Stop a SIM Swap Before It Starts
The most effective protection against a SIM swap attack is removing your phone number as the weak link in your accounts: set a passcode or PIN with your mobile carrier, move two-factor authentication (2FA) off text messages and onto an authenticator app or hardware security key, and watch for the one warning sign that matters most, a sudden loss of cell signal you didn't cause. A SIM swap attack, also called SIM hijacking or a port-out scam, happens when a criminal convinces your mobile carrier to move your phone number onto a SIM card they control, usually by impersonating you with personal details gathered from data breaches, social media, or a phishing message. Once your number is theirs, they can intercept the SMS codes and password-reset links that guard your email, bank, and cryptocurrency accounts.
Quick Answer
Protect yourself from a SIM swap attack by adding a PIN or passcode to your mobile carrier account, asking for enhanced identity verification before any SIM or number change, and switching account recovery away from SMS text codes to an authenticator app or a physical security key. Watch for a sudden "No Service" or "SOS only" message on your phone, unexpected "your SIM was updated" texts, or password reset emails you didn't request. If any of that happens, call your carrier immediately from another phone or line, then lock down your email and financial accounts before the attacker can.
How Criminals Pull Off a SIM Swap
A SIM swap doesn't require stealing your physical phone. Attackers gather enough personal information, your name, date of birth, address, and the last four digits of your Social Security number, from data broker sites, old data breaches, or a convincing phishing text, then call or chat with your carrier's support line and claim to be you requesting a new SIM for a "lost phone." If the carrier's identity checks are weak, the rep activates the attacker's SIM and your number goes dead on your own device within minutes. From there, the attacker requests password resets on your email, bank, and exchange accounts, all of which land as text messages the attacker now receives instead of you.
According to the FBI's Internet Crime Complaint Center (IC3)SIM-swapping complaints resulted in roughly $68 million in reported losses in 2021, more than eight times the losses reported in 2018. The Federal Communications Commission (FCC) responded with new rules, adopted in November 2023, requiring wireless carriers to verify a customer's identity through a secure method before processing a SIM change or porting a number to another carrier; the FCC's rule phased in for major carriers through 2024. Those rules raise the bar, but they don't eliminate the risk, since a determined attacker with enough of your personal data, or a bribed insider, can still get past carrier controls.
Why This Threat Is Growing
Six Steps to Lock Down Your Phone Number
You can cut your risk sharply without replacing your phone or carrier. The steps below take most people under an hour and address both how attackers get in and what they do once they're in.
Protect Yourself From a SIM Swap
Add a carrier account PIN or passcode
Call your carrier or log into your account and set a separate PIN or passcode required for any SIM change, porting request, or account modification. AT&T, T-Mobile, and Verizon each offer this under names like "extra security" or "number transfer PIN."
Move 2FA off SMS
Switch account recovery and two-factor authentication from text-message codes to an authenticator app (Google Authenticator, Authy, Microsoft Authenticator) or a hardware security key for email, banking, and any account holding money or sensitive records.
Reduce your exposed personal data
Remove your name, address, and phone number from data broker sites, and lock down social media so your date of birth, mother's maiden name, and other verification details aren't publicly visible.
Use non-obvious security question answers
Treat security questions like passwords: enter answers that aren't true or guessable, and store them in a password manager rather than trying to remember a real answer.
Ask about a port freeze or number lock
Some carriers offer a full freeze that blocks any SIM swap or port-out request until you personally remove it in person or with additional verification. Ask your provider what's available.
Set account alerts and monitor regularly
Turn on login and transaction alerts for your bank, email, and any cryptocurrency exchange so you see unauthorized activity within minutes rather than days.
Warning Signs You May Be Mid-Attack
- Your phone suddenly shows "No Service" or "SOS Only" with no known outage
- You receive a text or email confirming a SIM or account change you didn't request
- You're locked out of email, banking, or social accounts without warning
- You get password-reset confirmations for accounts you didn't try to reset
- A friend or contact says they received strange messages from your number
If You Think It's Happening Right Now
Act within minutes, not hours. Call your carrier from another phone or line and report the SIM swap; ask them to lock the account and reverse the port. Then, from a device you trust, change the passwords on your email and financial accounts and, wherever possible, revoke active sessions so the attacker is logged out. Check your bank, credit card, and any cryptocurrency exchange for unauthorized transactions, and place a fraud alert or credit freeze with the three credit bureaus. Bellator Cyber Guard's identity theft recovery steps guide walks through the full sequence, including filing reports with the FTC at IdentityTheft.gov and with the FBI's IC3.
If you hold cryptocurrency, treat a SIM swap as an emergency: many exchanges still allow SMS-based account recovery, which is exactly what SIM swap attackers target. See our crypto security guidance for exchange-specific protections. And if the attacker used your accounts to send phishing messages to your contacts, warn them directly, since your compromised number or email may now be attacking people who trust you.
SMS Codes Are a Known Weak Point
The National Institute of Standards and Technology (NIST), the federal agency that sets U.S. cybersecurity standards, has flagged SMS-delivered one-time codes as a weaker authentication method in its Special Publication 800-63B digital identity guidelines, precisely because a SIM swap lets an attacker receive those codes instead of you. If a service offers app-based or hardware-key 2FA as an alternative, use it, especially for email, banking, and any account tied to your finances.
Why Move 2FA Off SMS
- Removes your phone number as a single point of failure for account recovery
- Authenticator apps and hardware keys keep working even if your SIM is swapped
- Most major services, including Google, Microsoft, and most banks, offer app-based or hardware 2FA at no extra cost
What to Plan For
- Migrating every account from SMS to an app takes time if you use text codes across ten or more services
- Losing your device without saved backup codes can lock you out temporarily
- A few smaller or older services still only support SMS as a second factor
Who Attackers Target Most
SIM swap attackers focus on people whose phone number unlocks something valuable: cryptocurrency holders, business owners with access to company financial accounts, and public figures or executives whose contact information is easy to find. They also target older adults, who may be less familiar with the warning signs and more likely to have a phone number listed publicly for years. If you're helping an aging parent or relative manage their accounts, Bellator's guide on how to protect elderly parents from online scams and identity theft covers the setup steps in plain terms. More broadly, our guide to how to protect your digital identity covers the account hygiene habits, like unique passwords and minimizing data exposure, that make you a harder target in the first place.
Old data breaches also feed SIM swap attempts, since attackers use leaked personal details to answer a carrier's verification questions. Checking whether your information is circulating is worth doing regularly; see dark web monitoring: what it is and why you need it for how that monitoring works and what it can and can't catch.
Get Your Free Personal Security Review
Get plain-language help locking down your accounts, 2FA, and phone number against SIM swap and identity theft attempts. No pressure.
Frequently Asked Questions
Yes. A SIM swap happens at your carrier, not on your device. The attacker convinces your provider to activate your number on a SIM card they control, so your physical phone simply loses signal once the swap completes.
No. Your device passcode protects the phone itself, not your phone number at the carrier level. A SIM swap PIN, set directly with your mobile provider, is the control that actually blocks unauthorized number changes.
Policies vary by carrier and by what happened; some providers offer limited protections or credits in specific cases, but reimbursement isn't guaranteed. Report the incident to your carrier and file with the FTC and FBI's IC3 regardless, since those reports matter for any later claim, credit dispute, or investigation. Questions about liability or refunds are best directed to your carrier and, where needed, an attorney.
An eSIM, a digital SIM built into the device rather than a removable card, doesn't stop a SIM swap by itself, since the swap happens through your carrier account, not the physical card. The same carrier-level protections, an account PIN and identity verification, apply whether you use a physical SIM or an eSIM.
A SIM swap transfers your actual phone number to an attacker's device, so they receive your calls and texts. Spoofing is different: it lets someone display a fake caller ID without ever touching your real number or account. Both can be used in scams, but a SIM swap gives the attacker direct access to your accounts, while spoofing is mainly used to trick you into answering or trusting a call.
Start with the concern that matters most
Make your accounts, devices, or family safer one clear step at a time
You do not need to change everything today. Choose the account, device, scam, or family concern that brought you here and fix the highest-impact opening first.
People also look for
Keep exploring Passwords & account security
Make passwords, password managers, MFA, and passkeys work together to reduce account takeover risk.
- Common question: password security best practicesApply current password best practicesUse long unique passwords, password managers, MFA, and passkeys where they make sense.
- Common question: NIST password manager guidanceRead the NIST password manager guidanceUnderstand how official guidance treats password managers and modern authentication.
- Common question: best password manager for personal useChoose a personal password managerCompare the practical features that make a password manager safer and easier to keep using.
- Common question: how to create a strong passwordCreate stronger, unique passwordsReplace short, reused passwords with a system that is both stronger and manageable.
- Common question: password security guideStart with the password security guideBuild a complete account-protection routine for work or home.


