SIM Swap Fraud Explained: How Criminals Hijack Your Phone Number

SIM swap fraud is one of the most unsettling scams in existence — because the victim often does nothing wrong. One moment your phone works normally; the next, it goes dead. Meanwhile, a criminal somewhere else is receiving your calls and texts, resetting your passwords, and draining your accounts. Your phone number, which you use to prove your identity everywhere, is suddenly working for someone else.

This guide explains exactly how SIM swap fraud works, the real cases behind the headlines, the warning signs, and the concrete steps you can take to protect yourself.

What Is SIM Swap Fraud?

In SIM swap fraud, a criminal convinces your mobile carrier to transfer your phone number from your SIM card to a SIM card the criminal controls. The FBI describes it plainly: once the swap is done, the victim’s calls, texts, and other data are diverted to the criminal’s device.

The critical part is what comes next. So many of your accounts — email, banking, social media, crypto wallets — use your phone number for password resets and two-factor authentication (2FA) codes sent by text. With your number in hand, the criminal can request “Forgot password” links, intercept the SMS verification codes, and walk straight into your accounts. As the FBI’s Internet Crime Complaint Center (IC3) warns, the criminal then uses those codes to log in and reset passwords, gaining control of online accounts tied to your phone profile.

This is not a hack of your phone. Your device is fine — it’s your carrier account that gets tricked.

How the Attack Works, Step by Step

Step 1: The criminal collects your personal information

Attackers start by gathering details that help them impersonate you: your full name, address, date of birth, phone number, and sometimes the last digits of your Social Security number or answers to security questions. Sources include data breaches, phishing emails and texts, social media oversharing, and public records. The FBI specifically warns against advertising financial assets — including cryptocurrency holdings — on social media and forums, because it paints a target on your back.

Step 2: The criminal contacts your carrier

Using social engineering, the attacker calls your mobile carrier pretending to be you, claiming the phone was lost, stolen, or damaged, and asks to activate a new SIM on “your” number. In other cases, criminals use an insider threat — paying off a carrier store employee to perform the swap — or phishing attacks that trick carrier employees into downloading malware that lets attackers execute swaps remotely.

Step 3: The number moves — and your phone goes dark

If the carrier is fooled, your number is reassigned to the criminal’s SIM. Your phone suddenly loses service: no calls, no texts, no data. Many victims first assume it’s a network outage.

Step 4: The criminal resets your passwords and steals

Now holding your number, the attacker triggers password resets on your email, bank, and other accounts, intercepts the SMS verification codes, changes the passwords — locking you out — and transfers money, buys things, or drains crypto wallets.

Real Cases: This Is Not Theoretical

The insider case (2026): In September 2026, a former AT&T store employee in Portland, Oregon — Kenneth Carter, 44 — was sentenced to 16 months in federal prison for selling his carrier access to a hacker. According to the Department of Justice, Carter used victims’ personal information to fraudulently swap their SIMs to phones he and co-conspirators controlled, then intercepted password-reset texts and two-factor authentication codes for victims’ online bank accounts. The scheme caused nearly $600,000 in intended losses across at least three victims; one victim had $99,528 fraudulently transferred to a Portuguese bank account. Carter typically received $1,000 to $2,000 per SIM swap. This case shows the “insider threat” route is real — sometimes the person performing the swap works inside the phone store.

The scale (FBI data): The FBI’s IC3 reported just 320 SIM swapping complaints from January 2018 through December 2020 (about $12 million in losses). In 2021 alone, that jumped to 1,611 complaints with more than $68 million in losses — a roughly fivefold increase. In the FBI’s 2024 Internet Crime Report, SIM swap appeared as its own crime category with 982 complaints and nearly $26 million in reported losses. The numbers are smaller than phishing, but the per-victim damage is severe.

Warning Signs Your Number May Have Been Swapped

  • Sudden, total loss of mobile service — your phone shows “No Service” or “SOS only” and can’t make calls or send texts, even in an area with good coverage. This is the classic first sign.
  • Unexpected carrier notifications — a text or email saying your SIM was activated on a new device, or that account changes were made that you didn’t request.
  • Login alerts you didn’t trigger — password-reset emails, “new sign-in” notifications, or 2FA codes arriving when you aren’t logging in anywhere.
  • Being locked out of accounts — your email or bank password suddenly doesn’t work.
  • Contacts report strange messages from “you” — the criminal may text your contacts while controlling your number.

If your phone loses service unexpectedly, don’t assume it’s a glitch — treat it as a potential SIM swap and act immediately.

9 Ways to Protect Yourself From SIM Swap Fraud

These defenses come straight from FBI and FTC guidance:

  1. Set a PIN or password on your carrier account. This is the single most important step. Every major carrier lets you add a PIN or passcode required before account changes — including SIM swaps — can be made. It adds a credential the attacker must defeat.
  2. Move critical accounts off SMS-based 2FA. The FTC explicitly warns that “text message verification may not stop a SIM card swap.” Wherever possible, switch your email, bank, and other sensitive accounts to an authenticator app or a physical security key, which aren’t tied to your phone number.
  3. Limit personal information you share online. Don’t post your full name, address, phone number, or financial details on public sites and social media. Attackers use these to answer the carrier’s identity-verification questions.
  4. Don’t respond to calls, texts, or emails asking for personal information. The FTC notes these are often phishing attempts aimed at harvesting the details needed to impersonate you to your carrier. If someone claims to be your carrier, hang up and call the official customer-service number yourself.
  5. Use unique passwords for every account. If one account is breached, unique passwords stop the attacker from chaining into the rest.
  6. Don’t store passwords or login details in mobile apps. The FBI advises against keeping usernames and passwords saved in apps on your phone.
  7. Turn on login and transaction alerts. Enable email and text notifications for your bank, email, and other important accounts so you spot unauthorized access fast.
  8. Ask your carrier about extra protections. Some carriers offer number-lock features, port-out PINs, or notes requiring in-person changes. Ask what’s available and enable all of it.
  9. Treat data breaches seriously. Breaches expose exactly the personal details used to socially engineer a SIM swap. If your data appears in a breach, strengthen the accounts that matter most.

What to Do If Your SIM Is Swapped

Speed matters — every minute the attacker holds your number is another minute they can reset passwords.

  1. Contact your carrier immediately — from a different phone. Tell them you’ve been SIM-swapped. Ask them to reverse the swap, reattach your number to your SIM, and flag the account for fraud.
  2. Change your passwords from a trusted device — a computer, not the phone that just lost service. Start with your email account (it’s the master key to everything else), then banking and financial accounts. Use the carrier’s restored number carefully: don’t request SMS codes until you’re sure the number is back under your control.
  3. Call your bank and financial institutions. Tell them your number was hijacked. Ask them to lock withdrawals, flag suspicious logins, and dispute any unauthorized transactions.
  4. Check every account for unauthorized changes — new payees, changed email addresses, unfamiliar devices.
  5. File reports: a police report, a complaint with the FBI’s IC3 at ic3.gov, and an identity-theft report at IdentityTheft.gov if personal information was compromised. Consider a credit freeze with the major bureaus if your Social Security number may be exposed.
  6. Warn your contacts — attackers sometimes message your friends and family pretending to be you.

The Bottom Line on SIM Swap Fraud

SIM swap fraud works because your phone number has quietly become a master key to your digital life — and SMS-based verification codes are only as secure as your carrier account. A carrier PIN, authenticator apps instead of text-message codes, and tight control over your personal information dramatically raise the bar for attackers. Set those protections up today, before your phone ever goes dark.

Sources

  1. U.S. Department of Justice, “Oregon Man Sentenced to 16 Months in Federal Prison for Abusing His Role at Mobile Phone Store to Give Customers’ Info to Criminals” (Sept. 8, 2026) — https://www.justice.gov/usao-cdca/pr/oregon-man-sentenced-16-months-federal-prison-abusing-his-role-mobile-phone-store-give
  2. FBI Internet Crime Complaint Center, “Criminals Increasing SIM Swap Schemes to Steal Millions of Dollars from US Public” (PSA220208, Feb. 2022) — https://www.ic3.gov/PSA/2022/PSA220208/
  3. FBI Phoenix Field Office, “FBI Tech Tuesday: SIM Swapping” (Sept. 27, 2022) — https://www.fbi.gov/contact-us/field-offices/phoenix/news/press-releases/fbi-tech-tuesday-sim-swapping
  4. FBI Internet Crime Complaint Center, “2024 Internet Crime Report” — https://www.ic3.gov/AnnualReport/Reports/2024_IC3Report.pdf

Last reviewed: October 2026

This article is for education only and is not financial or legal advice.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top