Workforce and access social engineering · Also called SIM swapping, SIM hijacking, port-out fraud, phone number porting scam, SIM card swap
SIM swap
A SIM swap is a scam in which a criminal persuades your mobile provider to move your phone number to a SIM card they control. Your calls and texts then go to them, including one-time login codes, which lets them break into your email, bank, cryptocurrency, and work accounts that rely on text messages.
How it works
- Criminals gather your personal details through phishing, data breaches, or social media.
- They contact your mobile provider pretending to be you, say your phone was lost or damaged, and ask for your number to be moved to a new SIM or ported to another provider; some use insiders at the provider.
- Your phone loses service, and your calls, texts, and codes go to the criminal's device.
- They use text message codes to reset passwords and sign in to your accounts, lock you out, and take money or open new accounts in your name.
Red flags
- Your phone suddenly stops working, with no calls, texts, or data.
- Your mobile provider tells you your SIM card was activated on a new device you do not recognise.
- You receive password reset messages, PIN resets, or access codes you did not request.
- You get calls, emails, or texts asking for personal or account information.
If you are targeted
- Stop the takeover: contact your mobile provider immediately, from another phone if needed, to take back control of your number.
- Once you have your number back, change the passwords on your email, bank, and other important accounts.
- Check your bank, card, and other financial accounts for charges or changes, alert your bank, and if your identity details were exposed use IdentityTheft.gov or your national equivalent.
- Report it. Our Report a scam page lists where to report in your country, such as ic3.gov and ReportFraud.ftc.gov in the US.
Prevention
For individuals
- Set up a PIN or password on your mobile account to help block unauthorised changes.
- Use an authentication app or a security key instead of text message codes on important accounts.
- Limit the personal information you share online, such as your address, phone number, and any cryptocurrency holdings.
For organisations
- Mobile carriers can train staff on SIM swap schemes, set strict protocols for verifying customers, and authenticate requests from third-party retailers.
- Employers can replace text message codes with phishing-resistant MFA, such as FIDO security keys, which a SIM swap cannot intercept.
- Banks and other services can treat SMS as a last-resort factor rather than the only way to reset an account.
Step-by-step controls: the implementation guide
By the numbers
Figures are for the reporting category this scam falls under, not this scam alone.
| SIM swap losses reported to the FBI IC3 in 2025 | $17.4M | US, 2025, FBI IC3 |
Real cases
2024-01 · US · Charged · $400M stolen
SIM swap ring charged over $400 million crypto theft tied by press to FTX, 2024
Delivered through: SMS phishing (smishing)
How official datasets classify it
- FBI IC3
- SIM Swap
- Scamwatch
- Account or identity takeover scams
- MITRE ATT&CK
- T1451
Questions
- How do I know if I have been SIM swapped?
- The clearest signs are your phone suddenly losing all service, or a notice from your provider that your SIM was activated on a new device. Contact your provider straight away from another phone.
- Does text message two-factor authentication protect me from SIM swaps?
- Not fully. The FTC notes that text message verification may not stop a SIM swap, and CISA lists SMS as the weakest form of MFA. Use an authentication app or a security key instead.
Related scams
- Employee SMS phishing (0ktapus-style)
- MFA fatigue (push bombing)
- Account takeover through fake bank support
- Help desk password and MFA reset impersonation