How to Prevent a SIM Swap Attack on Your Phone Number

SecurityPasswordScamsOnline Safety

The Problem

A SIM swap — also called SIM hijacking or a port-out scam — is when someone convinces your mobile provider to move your phone number to a SIM card they control. It takes a phone call and some personal details about you, most of which are already in breach data.

The moment it succeeds, your phone loses signal and every SMS verification code for every account goes to the attacker. They then reset your email password, then your bank, then everything else — because a phone number has quietly become the master key to modern account recovery.

Victims are usually chosen because they are visible: crypto holders, people with valuable social media handles, small business owners. But the technique is cheap enough to be used broadly, and the defence takes fifteen minutes.

Phone already lost signal for no reason and you cannot make calls? Skip to If It Is Happening Right Now below. Minutes matter.

If It Is Happening Right Now

  1. Call your mobile provider from another phone immediately. Say "I think my number has been ported without authorisation." Ask them to freeze the account and reverse it.
  2. From another device, change your email password and sign out of all sessions.
  3. Call your bank on the number on your card and ask them to lock outgoing transfers.
  4. Do not wait for signal to return. It will not come back on its own.

Then work through the prevention steps below so it cannot recur.

The Fix: Step-by-Step

Step 1: Add a Port-Out PIN or Number Lock With Your Carrier

This is the single most effective control. Every major carrier offers some version of it, though the name varies: Port Protection, Number Lock, Port Freeze, Account PIN, or Transfer PIN.

Call your provider or open the account settings in their app and:

  1. Set a port-out / transfer PIN that is not your date of birth, postcode, or the last four digits of anything.
  2. Enable port freeze or number lock if offered — it blocks transfers outright until you disable it.
  3. Ask them to add a note requiring in-person or PIN verification for any SIM change.

Store the PIN in your password manager, not in your phone's notes app.

Step 2: Move Two-Factor Authentication Off SMS

SMS is the weakest common second factor precisely because it depends on your number. Replace it wherever the option exists.

Priority order:

  1. Passkeys — nothing to intercept. See set up passkeys.
  2. Authenticator app — Microsoft Authenticator, Google Authenticator, Aegis, or your password manager's built-in codes. Setup in set up two-factor authentication.
  3. Hardware security key — strongest for high-value accounts.
  4. SMS — only where nothing else is offered.

Do email first, then banking, then everything else.

Step 3: Remove Your Number as a Recovery Method Where You Can

Adding app-based 2FA does not help if your phone number is still listed as a password-reset route — the attacker simply uses the weaker path.

On each major account, go to security settings and either remove the phone number as a recovery option or downgrade it so it cannot on its own reset the password. Replace it with a recovery email you control plus offline recovery codes.

Walkthrough: set up account recovery options.

Step 4: Reduce What an Attacker Can Learn About You

Carrier verification questions are answered with information that is often public: date of birth, address, mother's maiden name, the last number you called.

Step 5: Use a Separate Number for Account Recovery

Where a phone number is unavoidable, use one that is not your public number — a second SIM, or a VoIP number from Google Voice or similar that is not held by a mobile carrier and therefore cannot be SIM-swapped.

Keep that number private: never give it to shops, sign-up forms, or delivery services.

Step 6: Turn On Every Alert Your Bank and Carrier Offer

Speed of detection determines how bad this gets.

  • Carrier: enable alerts for SIM changes, plan changes, and new devices — sent to email, not SMS.
  • Bank: enable push notifications for every transaction and every login, with no minimum threshold.
  • Email: enable new-device sign-in alerts.

An email alert reading "your SIM has been updated" that you did not request is your fifteen-minute warning.

Step 7: Consider eSIM and a Device PIN

An eSIM is harder to swap in practice because it requires more than convincing a shop assistant to hand over a physical SIM. Where your carrier and phone support it, moving to eSIM is a modest improvement.

Separately, set a SIM PIN on the physical card (iPhone: SettingsMobile DataSIM PIN; Android: SettingsSecuritySIM card lock). This does not stop a port-out, but it stops someone using your stolen physical SIM in another handset.

Step 8: Rehearse the Response

Write down, and keep offline:

  • Your carrier's fraud line number.
  • Your bank's fraud line number.
  • Your account recovery codes for email and password manager.

Anyone who has been through this will tell you the same thing: the difficulty is not knowing what to do, it is finding phone numbers and codes while your phone has no signal and your email is being reset.

Why SMS Codes Are Still Everywhere

| Factor | Resists SIM swap | Resists phishing | |---|---|---| | SMS code | No | No | | Authenticator app code | Yes | No | | Push approval | Yes | Partially | | Passkey | Yes | Yes | | Hardware key | Yes | Yes |

SMS survives because it works on every phone with no setup. It is better than no second factor — it is simply the one to move away from first.

What Not to Do

  • Do not use SMS 2FA on your email account. Email is what resets everything else; give it the strongest factor you have.
  • Do not store your carrier PIN on your phone in a notes app. If the phone is lost or compromised, so is the PIN.
  • Do not confirm details to someone who calls claiming to be your carrier. Hang up and call the number on your bill. See avoid tech support scam calls.
  • Do not ignore a brief unexplained loss of signal, especially if it happens while you are somewhere with normally good coverage.

FAQ

How would someone SIM swap me without my phone?

They call the carrier posing as you, supply details harvested from breaches and social media, and claim the phone was lost or damaged. The carrier activates the number on a new SIM. In some cases an insider at a retail store is paid to do it directly. Your physical phone is never involved.

What is the very first sign?

Sudden loss of mobile signal with no explanation — no calls, no texts, no mobile data, while Wi-Fi still works. If you also receive an email about a SIM or plan change you did not request, treat it as confirmed and act immediately.

Is SMS two-factor still better than nothing?

Yes, clearly. It stops automated credential-stuffing attacks, which are far more common than targeted SIM swaps. The point is not to remove SMS from accounts with no alternative — it is to stop relying on it for email, banking, and anything holding money.

Does a port-out PIN actually stop it?

It stops the common version, where the attacker relies on social engineering alone. It is not absolute — insider fraud and carrier process failures still occur — which is why it is paired with moving 2FA off SMS rather than used instead of it.

Can they do this if my phone is switched off or in a drawer?

Yes. The swap happens at the carrier, not on your handset. Your phone simply stops working whenever you next look at it.

I got my number back. What else needs doing?

Change every password that could have been reset while they had the number, starting with email, then banking, then everything else. Review sign-in activity and connected apps on each: review and revoke app access and active sessions. Check for mailbox forwarding rules, which are commonly left behind.

Still Not Working?

If your carrier is slow to reverse an unauthorised port, escalate to their fraud department in writing and file a report with your national telecoms regulator and fraud reporting service. Keep a written timeline — banks and carriers both respond faster to a clear record of when the number left your control.

Related: recover a hacked email account, recover a hacked Microsoft account, spot scam text messages (smishing).