Guide

How to protect your number from a SIM swap attack

SIM swapping is not hacking. Someone walks into a shop or calls support, convinces a human being that they are you, and your number moves to their SIM. Your phone falls silent and every code follows them. Three defences actually work — a locked carrier account, fewer accounts that depend on SMS, and a separate line for the codes that matter — plus a recovery order for the hour when it is already happening.

  • 11 min read
  • 8 sections
  • Updated 
Illustration: a padlock clamped over a phone's SIM tray while a duplicate SIM card is rejected and breaks apart
On this page
  1. What a SIM swap attack actually is
  2. The warning signs you have minutes to notice
  3. Lock the carrier account — the step that blocks the transfer
  4. Take SMS off the critical path
  5. Separate the number people can find from the number that receives codes
  6. If it has already happened: recovery, in order
  7. Key facts
  8. FAQ

What a SIM swap attack actually is

A SIM swap is not a hack of your phone. Nobody breaks into your device, your operating system or your apps. Someone contacts your mobile carrier, claims to be you, and asks for your number to be moved to a SIM they control — a new plastic card in a shop or, increasingly, an eSIM profile activated in seconds from an app. The carrier obliges, your handset drops off the network, and from that moment every call and every text meant for you arrives on their phone instead.

The number is the prize because so much is anchored to it. Banking one-time codes, exchange withdrawals, password-reset links, work chat, delivery confirmations — all of it flows to whoever holds the line right now. The attacker usually has your password already, from a breach or a phishing page; the swap is the last step that turns a stale password into a live account takeover.

There are only three ways a number moves, and all three run through a human being:

  • The retail counter: a walk-in with a convincing story and a borrowed or forged ID.
  • The support line: an agent whose script accepts a date of birth, an address and the last four digits of a card — details that sit in old data leaks.
  • The insider: a shop or call-centre employee paid a few hundred dollars to run the transfer, which is why even a perfect account PIN is not an absolute defence.

You will see the same attack called SIM swapping, SIM jacking, port-out fraud or SIM splitting. The mechanics are identical; only the paperwork differs, depending on whether your number moves to a new SIM at the same carrier or to a different operator entirely.

FeatureCarrier port-out lockAuthenticator app or passkeyA separate line for codes
What it actually stops The transfer itselfA stolen code being usefulCodes ever reaching the targeted line
Who has to cooperate Your carrierEach service, one by oneNobody
Time to set up Ten minutes, onceTwo minutes per accountUnder 60 seconds
Cost FreeFreeFrom $3.58/month
Works where SMS is the only option YesNoYes
Tied to your legal identity Yes, it is your carrier accountNoNo, crypto-only billing
Still useful after a swap happens No, it is prevention onlyYesYes
Covers accounts you cannot change YesNoYes, once the number on file is updated
Typical weak point An employee overriding the lockLosing the device with no backup codesLosing the account credentials

The warning signs you have minutes to notice

A SIM swap announces itself, but quietly, and the window between the transfer and the first emptied account is often under an hour. The most reliable symptom is silence: your phone shows No Service or SOS only while Wi-Fi still works perfectly. Data over Wi-Fi keeps flowing, so a handset on a home network can look entirely normal until you try to place a call.

Watch for these, and treat any two of them together as an emergency rather than a coincidence:

  • Sudden loss of mobile service with no outage in your area and no change of location.
  • A carrier notification confirming a SIM change, an eSIM activation or a transfer request you did not make.
  • Password-reset emails for accounts you never touched, above all for your primary mailbox.
  • Being signed out of messengers — a re-registered number kicks the old device off WhatsApp, Telegram or Signal.
  • Login alerts from unfamiliar places, or a two-factor prompt for an app you are not opening.
  • Small unexplained transactions that test whether a card still works before something larger is attempted.

Attackers often start the transfer late in the evening or over a weekend, when carrier fraud desks are thin and a dead phone is easy to mistake for a flat battery. If your handset goes silent at an odd hour, check it instead of assuming a network glitch: switch airplane mode on and off, and if service does not come back, call your carrier from another line straight away.

Lock the carrier account — the step that blocks the transfer

Everything else on this page limits the damage. Only one measure stops the swap from happening at all: telling your carrier in advance that this number may not move without a proof an attacker cannot produce.

The feature exists almost everywhere but carries a different name in every market — number lock, port freeze, port-out PIN, SIM protection, transfer PIN. Ask for it by describing what you want: no SIM replacement and no transfer to another operator without this passcode, in person, with ID. Then tighten the account around it:

  • Set a dedicated passcode you use nowhere else, and never a birthday, a postcode or the last four digits of anything printed on a card.
  • Delete the security questions or answer them with random strings kept in your password manager. Your mother's maiden name is public record; your first pet is on your own social feed.
  • Ask what an agent can override, and whether shop staff can bypass the lock. The honest answer tells you what the lock is actually worth at your carrier.
  • Check the notification address on the account. If confirmations go to an old mailbox you no longer read, you have lost your only early warning.
  • Get your number off people-search sites so you are not on the list of easy targets to begin with — our guide to keeping your real number private walks through the opt-outs.

Regulation has helped. In the United States, carriers have been required since 2024 to authenticate the account holder properly before moving a number to a new SIM or a new operator, and to notify them when such a request is made. Several European and Asian operators apply comparable rules. None of it closes the insider route, which is why the next two sections matter.

Take SMS off the critical path

Assume for a moment that the swap succeeds. What can the attacker actually do with your number? Exactly as much as you have allowed it to unlock. The point of this step is to make a stolen line boring.

Rank your second factors and move every account you can up the list:

  • Passkeys and hardware security keys — nothing about them touches the phone network, so a swapped number is worthless against them.
  • Authenticator apps (TOTP) — codes are generated on the device rather than delivered to the number. Keep the recovery codes offline, on paper.
  • Push approvals in a provider's own app — bound to the app installation, not to the SIM.
  • SMS codes — a last resort, and only where the service offers nothing better.

Then close the trap that catches almost everyone. Moving to an authenticator app changes nothing if the same account still offers lost access? we will text you a code as a recovery path: the attacker walks through the back door and ignores the front one you reinforced. In every account's security settings, remove the phone number from account recovery, not only from login.

Work through your accounts in the order an attacker would. Primary email first, because it resets everything else, then your password manager, then banking and any crypto exchange, then cloud storage, domain registrar and social accounts. Our guide to receiving one-time codes online covers the practical side of moving codes away from your personal SIM.

Some services genuinely refuse to drop SMS — many banks, most delivery platforms, a surprising number of government portals. That residue is exactly what the next defence is for.

Separate the number people can find from the number that receives codes

An attacker cannot swap a number they cannot identify. Before anything else happens they need your number, the operator it sits on, and enough about you to sound plausible at a support desk. Every one of those facts comes from the same place: the number you have been handing out for a decade, sitting in breach dumps, marketplace listings, delivery apps and data-broker profiles next to your name, your address and your carrier.

So split the roles. Keep your personal SIM for family, your employer and the two or three institutions that genuinely need it, and give a separate dedicated line to everything that sends you codes. That second line does not live at a retail carrier at all, which removes the attack path instead of defending it:

  • No shop counter and no consumer support desk that can be talked into a transfer with a birthday and an address.
  • No identity on the account to research or impersonate — PrivacyNumber asks for no ID and bills in crypto, so there is nothing to social-engineer against.
  • Not in the leak beside your name. The number criminals correlate with you is the old one, and it no longer receives anything worth stealing.
  • Real, dialable lines in 47 countries — mobile ranges banks and messengers accept, not the throwaway VoIP ranges most services now reject.
  • Long-term, not disposable — the same line still works next year, which is the whole point when it is on file at your bank.

Be clear about what this does not do. Any provider with humans in the loop has some social-engineering surface, interception at the network level is a separate and real problem, and a dedicated line only helps once you have actually changed the number on file at the accounts that matter. What it removes is the specific, cheap, industrialised attack described on this page — the one that starts at a mobile shop. Lines start at $3.58/month and activate in under 60 seconds.

If it has already happened: recovery, in order

Speed matters more than completeness. Work down this list from another phone or a computer, and do not stop to investigate — investigate afterwards.

  1. Call your carrier from any other line and say the words: my number has been transferred without my authorisation. Ask for the transfer to be reversed and the account frozen against further changes.
  2. Secure your primary email next: new password, sign out of every session, then check for forwarding rules, filters and recovery addresses the attacker added. An unnoticed forwarding rule keeps them inside long after you get the number back.
  3. Lock the money. Call your bank's fraud line and your exchange's support, freeze withdrawals, and reverse anything still pending.
  4. Rotate and revoke — password manager, cloud storage, domain registrar, social accounts, in that order, signing out of all sessions as you go.
  5. Re-register your messengers once the number is back, and check each one for linked devices you do not recognise.
  6. File the reports: carrier fraud department, your national telecom or consumer regulator, and a police report, which banks generally require before they will even discuss reimbursement.
  7. Write down timestamps as you go — when service died, when each notification arrived, who you spoke to. That record is what disputes are decided on.

Afterwards, treat the number as burned for anything sensitive. It has proven it can be moved, and it now sits on a list of numbers that were successfully targeted once. Move your codes to a line the attacker has never seen — and if you want to know what you are moving to before you commit, read how traceable a virtual number really is.

Key facts

  • A SIM swap is social engineering against your carrier, not a hack of your phone — no malware is involved.
  • The first symptom is silence: "No Service" or "SOS only" while Wi-Fi keeps working normally.
  • A number lock or port freeze on the carrier account is free, and it is the only measure that blocks the transfer itself.
  • Since 2024, US carriers must authenticate the account holder before moving a number, and must notify them of the request.
  • Passkeys and authenticator apps survive a swap; SMS codes do not.
  • Removing your number from account recovery matters more than upgrading the login method.
  • A separate, non-carrier line for codes has no retail counter and no identity on file to impersonate.

Frequently asked questions

  • How do I know if I have been SIM swapped?

    Your phone loses mobile service — "No Service" or "SOS only" — while Wi-Fi keeps working, and you are signed out of your messaging apps. Password-reset emails you did not request usually follow within minutes. A single symptom can be a network fault; two together should be treated as an attack in progress.

  • Can a SIM swap happen with an eSIM?

    Yes, and faster. An eSIM profile is provisioned remotely, so there is no plastic card to post and no shop to visit — an approved transfer can be live in under a minute. The defence is identical: lock the carrier account so no profile can be issued without your passcode.

  • Does a carrier PIN really stop a SIM swap?

    It stops the common version, where an attacker talks a support agent through your date of birth and address. It does not stop a bribed employee who can override the lock from inside the system. Set the PIN, and still assume that a determined attacker may get through.

  • Can someone SIM swap a virtual phone number?

    Not in the same way, because there is no SIM and no carrier retail channel to social-engineer. The risk moves to your provider account: whoever holds those credentials receives the messages. Use a unique password and a non-SMS second factor on that account and the classic swap simply has nowhere to happen.

  • Is SIM swapping the same as SIM cloning?

    No. Cloning copies the secret keys off a SIM card and needs physical access plus outdated card hardware; it is rare today. Swapping needs no technical skill at all — only a carrier employee convinced that the person asking is you. Almost every real-world case is a swap.

  • Should I stop using SMS two-factor authentication completely?

    Use the strongest factor each service offers, and keep SMS where nothing better exists — it still beats a password alone. What matters is which line those texts land on. SMS delivered to a dedicated number that is not published anywhere is a far smaller target than SMS on the number in every breach dump.

  • What should I do in the first five minutes?

    Call your carrier from another phone and ask them to reverse the transfer and freeze the account. Then, from a computer, change your primary email password and sign out of all sessions. Everything else — banks, exchanges, reports — comes after those two steps, in that order.

Keep reading

A real number you own.
No ID. Pay in crypto.

Real local mobile or landline lines in 47 countries — calls, SMS, voicemail and AI auto-pickup, live in 60 seconds. No identity required.