When Your Phone Number Turns Against You
SIM swapping turns a phone number into a master key. How carriers get socially engineered, what the SEC X account hack showed, and how to defend your org.

On January 9, 2024, a man walked into an AT&T store in Huntsville, Alabama, with a fake ID he had printed that morning. Minutes later he walked out with a replacement SIM card for a phone number he did not own — the number tied to the US Securities and Exchange Commission's @SECgov account on X. His co-conspirators used the password-reset code it received to post a fake announcement that spot Bitcoin ETFs had been approved. Bitcoin jumped more than $1,000 on the news, then fell by more than $2,000 when the SEC regained control. The man with the printer, Eric Council Jr., was sentenced to 14 months in prison in May 2025. He had been paid about $50,000 for performing swaps like this one.
No malware. No phishing email. No password stolen. The entire compromise of a US federal agency's most visible communications channel came down to one retail employee accepting one fake ID — because a phone number, in most organizations, is still quietly accepted as proof of identity.
This guide covers how SIM swapping works, what the data says about where it is heading, and how to get your organization's most important accounts off the phone number entirely.
The phone number became a password nobody chose
Over two decades, phone numbers accumulated authentication duties they were never designed for: SMS one-time passcodes, voice-call verification, password-reset flows, and "forgot my authenticator" fallbacks. The number became a de facto master credential — yet it is administered not by your security team but by a telecom carrier whose support staff are measured on how quickly they resolve a locked-out customer's problem.
Academic researchers demonstrated how fragile that arrangement is. In a Princeton study presented at USENIX SOUPS 2020, all five US prepaid carriers tested used authentication challenges that attackers could defeat — such as verifying identity with recent call records or payment details an attacker can plant or look up. The same team analyzed over 140 websites and found 17 where an account could be taken over with a SIM swap alone, no password needed; nine of those sites had not fixed the issue after disclosure.
An attacker who controls your number does not need to break your authentication. They are your authentication.
How the attack works
Every SIM swap is pretexting aimed at the carrier rather than the end victim. The playbook varies by route:
| Route | What the attacker needs | What the victim sees |
|---|---|---|
| Support-line impersonation | Victim's personal data (from breaches, social media, infostealer logs) to pass "identity verification" questions | Phone drops to No Service; reset emails arrive |
| Retail store with fake ID | A printed fake ID and confidence — the SEC attack's route | Same, often outside business hours |
| Insider at the carrier | A bribed or recruited employee processing the port directly | Same, with no failed-verification trail |
| Hijacked carrier account / eSIM | The victim's carrier-portal credentials (phished or stuffed); transfer completes digitally | Same, and can be done at scale |
Once the number moves, the attacker works fast: password resets on email first (to control recovery everywhere else), then banking, crypto, and — in the corporate variant — VPNs, SSO fallback flows, and admin consoles that still deliver codes by SMS. The victim's phone shows one bar of nothing while their digital life is rekeyed.
A SIM swap is not a phone problem. It is an identity-architecture problem that happens to begin at a phone store.
What the numbers say
The headline US trend looks like good news — until you see where the attack went. The FBI's Internet Crime Complaint Center logged 1,611 SIM swap complaints with $68 million in losses in 2021, up from just 320 complaints across the three prior years combined. By the FBI's 2024 Internet Crime Report, US complaints had fallen to 982 with about $26 million in reported losses — a real improvement, plausibly helped by carrier hardening and new regulation.
But the attack did not shrink; it moved. In the UK, fraud-prevention body Cifas recorded almost 3,000 unauthorized SIM swaps in 2024 — a 1,055% surge from 289 cases the year before, and nearly half of all account-takeover cases filed involved mobile phone accounts. SIM swapping is also a documented tool of the groups that most worry enterprise defenders: CISA and the FBI's joint advisory on Scattered Spider lists SIM swap attacks alongside push bombing and help-desk impersonation in the group's standard identity playbook.
Why this is your problem, not just your employees' problem
It is tempting to file SIM swapping under personal crime — crypto theft, drained bank accounts. The enterprise exposure is more direct than that.
In August 2023, an attacker SIM-swapped the T-Mobile number of a single employee at Kroll, the claims administrator handling the FTX, BlockFi, and Genesis bankruptcies. According to Kroll, the carrier transferred the employee's number without any contact with Kroll or the employee. With the number came access to systems holding bankruptcy claimants' personal data — which promptly fueled targeted phishing waves against thousands of creditors. One number, one employee, three downstream breach notifications.
The corporate attack surface is any place a phone number still stands in for identity: SMS-based MFA on VPN or SSO, voice-call verification for wire approvals, phone-number recovery on executives' email accounts, and the "call the employee to verify" step in your own help desk's reset procedure. Attackers who cannot swap a SIM often pivot to impersonating employees to the IT help desk — the same pretext, aimed at your weakest verifier instead of the carrier's.
What changed in 2024: the FCC steps in
US regulation now backstops part of the defense. FCC rules that took effect in July 2024 require wireless carriers to use secure methods of authenticating customers before SIM changes or port-outs, to notify customers immediately when such a request is made, to offer free account locks that block SIM changes and ports until removed, to train employees against fraudulent requests, and to keep records of SIM-change fraud for three years.
That raises the floor — it does not raise the ceiling. The rules deliberately avoid prescribing specific authentication methods, insider recruitment bypasses process entirely, and none of it protects your organization's accounts from the numbers you do not manage. The architectural fix is still yours to make.
Getting your organization off the phone number
A practical sequence, in priority order:
- Inventory where phone numbers authenticate. Pull the MFA-method report from your identity provider. Every account whose second factor is SMS or voice — and every account whose recovery path is a phone number, even if the primary factor is strong — is in scope. Recovery flows are where this control usually leaks.
- Move high-value users to phishing-resistant MFA first. Admins, executives, finance, and anyone who can approve payments or access customer data should be on phishing-resistant MFA — FIDO2 keys or passkeys — which a swapped SIM cannot touch. App-based codes are an acceptable interim step; they live on the device, not the number.
- Lock the carrier side for the people who matter most. For executives and privileged users, require carrier account locks and port-out PINs — now free by regulation in the US — on both corporate-managed and, where they consent, personal numbers used for work recovery.
- Remove numbers from recovery chains. An account with a passkey front door and an SMS-reset back door is an SMS-protected account. Replace phone-based recovery with backup codes held offline or admin-mediated recovery with real identity verification.
- Harden your own "carrier." Your help desk is the in-house version of that AT&T store. Apply the same standard you wish carriers did: verification that does not rely on lookupable facts, callbacks to numbers on file, and extra friction for resets on privileged accounts.
- Treat sudden signal loss as a security event. Teach employees — in onboarding and in awareness training — that No Service plus unexpected reset emails means call security first, not the carrier queue. Minutes matter; the Kroll attacker needed very few of them.
- Exercise it. Add a SIM swap scenario to your tabletop program: an executive's number ports at 6 p.m. on a Friday — who notices, who can revoke sessions, and which systems would the attacker already own? The answers tend to reshape priorities 2 and 4.
SIM swapping persists because it exploits a dependency most organizations have never consciously chosen and therefore never review. Map where the phone number still equals identity, measure which of your people would be hit hardest — the visibility a human risk score is designed to provide — and retire the number from the job it was never hired to do.
Frequently asked questions
What is SIM swapping?
SIM swapping (also called SIM hijacking or port-out fraud) is an account-takeover technique in which an attacker convinces a mobile carrier to move a victim's phone number onto a SIM or eSIM the attacker controls. The deception targets the carrier, not the victim: the attacker impersonates the customer at a support line or retail store, often using personal details from breaches or social media. Once the number moves, every SMS one-time passcode and password-reset call goes to the attacker.
Does SIM swapping defeat multi-factor authentication?
It defeats SMS- and voice-based MFA, because those factors are delivered to the phone number rather than bound to a device. After a swap, the attacker receives the codes your systems send. App-based authenticators are better, and phishing-resistant methods — FIDO2 security keys and passkeys — are unaffected entirely, because the credential lives on hardware the attacker never touches. That gap is why moving admins, executives, and finance staff off SMS codes is the single highest-value defense.
How do I know if my SIM has been swapped?
The classic first sign is your phone suddenly dropping to "No Service" in a place where it normally works, often followed by password-reset emails you did not request. Since July 2024, US carriers are required to notify customers immediately when a SIM change or port-out is requested on their account. Treat the combination of lost signal and unexpected reset messages as a live incident: contact your carrier from another line, lock your financial accounts, and alert your security team before the attacker finishes resetting passwords.
Are eSIMs safe from SIM swapping?
No. eSIM provisioning removes the need for a physical card, but the number transfer is still authorized by the same carrier processes that attackers social-engineer. In some cases eSIMs make the fraud easier, because a transfer can be completed entirely through a hijacked carrier account or a support call, with no store visit or mailed SIM. The defense is the same: carrier-level locks and port-out PINs, and removing the phone number from the authentication chain wherever possible.
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo