SIM swapping is one of the most effective attacks against accounts protected with SMS-based 2FA. It requires no hacking skill โ just a phone call to your carrier.
What Is a SIM Swap Attack?
An attacker calls your mobile carrier and impersonates you, claiming they've lost their phone or SIM card. Using personal information gathered from social media, data breaches, or phishing, they convince the carrier to transfer your phone number to a new SIM card they control.
Once your number is on their SIM, they can receive all your SMS messages โ including every 2FA code sent to that number.
How Attackers Get Your Personal Information
Carriers typically ask verification questions like your billing address, last four digits of your Social Security number, or account PIN. Attackers obtain this through:
- Data breaches โ billions of records including SSNs are available on dark web markets
- Social media mining โ birthdays, addresses, pet names used in security questions
- Phishing calls pretending to be carrier support
- Insider threats โ corrupt carrier employees
Real Consequences
SIM swapping has been used to steal cryptocurrency worth millions. In documented cases, attackers have drained entire exchange accounts within minutes of completing a SIM swap. By the time the victim notices something is wrong, the funds are gone.
Notable SIM Swapping Cases
SIM swapping has been responsible for some of the largest individual thefts in cybercrime history:
- Michael Terpin (2018) โ Lost $23.8 million in cryptocurrency through a SIM swap attack on AT&T, subsequently suing AT&T for $200 million.
- Jack Dorsey (2019) โ The then-CEO of Twitter had his own account compromised via SIM swapping.
- Joel Ortiz (2019) โ A 20-year-old who stole over $5 million in cryptocurrency through SIM swapping and was sentenced to 10 years in prison.
Technical Deep Dive: How the Attack Works
- Target identification โ The attacker identifies a victim with valuable accounts and gathers personal information through social media, data breaches, or phishing.
- Carrier contact โ The attacker calls the victim's mobile carrier, impersonating the victim with social engineering, fake IDs, or bribed employees.
- SIM activation โ The carrier transfers the phone number to a SIM card controlled by the attacker. The victim's phone immediately loses service.
- Account takeover โ The attacker uses SMS-based password reset flows to gain access to email, financial accounts, and crypto wallets.
- Asset theft โ The attacker drains accounts before the victim realizes what happened.
Carrier-Specific Protection Features
- T-Mobile โ "Account Takeover Protection" and "SIM Protection" can be enabled through the T-Mobile app
- AT&T โ "Extra Security" passcode required for account changes
- Verizon โ "Number Lock" prevents unauthorized port-outs
Contact your carrier and ask them to add a PIN or passcode requirement for any SIM changes or port-out requests. This is the single most important step you can take.
How to Protect Yourself from SIM Swapping
1. Switch from SMS 2FA to an Authenticator App
TOTP codes are generated on your device and are not tied to your phone number. SIM swapping has zero effect on authenticator app-based 2FA. This is the single most important step.
2. Set a Port Freeze / SIM Lock with Your Carrier
Most major carriers allow you to place a port freeze or number lock on your account. This requires in-store verification (with ID) to make any SIM-related changes โ making remote SIM swapping nearly impossible.
3. Set a Unique Carrier PIN
Use a carrier-specific PIN or passcode (separate from your account password) that must be provided before any account changes. Don't use predictable numbers like your birthday.
4. Use a Google Voice Number for SMS 2FA
If SMS 2FA is required on a service that doesn't support authenticator apps, use a Google Voice number. Google Voice numbers require Google account authentication to access โ much harder to hijack than a carrier number.
What to Do If You're SIM Swapped
- Call your carrier immediately โ report the SIM swap and restore your number
- Change passwords on all accounts accessible via your number
- Contact your bank and crypto exchanges if financial accounts were exposed
- Review and disable SMS 2FA on all accounts, switching to authenticator apps
Why Carriers Keep Falling for It
Carrier support agents are measured on fast call resolution, which pressures them to complete SIM transfers quickly. Attackers exploit this: they act hurried and confident, cite account details bought from data breaches, and ask to escalate to a supervisor if the first agent hesitates. Some attacks never involve a phone call at all โ a forged ID presented at a store, or an employee paid a few hundred dollars to process the transfer.
The security of your number ultimately depends on your carrier's verification policy, not on you. That is why setting a carrier PIN or account lock matters so much: it shifts the decision from an agent's judgement to a secret only you know. If your carrier offers biometric verification, a port freeze, or in-store-only SIM changes, enable every one of those options.
Signs You Might Be a Target
Attackers choose targets by expected value: cryptocurrency holders, public figures, business executives, and anyone whose number is tied to financial SMS alerts. You are more exposed if your phone number is visible on social media, if you post about investments, or if your details appear in a known data breach โ services like haveibeenpwned tell you which breaches your email or number appear in. Being anonymous does not guarantee safety; some operations target numbers in bulk through call centres rather than selecting victims individually.
A practical middle ground: use SMS 2FA only where no better option exists, keep an authenticator app for everything important, and treat any unsolicited call claiming to be from your carrier with suspicion โ especially one that asks you to "confirm" a PIN or read back a code. Legitimate carriers never ask for the 2FA codes delivered to your phone.
eSIM Swapping: How the Attack Evolved
eSIMs removed the plastic card but not the attack. Instead of requesting a replacement physical SIM, the attacker asks the carrier to move your number to an eSIM profile they can activate with a QR code or a confirmation code on their own device. From the carrier's perspective it is the same transfer process, and from the attacker's perspective the outcome is identical: your number lands on hardware they control and every SMS sent to it โ including 2FA codes โ is theirs to read.
Ask your carrier whether eSIM transfers are covered by the same PIN and port-freeze protections as physical SIM swaps. Some carriers require in-store verification for eSIM moves, while others allow self-service eSIM transfers from the account portal, which is exactly the kind of convenience an attacker wants. If your carrier offers a separate toggle to block eSIM transfers without verification, enable it.
The First 15 Minutes of a Suspected Swap
Your phone suddenly shows No Service or SOS Only while another phone in the house works fine โ that is the moment to move, not to investigate. Call your carrier from a landline or a second phone immediately and report a SIM swap, asking them to freeze the account and restore your number. Then change the password of your primary email from a device on a different network, because that inbox is the reset hub for everything else.
Next, check your bank and crypto exchanges for recent transactions and notifications of logins or address changes you did not make, and look through your email for reset messages sent in the last hour. Write down what you saw and the times โ support teams ask for a timeline, and screenshots of the notifications make the report concrete. Do not use the affected phone for anything until your carrier confirms the number is back on your SIM.
Which Accounts to Move Off SMS First
If you cannot migrate everything to authenticator apps in one sitting, prioritise by damage. Your primary email comes first โ it resets every other account you own. Then banking and payment apps, then crypto exchanges, and only after those, social media and work accounts. For each one, disable SMS as the 2FA method and enrol a TOTP app or hardware key instead.
For services that insist on a phone number, use a number you do not rely on for other accounts โ a Google Voice number or a dedicated prepaid SIM that is not linked to your identity โ and add a recovery method that is not SMS. Keep a list of which accounts still use SMS and re-check it every few months; the accounts you never think about are the ones attackers try first.
Why a Carrier PIN Helps but Isn't a Silver Bullet
A carrier PIN stops the casual social-engineering call, but it does not stop every path: attackers have used forged IDs at retail stores, bribed insiders, and PIN resets via other verification questions. Treat the PIN as one layer rather than the finish line, and combine it with a port freeze, in-store-only SIM changes, and TOTP everywhere the platform allows it.
The deeper lesson is that your phone number is someone else's infrastructure. Even with perfect carrier hygiene, you cannot fully control how a support agent in another timezone verifies callers. That is why security experts keep saying the same thing: move every important account off SMS-based 2FA, because the carrier is the weak link you cannot patch โ you can only stop depending on it.