SIM swapping can steal control of your phone number, but carrier locks, stronger MFA, and safer recovery settings can sharply reduce the damage.
Protect Your Phone Number Before It Becomes a Master Key
Your mobile number may be connected to far more than calls and text messages. It can also be tied to your email, bank accounts, social media, cryptocurrency services, password resets, and other identity checks.
That makes it valuable to criminals.
A SIM swap happens when an attacker gets a mobile carrier to transfer your phone number to a SIM card or eSIM they control. A related attack, known as port-out fraud, moves your number to an account with another carrier.
Once the attacker controls the number, calls and text messages meant for you can reach them instead. If your accounts use SMS or voice calls for login codes or password recovery, that can give the attacker a route into email, financial accounts, social networks, and other services. The FTC specifically warns that SIM swapping can be used to defeat text-message authentication and take over sensitive accounts.
The best defense has two parts: make your mobile account harder to take over, and make your other accounts less dependent on your phone number.
The Most Important SIM-Swap Protections
If you want to reduce your risk quickly, start with these actions:
- Add the strongest security your mobile carrier offers.
- Use a unique password for your carrier account.
- Enable a number-transfer lock, port protection, or SIM-change lock if available.
- Move important accounts away from SMS and voice-call authentication.
- Protect your primary email account with strong MFA.
- Check whether SMS is still available as an account-recovery fallback.
- Keep personal information used for identity checks private.
- Treat unexpected carrier notifications or loss of cellular service as urgent.
The exact names of carrier protections vary, so do not assume a normal account password is enough. Ask your provider specifically what prevents someone from replacing your SIM, activating an eSIM, or transferring your number.
How Does a SIM Swap Happen?
An attacker usually does not need your physical SIM card.
Instead, they try to convince your mobile provider that they are you. They may claim that your phone was lost or damaged, request an eSIM activation, or ask for the number to be transferred to another device.
Information used to impersonate you can come from:
- phishing emails, calls, or text messages;
- data breaches;
- reused or stolen passwords;
- social media profiles;
- publicly available personal information;
- compromised email accounts;
- stolen identity documents;
- answers to security questions.
Attackers may also compromise an online carrier account directly or, less commonly, exploit insider access at a telecommunications provider. Canada’s Cyber Centre identifies customer impersonation, stolen credentials, online account compromise, and insider access as SIM-swapping risks.
If the fraudulent request succeeds, your phone can still be sitting in your hand when its cellular service suddenly stops.
SIM Swapping vs. Port-Out Fraud
The two attacks have the same basic goal but use different routes.
| Attack | What happens |
|---|---|
| SIM swap | Your existing carrier transfers your number to another SIM card or eSIM. |
| Port-out fraud | Your number is fraudulently transferred to an account with another carrier. |
Both can give an attacker control of communications sent to your number.
This is why it is worth asking your carrier about both SIM-change protection and number-porting protection.
1. Lock Down Your Mobile Carrier Account
Your carrier account is the first line of defense.
Use a strong, unique password that you do not use anywhere else. If your provider offers an additional account PIN or passcode, enable it.
Look for protections with names such as:
- number lock;
- transfer lock;
- port protection;
- SIM-change lock;
- account takeover protection;
- number-transfer PIN;
- extra identity verification.
Availability varies by provider and country.
If the carrier lets you prevent number transfers until you manually remove a lock, consider enabling it. Canada’s Cyber Centre specifically recommends additional carrier verification and port protection or a SIM lock where available.
Do not rely solely on security questions based on information other people might discover, such as your birth date, address, family names, or other details available online.
2. Move Important Accounts Away From SMS Authentication
Text-message two-factor authentication is better than relying on a password alone when no stronger option exists.
But SMS has a major weakness against SIM swapping: whoever controls your number may be able to receive the authentication code.
For sensitive accounts, choose stronger authentication when available.
| Authentication method | Protection against SIM swapping | Main limitation |
|---|---|---|
| Passkey | Strong | Recovery methods still need protection |
| FIDO hardware security key | Strong | Requires backup and recovery planning |
| Authenticator app | Strong against SIM swaps | Codes may still be stolen through phishing |
| SMS or voice code | Weak against SIM swaps | Number takeover can redirect the code |
| Password only | Poor | One stolen password may be enough |
CISA identifies FIDO/WebAuthn authentication as phishing-resistant and notes that SIM-swap attacks do not apply to FIDO or app-based authentication in the same way they apply to SMS and voice authentication.
For your most valuable accounts, passkeys or FIDO security keys are preferable when supported. Authenticator apps are also a meaningful improvement over SMS for SIM-swap protection.
3. Check Whether SMS Is Still a Backup Login Method
Enabling stronger MFA does not always remove weaker authentication.
You might add a passkey or authenticator app and still discover a “try another way” option that sends a code to your phone number.
That fallback can undermine the stronger protection you added.
Review the security and recovery settings for important accounts and look for:
- SMS login codes;
- voice-call verification;
- password resets by phone;
- recovery phone numbers;
- backup MFA methods.
Remove phone-number-based recovery where you can do so safely and have another reliable recovery method in place.
CISA warns that enrolling in authenticator-based MFA does not automatically disable SMS and that the remaining SMS option can become an exploitable fallback.
Strong authentication can still be undermined by weak account recovery. Protect both.
4. Secure Your Primary Email Account First
Your primary email deserves special protection because it often acts as a recovery hub for other accounts.
If an attacker gains access to it, they may be able to reset passwords elsewhere, approve security changes, hide alerts, or impersonate you.
Protect your main email account with:
- a unique password;
- a passkey, security key, or authenticator-based MFA;
- secure recovery information;
- backup recovery codes where supported.
Store recovery codes somewhere that does not depend entirely on the same phone or email account you are trying to protect.
Also review your email account periodically for unfamiliar:
- recovery addresses;
- phone numbers;
- devices;
- active sessions;
- forwarding rules;
- connected applications.
5. Reduce the Information Attackers Can Use to Impersonate You
SIM swapping often depends on social engineering, and personal information makes impersonation easier.
Avoid publishing sensitive details unnecessarily, particularly:
- your personal mobile number;
- full date of birth;
- home address;
- answers to common security questions;
- photographs of identity documents;
- account numbers or customer identifiers.
Review old social profiles as well as current ones. Information that seems harmless individually can become useful when combined with breach data or information obtained elsewhere.
The goal is not to disappear from the internet. It is to reduce the amount of information someone can use to convince a carrier or another service that they are you.
6. Take Unexpected Carrier Messages Seriously
A legitimate notification about a SIM replacement or number transfer that you did not request deserves immediate attention.
Watch for alerts mentioning:
- a new SIM;
- an eSIM activation;
- a number transfer;
- a transfer PIN;
- an account password change;
- a new authorized user;
- changes to your carrier account.
Do not use links or phone numbers in a suspicious message.
Instead, open the carrier’s official app or website yourself or use a customer-service number you independently know is genuine.
7. Understand What a SIM PIN Can — and Cannot — Do
A SIM PIN can be useful, but it solves a different problem.
It can prevent someone who physically steals your SIM card from simply inserting it into another device and using it without the PIN.
It does not normally prevent an attacker from convincing your carrier to issue a completely new SIM or eSIM.
For SIM-swapping protection, the more important controls are on your carrier account, such as transfer locks, account PINs, and stronger identity verification.
8. Secure the Phone Itself
Physical phone theft and SIM swapping are different attacks, but criminals can combine techniques.
Protect the device with:
- a strong passcode rather than a simple four-digit code;
- biometric unlocking where appropriate;
- current operating-system and security updates;
- hidden notification previews on the lock screen;
- device-location and remote-lock features.
If someone steals an unlocked phone and can also access your email, passwords, or carrier account, the potential damage increases considerably.
Does an eSIM Prevent SIM Swapping?
No.
An eSIM removes the removable plastic card, but SIM swapping is primarily an account takeover and identity-verification problem.
If an attacker successfully impersonates you to your carrier or compromises your carrier account, they may still be able to activate your number on an eSIM they control.
Canada’s Cyber Centre specifically warns that eSIMs can remain exposed to mobile-account compromise and remote social-engineering attacks.
An eSIM can make it harder for someone who physically steals your phone to remove and reuse a traditional SIM card, but it is not a substitute for carrier account security.
Warning Signs of a SIM Swap
One of the clearest warning signs is an unexplained loss of cellular service.
Your phone might suddenly show:
- No Service;
- SOS Only;
- no mobile data;
- inability to make or receive calls;
- missing SMS verification codes.
Other warning signs include:
- a SIM or eSIM activation you did not request;
- unexpected password-reset messages;
- changes to your carrier account;
- login alerts from unfamiliar devices;
- financial transactions you do not recognize;
- being locked out of email or social media;
- authentication messages suddenly stopping.
A network outage can cause similar symptoms, so loss of service alone does not prove your number was stolen.
However, loss of service combined with account-change notifications or suspicious login activity should be treated urgently.
There is another complication: Wi-Fi can hide the problem. Your phone may still access the internet and messaging apps over Wi-Fi even after cellular service has been moved elsewhere, so you may not immediately realize the number has been compromised. Canada’s Cyber Centre specifically warns about this possibility.
What to Do Immediately if You Are SIM Swapped
Speed matters. An attacker controlling your number may already be attempting password resets, financial transactions, or account recovery.
1. Contact Your Mobile Carrier
Use an official contact method.
Ask whether there has been:
- a replacement SIM activation;
- a new eSIM activation;
- an unauthorized number port;
- a change to your account security settings.
If your number has been moved, ask the carrier to:
- deactivate the unauthorized SIM or eSIM;
- reverse an unauthorized port;
- restore your service;
- secure the carrier account;
- add available fraud protections.
2. Contact Financial Institutions
Immediately notify banks, card issuers, cryptocurrency exchanges, payment services, and other financial providers that may be affected.
Ask them to check for unauthorized activity and explain what temporary security restrictions they can place on the account.
3. Secure Your Primary Email
Check your email account for unauthorized:
- logins;
- password changes;
- recovery addresses;
- recovery phone numbers;
- forwarding rules;
- connected apps.
Sign out unfamiliar sessions and change compromised credentials.
4. Work Through Other Important Accounts
Prioritize accounts that can lead to further compromise, including:
- primary email;
- password manager;
- mobile carrier account;
- banking and investment services;
- cryptocurrency accounts;
- major cloud accounts;
- government or identity-related accounts;
- social media and messaging accounts.
Remove unauthorized recovery information, revoke suspicious sessions, replace compromised or reused passwords, and move away from SMS authentication where possible.
5. Preserve Evidence
Keep records of:
- carrier notifications;
- suspicious emails and messages;
- transaction details;
- dates and times;
- screenshots;
- case or reference numbers;
- account changes.
These records can help with fraud reports, disputes, investigations, and account recovery.
SIM-Swap Protection and Reporting in the U.S., U.K., Australia, and Canada
SIM swapping is an international problem, but carrier protections and reporting systems differ.
| Country | Important points |
|---|---|
| United States | The FTC recommends carrier account PINs and stronger alternatives to SMS authentication. The FCC has adopted rules designed to strengthen authentication for SIM changes and ports and provide protections such as customer notifications and account-lock mechanisms. |
| United Kingdom | The NCSC warns that phone-number takeover can redirect SMS messages and voice calls. Fraud and cybercrime in England, Wales, and Northern Ireland can be reported through Report Fraud, which replaced Action Fraud in December 2025. Scotland continues to use Police Scotland. |
| Australia | Telcos must use strengthened identity authentication for high-risk transactions such as SIM swaps and number transfers. If your number is stolen, ACMA advises contacting your telco immediately and contacting financial institutions if fraud may be involved. |
| Canada | Canada’s Cyber Centre recommends additional carrier verification, port protection or SIM locks where available, unique passwords, and authentication methods that do not depend on the phone number. SIM-swap fraud can also be reported to the Canadian Anti-Fraud Centre. |
Carrier and regulatory protections reduce risk, but they cannot make a phone number impossible to steal. Your own account configuration still matters.
Should You Remove Your Phone Number From Every Account?
Not necessarily.
Some services legitimately require a phone number, and a number can still be useful for notifications and account recovery.
The better objective is to stop your number from becoming a single point of failure.
For your most important accounts, ask a simple question:
If someone controlled my phone number for the next hour, could they use it to take over this account?
If the answer is yes, review the account’s authentication and recovery options.
For particularly sensitive services, also consider whether they need your everyday publicly shared number at all.
SMS Authentication Is Still Better Than No MFA
The weaknesses of SMS do not mean you should disable MFA and return to password-only security.
If a service offers only SMS-based two-factor authentication, using it will generally provide more protection than relying on a password alone.
The important distinction is that stronger alternatives should be preferred when available, especially for email, financial services, password managers, cloud accounts, and other high-value targets.
Passkeys and FIDO security keys offer stronger protection against both SIM swapping and common phishing attacks. Authenticator apps are also resistant to SIM swapping because the codes are generated through the app rather than delivered to the phone number.
Make Your Phone Number Less Powerful
SIM swapping is dangerous because a mobile number is often trusted by multiple systems at once.
You may not be able to prevent every criminal from trying to impersonate you, every data breach from exposing information, or every carrier employee from making a mistake.
You can make a successful SIM swap far less useful to an attacker.
Start with your carrier. Add the strongest available PIN, number lock, SIM-change protection, or port protection.
Then secure your primary email and other valuable accounts with passkeys, security keys, or authenticator-based MFA instead of relying on text messages or phone calls.
Finally, review your recovery settings. A strongly protected account can still be vulnerable if an attacker can bypass its security through an SMS password reset.
The best SIM-swap defense is not simply keeping control of your phone number. It is making sure that temporary loss of that number does not mean losing control of everything else.