How a SIM swap takes over a phone number without stealing the handset
How carrier account takeover moves a number to an attacker’s SIM, breaks SMS two-factor codes, and differs from a simple network outage.
Article prepared with AI assistance, then verified, edited, and approved by Nicolas Coutant.
The short version
A SIM swap is not theft of a physical phone. It is an attack on the carrier account that controls a phone number. A fraudster persuades the mobile provider to move the number onto a SIM they control. The victim’s handset suddenly shows no service; the attacker starts receiving calls and SMS, including one-time passwords.
That break matters because many accounts still treat an SMS code as proof of identity. Once the number moves, SMS-based two-factor authentication becomes a delivery channel for the attacker. This guide decodes the mechanism, separates it from a network glitch, and points to the institutional descriptions from the U.S. Federal Trade Commission (FTC) and the Cybersecurity and Infrastructure Security Agency (CISA). It is not a recovery playbook or legal advice.
How it works
The number — not the handset — is the asset. Carriers maintain a mapping between a subscriber identity and a SIM. Changing that mapping is a normal support operation when someone loses a phone or upgrades hardware. SIM-swap fraud abuses the same workflow.
Typical sequence:
- Reconnaissance. Attackers gather personal details that make an impersonation sound plausible: name, address, account hints, answers that appear in breaches or social profiles.
- Impersonation at the carrier. Posing as the account holder, they claim loss, theft or a device change and ask for a new SIM or an eSIM transfer.
- Transfer. If verification is weak or secrets are guessed, the carrier activates the number on the attacker’s SIM and deactivates the victim’s.
- Account takeover. SMS reset codes and voice OTPs arrive on the attacker’s device. Banking, email and social logins that trust SMS become reachable without touching the victim’s phone.
A tower outage or regional network fault usually affects many people in an area and clears when the network recovers. A SIM swap looks like a sudden, personal loss of service while the number stays live elsewhere — a different failure mode of the identity system.
What is sourced
The FTC’s consumer page on SIM-swap scams describes the attack as tricking a mobile provider into transferring a phone number to a SIM the scammer controls, then using intercepted texts to break into accounts. It frames the problem as social engineering against the carrier relationship, not malware on the handset.
CISA’s public note on SIM swapping likewise treats the number transfer as a path to intercept authentication messages and take over online accounts. Both agencies emphasise that SMS-delivered codes inherit the security of the carrier account: if that account can be socially engineered, the code channel fails with it.
Those institutional descriptions are the evidentiary spine here. Vendor blogs and bank marketing pages may retell the same story; they are not required to understand the mechanism the FTC and CISA already publish.
Caveats
Carrier verification practices differ by provider and country. A PIN, passcode or in-store identity check can raise the bar; none of the public agency pages claim a single global procedure. This article does not inventory every operator’s internal script.
Aggregate fraud statistics quoted in commercial roundups are not reproduced here unless they appear on the institutional pages used as sources. Individual risk depends on how exposed personal data is and whether SMS remains the only second factor on high-value accounts.
Recovering funds, disputing a carrier decision or pursuing civil claims sits outside this decode. The mechanism explanation stops at how the number moves and why SMS trust collapses afterward.
What's next
Defences target the weak link the agencies describe: the carrier account and the SMS channel.
Setting a carrier account PIN or passcode that must be presented before SIM or number changes forces the attacker to know a secret that is not usually sitting in a public profile. Moving important logins off SMS toward authenticator apps or hardware keys removes the phone number as a single point of failure for those accounts. A sudden “no service” message in a coverage area that otherwise works is a practical signal to contact the carrier and freeze changes — not proof by itself, but a reason to check whether the number was remapped.
None of those steps invent a new law; they follow from the same model the FTC and CISA describe: protect the carrier relationship, and stop treating SMS as strong proof of identity.
Going further
- SIM swap scams — FTC — Official U.S. consumer explanation of how number transfers enable account takeover.
- SIM swapping — CISA — Federal cybersecurity note on intercepting authentication via SIM remapping.
Sources
Found an error? Email us — we correct factual mistakes and note significant updates on the article. Contact us
Keep exploring
Remote work monitoring software: what is measured, what is restricted, and the gap with performance
A breakdown of activity logs, screenshots, and productivity scores in remote work tools, alongside EU legal limits on data collection.
Read the article →Health and fitness app data: what platforms can infer beyond a step count
A breakdown of how wellness apps collect device data, manage permissions, and share sensitive health information with third parties.
Read the article →Credit freeze vs fraud alert: what each does after a data breach
A breakdown of the procedural differences between a credit freeze and a fraud alert in the US system, based on FTC guidance and recent breach reports.
Read the article →