SIM swap attacks: how to spot one and what to do

Your phone shows "No Service" or "SOS." You haven't changed anything, you're somewhere with normal coverage, and rebooting doesn't help.

That's the symptom worth knowing, because it's often the only warning a SIM swap gives you, and the window to act is short.

What a SIM swap is

Your mobile number isn't tied to the phone in your hand. It's tied to a record at your carrier, and that record can be moved to a different SIM card or eSIM.

In a SIM swap, someone contacts your carrier pretending to be you and asks for the number to be transferred to a device they control. When it works, your phone goes dead and every call and text meant for you arrives on their phone instead.

That includes every SMS verification code. Bank codes, email recovery codes, exchange withdrawal confirmations. This is why text-message two-factor authentication is the weakest form: it protects an account by sending a secret to a phone number that can be taken away from you.

To make the request believable, the attacker needs your name, phone number, address, date of birth, and often the last four of your Social Security number or an account PIN. None of that is hard to assemble, which is the part that matters most.

The warning signs

  • Sudden, unexplained loss of service in a place you normally have coverage.
  • A carrier notification about a SIM change, port request, or account update you didn't make.
  • Verification codes stop arriving for accounts you're actively trying to use.
  • Password reset or login alerts from accounts you didn't touch.
  • Friends receiving messages from your number that you didn't send.

Loss of service is the one to act on. If your phone dies for no reason and someone else's works fine on the same network, don't wait to see if it comes back.

What to do, in order

1. Call your carrier from another phone, immediately

Borrow a phone or use a landline. Tell them you believe your number has been transferred without authorization and ask them to reverse it and lock the account. Say the words "SIM swap." Carriers have a process for this, and speed determines how much happens in the meantime.

2. Get to your email account first, from a computer

Email is the recovery root for everything else. Change the password from a device that isn't the phone, and remove SMS as a recovery method there.

3. Work down by value

Banking, then any crypto exchange, then payment apps, then everything else. Change passwords and replace SMS-based two-factor authentication with an authenticator app or a security key as you go.

4. Call your bank and any exchange directly

Tell them your number was compromised and ask them to flag the account. Ask specifically whether any transfers, withdrawals, or new payees were added in the last few hours.

5. Report it

File with the FTC and the FBI's IC3, and file a police report. Documentation matters if money moved, and it's usually needed for any dispute that follows.

Preventing the next one

Add a carrier PIN or port-freeze. Every major carrier offers a number-transfer PIN or lock that has to be provided before a port or SIM change. It's the single most effective control, and most people have never turned it on. Do it today, and use a PIN that isn't derived from your birthday or address.

Get off SMS two-factor authentication where you can. Authenticator apps generate codes on your device. Hardware keys and passkeys are stronger still. Anywhere holding money should not be protected by a text message.

Don't use your main number as a recovery method for high-value accounts. Some people keep a separate number, unpublished and used for nothing else, for account recovery only.

Reduce what a stranger can learn about you. This is the part that actually determines whether the attempt succeeds.

Why the request gets approved

A carrier representative approves a swap when the caller answers the questions convincingly. So the attack isn't really technical. It's research.

Data brokers and people-search sites publish the exact set of answers those questions ask for: full name, current and past addresses, date of birth, phone numbers, and relatives. It's compiled from public records and commercial data, sold openly, and available to anyone for a small fee.

People who hold crypto, run businesses, or have a public profile get selected more often, because the payoff justifies the effort. But the raw material is the same for everyone, and it's sitting in the open.

Delist finds those listings, files the removals, and keeps re-checking them, since brokers routinely repost profiles after they come down. Fewer published records means fewer correct answers available to whoever calls your carrier pretending to be you. Run a free scan to see what's out there.

Frequently asked questions

How do I know if I've been SIM swapped rather than just having a network problem?

Check whether another phone on the same carrier has service in the same place. If theirs works and yours shows no service after a reboot, treat it as a swap and call your carrier from the other phone.

How fast do I need to move?

Within minutes if you can. Attackers work immediately, because the window closes as soon as you contact your carrier. Email first, then money.

Will a carrier PIN actually stop it?

It stops the common version, where a representative is talked into a transfer. It doesn't stop an attacker who has compromised carrier staff or systems, which is rarer. It's the highest-value step available to you.

Is an eSIM safer than a physical SIM?

Somewhat, since there's no physical card to swap, but the attack targets the carrier's account record rather than the hardware. An eSIM can be reassigned the same way. The PIN and getting off SMS matter more than the SIM type.

I got my number back. Am I finished?

No. Assume any account still using SMS recovery was reachable while the number was theirs. Work through your accounts, check for changed recovery details and added payees, and read your email for notices that arrived during the gap.

Find out what data brokers know about you

Run a free scan to see which sites are exposing your personal information — name, phone, address, email, and more.

Start your free scan