Reviewed September 2026.
A SIM swap (also called a SIM hijack or port-out attack) moves your mobile number to a SIM or eSIM the attacker controls. Once they own the number, they intercept SMS one-time codes for bank apps, email, crypto exchanges, and Apple or Google account recovery. This page is prevention and first-hour recovery. Broader login theft patterns: Phishing and account takeover.
What a SIM swap looks like
- You suddenly lose cellular service while Wi-Fi still works.
- Friends say your texts bounce or go to a stranger.
- You get a carrier email that a new SIM or port was approved, and you did not request it.
- Bank or email MFA codes never arrive, or someone else resets those accounts first.
Attackers often collect enough personal data from breaches, social media, or phishing to pass a weak carrier identity check. Harden the carrier account before that call happens.
Carrier PIN, passcode, and port freeze
Call the provider that bills and manages your mobile account (AT&T, T-Mobile, Verizon, or your MVNO’s own support, not necessarily a host-network “parent”) using the number on your bill or the official app, not a number in a text.
| Control | What to ask for | Why it helps |
|---|---|---|
| Account PIN / passcode | A PIN that is not your birthday, SSN last four, or “0000” | Stops many phone-based “verify me” social-engineering scripts |
| Port-out / number-transfer freeze | Freeze or extra authentication before the number can leave the account | Blocks unauthorized ports to another carrier |
| SIM change authentication | Require in-app or in-store ID for any SIM / eSIM swap | Stops remote “new phone” swaps |
| Account alerts | Email/SMS when SIM, port, or password changes | Faster notice if someone tampers |
Write the PIN in your password manager. Tell household members who can call on the account that the PIN is required; do not recite it to cold callers.
MFA that survives a stolen number
Prefer authenticator apps (Authy, Google Authenticator, Microsoft Authenticator) or hardware keys (YubiKey and similar) on email, banks (Chase, Bank of America, Capital One, Ally, local credit unions), brokerage, and Apple ID / Google Account. SMS MFA is better than nothing, but a SIM swap defeats it.
Order of lockdown after you set carrier PIN:
- Email password + app or hardware MFA first (password resets flow through email).
- Bank and brokerage apps next.
- Apple ID / Google Account, then social logins.
- Crypto exchanges and password managers last if those hold money or vault keys.
After a corporate password dump, pair this with Account takeover after a data breach.
Worked example: Maya loses bars at lunch
Maya’s phone shows “No Service” at 12:40. Wi-Fi still works. She opens her carrier app: a SIM change completed at 12:32 that she did not request.
- From Wi-Fi she emails the carrier fraud address listed in the app and calls the fraud line from a friend’s phone using the number on her paper bill.
- She changes her Gmail password and moves MFA from SMS to an authenticator app.
- She opens Chase and her credit-union apps over Wi-Fi, revokes unknown devices, and turns on transaction alerts.
- She freezes Equifax, Experian, and TransUnion that evening (Credit freezes and fraud alerts).
- She reports the incident at ReportFraud.ftc.gov and documents the carrier case number for the bank.
Total cash loss: $0 because the thief never cleared the new email MFA. Time cost: about three hours.
First hour if the swap already happened
- Contact the carrier fraud desk; demand the number restored to your SIM and a case ID.
- Change email and bank passwords from a trusted device on Wi-Fi; drop SMS MFA where a better factor exists.
- Review recent Zelle, wire, ACH, and card activity; dispute unauthorized items in writing.
- Freeze credit files if SSN or ID data may also be in play (Protect your SSN).
- Lock down public posts and friend lists that leak answers to “mother’s maiden name” style prompts: Lock down social media after a scam attempt.
- If new credit accounts appear, start Rebuild after identity theft.
Checklist
- Set a strong carrier account PIN; store it in a password manager.
- Ask for a port-out freeze or equivalent transfer lock.
- Require extra authentication for SIM / eSIM changes.
- Move email and money apps off SMS-only MFA.
- Turn on carrier and bank alerts for SIM, port, and device changes.
- If service dies without explanation, treat it as a security incident the same day.
Educational only. Not legal or cybersecurity advice. Carrier menus and freeze names differ; confirm steps in your carrier’s official app or bill inserts. Do not rely on phone numbers from unexpected texts.