, explain that you’ve been targeted, and ask specifically for the fraud department—they’re equipped to handle this and can usually restore your number to a SIM you control.
- Lock down every account that may be exposed. Start with financial institutions and email, resetting passwords as soon as your number is back. Check your email provider’s sign-in activity for logins from unfamiliar devices, and going forward, refresh your passwords periodically and glance at your credit report for accounts or inquiries you don’t recognize.
- Report it. In the U.S., you can file a report with both the Federal Communications Commission (FCC) and the Federal Trade Commission (FTC). Beyond helping your own case, it gives investigators data they can use to track patterns across other attacks.
Disclaimer: This article is for general information and education only. It should not be considered financial or tax advice.
1https://www.darkreading.com/cyberattacks-data-breaches/scattered-spider-member-prison
