SIM swapping: how it works and how to protect yourself
SIM swapping lets criminals hijack your phone number and the SMS codes sent to it. How the scam works, the warning signs and a practical protection checklist.
Login securityPublished
SIM swapping is a form of account takeover in which a criminal gets your phone number moved to a SIM card, or eSIM profile, that they control. After the swap, your calls and text messages, including SMS login codes and password-reset messages, reach them instead of you. It does not require breaking into your phone, only fooling the staff or systems of your mobile provider. The risk is modest for most people, but it is the reason security bodies advise against relying on SMS codes for important accounts.
How a SIM swap works
- Gathering information. The attacker collects personal details: name, address, date of birth, sometimes account or customer numbers. These come from data breaches, phishing, social media or social engineering.
- Contacting the provider. They pose as you, claim the phone is lost or the SIM damaged, and ask for a replacement SIM or a new eSIM. Sometimes they bribe or deceive an employee, or use a weak online process.
- Taking over the number. Once the provider switches the number, your own SIM stops working.
- Using the codes. The attacker triggers password resets or logins on your accounts and reads the SMS codes that arrive on their device. Banks, email providers and exchanges are the typical targets.
Related is port-out fraud, where the number is moved to another provider. The effect for you is the same.
Warning signs
- Your phone suddenly shows “No service” or “SOS only” for no obvious reason.
- You receive a message from your provider about a SIM change, a number transfer or a new eSIM that you did not request.
- You get unexpected security notifications, password-reset emails or login alerts.
- Contacts tell you they received odd messages from your number.
A single dropped signal is usually harmless, since networks do fail. If it lasts and other phones nearby are fine, act promptly.
How to protect yourself
Reduce what SMS can do for an attacker
- Move 2FA away from SMS. Use passkeys, hardware keys or authenticator apps on email, banking, cloud and social accounts.
- Check recovery options. Many accounts let you reset the password by SMS even when a stronger factor is on. Remove or tighten this where possible. See account recovery.
- Protect your email first. Your email account can reset almost everything. Our guide to securing your email account covers this.
Protect the number at the provider
- Add a PIN or password to your mobile account for any contract or SIM change, if your provider offers one.
- Ask about SIM or porting locks. Some providers let you block SIM replacement or number transfers unless extra checks pass.
- Set up account notifications so you are alerted by email or app about SIM changes.
- Use a strong, unique password for your mobile provider’s customer portal, ideally with a second factor.
Limit what others can learn about you
- Do not give out your birth date, address or customer number to unknown callers or on unsolicited links.
- Be cautious with posts that reveal personal data used in identity checks.
- Beware of calls or texts pretending to be your provider or bank. Hang up and call the official number yourself.
- Keep your phone number out of public profiles where you can.
What to do if you suspect a swap
- Call your provider from another phone or visit a shop with ID. Ask them to block the SIM, restore your number and note the incident.
- Change the password of your email account from a safe device, and enable a stronger second factor.
- Contact your bank, and check your accounts for transactions or changes you did not make. Ask the bank to block cards or online access if needed.
- Secure other accounts: messaging, cloud, social media, crypto and shopping accounts.
- Review recovery settings and remove your phone number as a reset method where possible.
- Consider reporting it to the police, and keep records of messages and times, which can help with banks and insurers.
Why criminals like this method
SIM swapping appeals to attackers because it needs no technical barrier to be crossed: there is no malware you might notice and no fake link you have to click. The attack targets a process at the provider. That makes it hard to see from the victim’s side, but easy to plan for. If your important accounts no longer depend on your phone number, the attack loses most of its value.
Your ten-minute checklist
- Ask your provider whether you can set an account PIN or password for SIM changes, and set one.
- List the accounts that still send codes to your number: email, bank, cloud, social media.
- Switch the top three to an authenticator app, passkey or security key.
- Check the “forgot password” options of your email account and remove the phone number if a stronger option exists.
- Save the number of your provider’s support line on another device, so you can call quickly if your SIM stops working.
Is it a big risk for me?
For most people the chance of a targeted SIM swap is low, and the damage can be contained if your important accounts do not depend on SMS. That is the practical message: you do not have to defend the phone number, you just have to stop making it the only thing between an attacker and your accounts. The BSI recommends authenticator apps and hardware-based methods over SMS for this reason.
Switch the accounts that matter most, ask your provider about a PIN, and you will have dealt with most of the risk.
Frequently asked questions
How do I know if I am a victim of SIM swapping?
Common signs are sudden loss of mobile signal, a phone that shows no network while others around you have one, unexpected messages from your provider about a new SIM or number change, and security alerts or password-reset emails you did not request.
Can SIM swapping happen with an eSIM?
Yes. The principle is the same: an attacker convinces the provider to activate your number on a new eSIM profile. Provider-side identity checks and account PINs matter for both SIM and eSIM.
What do I do first if my number has been taken over?
Use another phone to call your provider and ask them to block the SIM and restore your number. Then change the password of your email account, banking and other key services from a safe device, and tell your bank.
Does an authenticator app stop SIM swapping?
It does not stop the swap itself, but it makes the stolen number far less useful, because your login codes no longer depend on it. Also check whether your accounts still allow password reset by SMS.
More in Login security
Account security for the whole family: a practical guide
Keep a household safe online: a shared password manager, 2FA for everyone, child accounts, help for parents and a simple plan if someone loses access.
Backup codes: what they are and where to keep them
Backup codes get you into an account when your phone or authenticator is gone. Learn how to generate them, where to store them safely and when to replace them.
Data breach: what to do now, step by step
Your email was in a breach? Check Have I Been Pwned or the HPI Identity Leak Checker, change the right passwords, switch on 2FA and watch for follow-up scams.
Fingerprint and face login: how safe is biometrics?
Fingerprint and face unlock are convenient and, used on your own device, quite safe. Learn how they work, where they fall short and how to set them up sensibly.
Hardware security keys explained: how they work
A hardware security key is a small device that proves it is you. Learn how FIDO2 keys work, what to look for, how to set one up and why you need a spare.
How password managers work and why they are safe
A password manager keeps your logins in an encrypted vault that only your master password opens. How it works, the real risks and how to start in an afternoon.