SIM Swap Scam Explained: How Criminals Steal Your Phone Number, WhatsApp and Bank Accounts (2026 Guide)
Your phone can remain safely in your hand while a criminal takes control of your mobile number. This is called a SIM swap scam, and it can expose SMS verification codes, password-reset messages, WhatsApp registration and financial accounts that rely on your phone number.
What Is a SIM Swap Scam?
A SIM swap is an account-takeover attack against your mobile service. The attacker convinces the carrier to activate your phone number on a SIM card or eSIM controlled by the attacker. When the change succeeds, your existing cellular service may stop and incoming calls and SMS messages can be redirected to the attacker’s device.
The attacker does not necessarily need to steal your physical phone. The target is the mobile account and phone number. The Federal Trade Commission warns that criminals can use control of the number to receive text-message verification codes and attempt access to email, banking or other accounts. FTC: SIM Swap Scams
SIM Swap vs Unauthorized Number Porting
The two attacks can produce similar warning signs, but the carrier action is different:
- SIM swap: Your number is activated on another SIM or eSIM, usually within the carrier’s systems.
- Port-out fraud: Your number is transferred without permission from your current carrier to another provider.
Both can redirect calls and SMS messages away from you. Ask your provider whether it offers both SIM-change protection and a separate number or port-out lock. In the United States, the FCC treats SIM swapping and port-out fraud as related but distinct threats; carrier rules and consumer remedies vary in other countries. FCC: Port-Out Fraud
A SIM swap steals control of the phone number—not necessarily the phone itself.
How Can a Criminal Take Over Your Number?
SIM swapping normally involves social engineering. An attacker may collect personal details from data breaches, phishing messages, social-media profiles or previous scams. The attacker then impersonates the customer and requests a replacement SIM, eSIM activation or number transfer.
The exact carrier-verification process differs by country and provider. A successful attack may involve:
- Collecting the victim’s name, phone number and other identifying details.
- Contacting the carrier while pretending the phone was lost, damaged or replaced.
- Passing or bypassing the carrier’s identity checks.
- Activating the victim’s number on a SIM or eSIM controlled by the attacker.
- Using intercepted calls or SMS codes to attempt password resets and account recovery.
Why Is a SIM Swap So Dangerous?
Many services still treat a phone number as proof of identity. Once an attacker controls that number, it may become a gateway to several accounts.
Email often controls password resets for other services. If it is taken over, the attack can spread quickly.
Banking
SMS codes or phone-based recovery may expose financial accounts, depending on the bank’s security controls.
An attacker may attempt to register your number on another phone using an SMS or call verification code.
Social media
Phone-number recovery can be used to reset passwords or take over profiles that rely heavily on SMS.
Control of the number does not automatically reveal every old message, photo, password or bank balance. The damage depends on which accounts use the number, what other authentication is enabled and what the attacker already knows.
Seven Warning Signs of a Possible SIM Swap
- Your phone suddenly loses cellular service. Calls, SMS and mobile data stop even though you are in a normal coverage area.
- You receive a carrier notice about a SIM, eSIM or number change you did not request.
- Your carrier-account password or PIN no longer works.
- You receive unexpected password-reset or verification notifications.
- You are signed out of email, WhatsApp, banking or social accounts.
- Friends receive strange messages from your accounts.
- Your bank reports a new login, changed contact information or an unfamiliar transaction.
SIM Swap vs Port-Out Fraud vs SIM Cloning vs Phone Hacking
| Threat | What happens | Typical effect | Does the attacker need your phone? |
|---|---|---|---|
| SIM swap | The carrier moves your number to a different SIM or eSIM. | Your original line may lose service; calls and SMS go to the attacker-controlled line. | Usually no. |
| Port-out fraud | Your number is moved without permission to a different carrier. | Your old line loses the number; calls and SMS follow the unauthorized port. | Usually no. |
| SIM cloning | SIM credentials are copied or duplicated through a technical or insider attack. | A duplicate may attempt to connect as the same subscriber. | Not always, but access to SIM information or carrier systems may be required. |
| Phone hacking | Malware, stolen credentials or an exploited vulnerability compromises the device or accounts. | Data, apps, camera, microphone or accounts may be exposed. | Not always; phishing and remote attacks are possible. |
These terms are not interchangeable. A phone can be SIM-swapped without malware, and a hacked phone may still have normal cellular service. For wider device-security checks, read Is Your Phone Hacked? 12 Signs and How to Protect It.
How to Protect Yourself from SIM Swap Scams
1. Add a PIN or Passcode to Your Carrier Account
Ask your mobile provider whether it supports an account PIN, verbal password, number lock, port-out lock or extra verification before SIM and eSIM changes. Use a unique PIN that is not your birthday, address, phone-number ending or screen-lock code.
CISA guidance recommends adding a PIN and multifactor authentication to the mobile-carrier account to reduce SIM-swapping risk. CISA mobile communications guidance
2. Use Stronger Authentication Than SMS Where Possible
SMS two-factor authentication is better than using only a password, but it depends on control of the phone number. For important email, financial and social accounts, prefer one of these when supported:
- A passkey;
- A hardware security key;
- An authenticator app that generates codes locally; or
- A trusted-device prompt that does not depend only on SMS.
The FTC specifically notes that authenticator-app codes are not susceptible to a SIM-swap attack in the same way as SMS codes. FTC two-factor authentication guidance
3. Secure Your Primary Email First
Your main email account can reset many other accounts. Give it a unique password, stronger multifactor authentication, current recovery information and login alerts. Review active sessions and remove devices you do not recognize.
4. Harden Your Google or Apple Account
These accounts may protect email, cloud backups, saved passwords, photos and trusted devices. Review them before an emergency.
Google Account
Open your Google Account’s Security section, turn on 2-Step Verification, review recovery information and devices, and add a passkey, Google prompt or security key where suitable. Google states that prompts can help protect against SIM-swap and other phone-number-based attacks. Google 2-Step Verification
Apple Account
On iPhone, go to Settings > your name > Sign-In & Security > Two-Factor Authentication. Review trusted devices and consider adding another trusted phone number you can genuinely access. Security keys are an optional advanced feature for people facing targeted attacks. Apple two-factor authentication
Do not remove your only working recovery method without first testing a safer replacement. Passkeys and hardware security keys are strong options, but losing every trusted device, key and recovery method can lock you out.
5. Reduce Public Personal Information
Do not publish unnecessary details such as your full date of birth, home address, personal phone number or answers that resemble account-security questions. Treat unexpected calls and messages asking for carrier, SIM or account information as suspicious.
6. Turn On Security Alerts
Enable notifications for carrier-account changes, password resets, new-device logins, bank transfers and changes to recovery information. Fast warnings can reduce the time an attacker has control.
7. Use Unique Passwords
If the same password is used for your carrier, email and social accounts, one leak can multiply the damage. Use a reputable password manager and a different strong password for every important account.
8. Prepare a Recovery Plan
Write down your carrier’s official support number, keep an alternative contact method, and know how to reach your bank from a device other than your phone. Keep the phone’s IMEI and account information in a secure place.
Carrier PIN and SIM PIN Are Not the Same
Carrier-account PIN
Helps the provider verify you before making account changes. This is the more relevant control for a carrier-side SIM swap.
SIM PIN
Locks the existing physical SIM or eSIM against unauthorized cellular use after a restart or removal. It does not necessarily stop a criminal from deceiving the carrier into issuing a replacement.
How to Turn On a SIM PIN on Android and iPhone
A SIM PIN can add protection against someone using the SIM or eSIM already associated with your device. Menu names vary, and you must know the carrier’s default SIM PIN before enabling or changing it.
Android
- Open Settings.
- Tap Security & privacy.
- Open More security settings.
- Tap SIM lock, then enable Lock SIM.
This is Google’s current general Android path, but Samsung, Xiaomi, OnePlus, Motorola, OPPO and other manufacturers may place the option elsewhere. Use Settings search for “SIM lock” or “SIM PIN” if needed. Google Android theft-protection guidance
iPhone
- Open Settings.
- Tap Cellular.
- For one line, tap SIM PIN. With Dual SIM or Dual eSIM, select the number first, then tap SIM PIN.
- Turn on SIM PIN and enter the correct carrier-provided PIN.
Apple warns not to guess the default SIM PIN or PUK code because repeated incorrect entries can lock the SIM or eSIM and require carrier assistance or replacement. Apple: Use a SIM PIN
How to Protect WhatsApp from SIM Swap Attacks
WhatsApp registration normally depends on verifying the phone number. Turn on WhatsApp two-step verification so registration also requires a PIN.
- Open WhatsApp.
- Go to Settings > Account > Two-step verification.
- Turn the feature on and create a PIN you can remember.
- Add a secure recovery email when offered.
- Review Linked devices and sign out any device you do not recognize.
WhatsApp describes two-step verification as an optional security feature that adds protection to the account. WhatsApp two-step verification
Protect Banking and Financial Accounts
- Use the bank’s official app and enable transaction alerts.
- Prefer app approval, authenticator-based verification or a security key when the institution supports it.
- Never move money because a caller claims it must be transferred to a “safe” account.
- Do not approve a login or payment notification you did not initiate.
- Keep the bank’s official fraud number outside your phone.
Security options differ by bank and country. Contact the institution using the number printed on your card, statement or official website—not a number sent by the suspected attacker.
What to Do Immediately After a SIM Swap
- Contact your carrier immediately. Ask it to block the unauthorized SIM or eSIM, restore your number and place additional security on the account.
- Secure your primary email. Change its password, remove unknown recovery methods and sessions, and enable stronger multifactor authentication.
- Call banks and payment services. Report suspected account takeover, review transactions and follow their fraud procedures.
- Change passwords for high-value accounts. Prioritize email, banking, password manager, cloud storage, social media and cryptocurrency services.
- Revoke unknown sessions and devices. Do not assume a password change signs out every existing session.
- Recover WhatsApp. Obtain a replacement SIM with the same number from the carrier, register the number again, use the two-step verification PIN if enabled, and review linked devices. WhatsApp account recovery guidance
- Save evidence. Keep carrier messages, emails, screenshots, timestamps and transaction details.
- Report identity theft or fraud. Follow your country’s official reporting process and obtain a police report if required by the bank, insurer or carrier.
The FTC advises victims to contact the carrier, regain control of the number, change account passwords and check financial accounts for unauthorized activity. FTC recovery guidance
What Your Carrier Can and Cannot Do
| The carrier may be able to | The carrier usually cannot do for you |
|---|---|
| Disable the unauthorized SIM or eSIM and restore mobile service. | Recover your email, WhatsApp, social-media or banking account automatically. |
| Add an account PIN, port lock or extra verification where supported. | Reverse bank transfers, cryptocurrency transactions or purchases. |
| Provide records or a case number under its procedures. | Guarantee that every SMS code or call received by the attacker is erased. |
| Explain whether the line was moved, replaced or ported. | Replace the need to change passwords and revoke compromised sessions. |
SIM Swap Protection Checklist
Frequently Asked Questions
Can a SIM swap happen if I use an eSIM?
Yes. The attack targets control of the mobile account and phone number. A carrier may be deceived into activating the number on another physical SIM or eSIM, depending on its systems and verification procedures.
Is port-out fraud the same as a SIM swap?
No. A SIM swap activates your number on another SIM or eSIM, while port-out fraud transfers the number to another carrier. Both can redirect calls and SMS messages, so ask your provider about protection for both types of change.
Does a SIM PIN prevent SIM swapping?
Not necessarily. A SIM PIN protects the existing SIM or eSIM from unauthorized cellular use. A carrier-account PIN, number lock and stronger carrier verification are more directly related to preventing an unauthorized replacement or transfer.
Can a SIM swap reveal my old text messages?
It does not automatically copy the old messages stored on your phone. However, the attacker may receive new calls and SMS messages sent after the number is transferred and may use them to attack accounts.
Will turning off my phone stop a SIM swap?
No. A carrier-side number transfer can occur even when your phone is switched off. Turning off the device does not secure the carrier account.
Can a SIM swap take over WhatsApp?
An attacker who receives the registration code may attempt to register the number on another phone. WhatsApp two-step verification adds a separate PIN and makes that attempt more difficult.
Is SMS two-factor authentication useless?
No. SMS verification is generally better than relying only on a password, but it is vulnerable when an attacker takes control of the phone number. Use an authenticator app, passkey, trusted-device prompt or security key for important accounts when available.
How quickly should I act after losing service?
Immediately when unexpected signal loss is combined with a carrier-change notice or suspicious account activity. Contact the carrier and financial institutions from another trusted device.
Final Thoughts
A SIM swap can turn one stolen phone number into several account-recovery attempts. The best defence is layered: secure the carrier account, protect the primary email, reduce reliance on SMS for critical accounts, enable WhatsApp two-step verification and prepare recovery information before an emergency happens.
If your phone loses service unexpectedly, do not focus only on the device. Check the carrier account, email, financial accounts and messaging services at the same time.
Official References
- Federal Trade Commission: SIM Swap Scams
- CISA: Mobile Communications Best Practice Guidance
- FCC: Port-Out Fraud Targets Your Private Accounts
- Google Android Help: Protect Personal Data Against Theft
- Google Account Help: Turn On 2-Step Verification
- Apple Support: Use a SIM PIN
- Apple Support: Two-Factor Authentication for Apple Account
- WhatsApp Help: Two-Step Verification
Clear, practical and carefully researched technology guidance for everyday users.

Comments
Post a Comment