SIM Swapping
SIM swapping is an attack where criminals socially engineer a mobile carrier into transferring a victim's phone number to their SIM, hijacking SMS codes and accounts.
SIM swapping (also called SIM hijacking or port-out fraud) is an account-takeover technique in which an attacker convinces a mobile carrier to transfer the victim's phone number onto a SIM card the attacker controls. Once the number moves, every call and SMS — including one-time passcodes for banking, email, and corporate logins — goes to the criminal instead of the victim.
How it works
The attack is pretexting aimed at the carrier rather than the victim. The attacker first gathers personal details from data breaches, social media, or phishing — name, address, date of birth, last payment amount — then calls the carrier's support line posing as the victim, claiming a lost or damaged phone and requesting the number be moved to a "new" SIM or eSIM. In other variants, the attacker bribes or recruits retail-store insiders, or uses stolen carrier credentials to process the port themselves.
The victim's first clue is usually their phone dropping to "No Service." From that moment the attacker races to reset passwords on high-value accounts, intercepting the SMS verification codes that were supposed to protect them. Cryptocurrency wallets, bank accounts, and email are the typical first targets; for executives and system administrators, a swapped SIM can also unlock corporate VPNs and admin consoles that still rely on SMS-based authentication.
How to defend against it
Individually: add a port-out PIN or number-lock with your carrier, minimize the personal data that could answer "identity verification" questions, and treat a sudden loss of signal plus password-reset emails as an active emergency — contact your carrier and banks immediately.
Organizationally, the core fix is architectural: stop treating phone numbers as identity. Move employees — especially admins, finance staff, and executives — from SMS codes to app-based or, ideally, phishing-resistant FIDO2/passkey authentication, so a hijacked number no longer opens anything important. Quantifying who still relies on weak second factors is exactly the kind of signal a human risk score should capture, and helpdesk staff should be trained and tested against the same impersonation tactics carriers face — attackers who can't swap a SIM often try your own IT support desk next.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo