One Tuesday afternoon, my cousin’s phone went dead. No bars, no calls, no texts. She assumed it was a tower issue. Within an hour, her bank account was empty, her email was locked, and someone had taken over her Instagram. That is what a SIM swap attack looks like in real life.
A SIM swap attack is a type of fraud where criminals convince your mobile carrier to transfer your phone number to a SIM card they control. Once they hold your number, they receive every call and text meant for you, including the one-time codes that protect your bank, email, and crypto accounts. It is one of the fastest-growing phone scams, and most victims never see it coming.
In this guide, I’ll walk you through exactly how a SIM swap attack works, the warning signs to watch for, and the specific steps I use to lock a phone number down before an attack happens. You’ll also get a recovery checklist and FAQ answers based on what real victims on Reddit have shared.
Table of Contents
- What a SIM Swap Attack Looks Like (And Why It’s So Dangerous)
- How SIM Swap Attacks Actually Work: A Step-by-Step Breakdown
- Warning Signs Your Number Has Been Hijacked
- How to Lock Down Your Phone Number Before an Attack Happens
- Carrier-Specific SIM Protection Setup
- What to Do If You’re Hit by a SIM Swap Attack?
- Frequently Asked Questions About SIM Swap Attacks
- Final Thoughts on Locking Your Number Down in 2026
What a SIM Swap Attack Looks Like (And Why It’s So Dangerous)
A SIM swap attack is a form of identity theft where a scammer convinces your phone carrier to move your number to a new SIM card that they own. From that moment on, your phone loses service, and every text or call routed to your number goes straight to the attacker’s device instead.
Your SIM card (subscriber identity module) is the tiny chip that ties your phone number to your device. When that link moves to the attacker’s SIM, they essentially become you in the eyes of the mobile network. Banks, email providers, and crypto exchanges use your phone number as proof of identity. The attacker now holds that proof.
Why this matters: Modern security relies on two-factor authentication (2FA), where a code sent by SMS proves it’s really you logging in. SIM swap attacks bypass SMS-based 2FA completely because the codes arrive in the attacker’s phone, not yours. The FTC, FBI, and every major carrier in 2026 have flagged it as a top-five consumer scam.
Real-world damage is not theoretical. In 2019, Twitter’s CEO Jack Dorsey was SIM swapped and used to post racist messages from his own account. A Maryland woman lost $17,000 in a single afternoon despite claiming she had protection in place. On Reddit’s r/personalfinance, victims describe three-week recovery nightmares involving drained bank accounts, hijacked email, frozen business credit lines, and lost photos during forced device resets.
High-Profile SIM Swap Incidents That Changed the Industry
Several public cases pushed SIM swapping into the mainstream:
Jack Dorsey (2019): Twitter’s CEO lost control of his own account for about 30 minutes after a SIM swap targeted his carrier. The attacker posted offensive tweets before Twitter regained control.
The “SIM Swapping Ring” busts (2018-2021): Federal prosecutors charged nine people in a $2.4 million crypto theft ring that targeted at least 50 victims, including Silicon Valley executives and crypto investors.
Michael Terpin ($24 million, 2020): A crypto investor sued AT&T after attackers allegedly bribed a carrier employee to swap his SIM. The lawsuit argued AT&T’s security was “amateurish,” and the case is now a landmark reference for carrier liability.
How SIM Swap Attacks Actually Work: A Step-by-Step Breakdown
A SIM swap attack unfolds in four phases: gathering your personal data, social engineering your carrier, transferring your number, and draining your accounts. Understanding the timeline helps you spot the attack while there’s still time to stop it.
Phase 1 – Reconnaissance (Days to Weeks)
Attackers buy or scrape personal information about you from data brokers, social media, and breach databases. They hunt for full name, date of birth, address, and the last four digits of your Social Security number. Sometimes this data comes from corrupt carrier employees who sell account details for a few hundred dollars. In one Reddit thread, multiple victims learned their details came from inside the carrier itself.
Phase 2 – Social Engineering the Carrier (15 to 60 Minutes)
The attacker calls your carrier’s support line pretending to be you. They say the phone was lost, damaged, or stolen, and ask to activate a new SIM card with your number. If they pass the security questions, the carrier issues a new SIM and deactivates yours. Carrier training and authentication practices vary widely, which is why this step succeeds more often than it should.
Phase 3 – Number Transfer (Instant)
Once the swap completes, your phone shows “No Service” or “SOS Only.” The attacker’s phone rings with your number. They now control every SMS-based verification process tied to that number.
Phase 4 – Account Takeover (30 to 90 Minutes)
With SMS in hand, the attacker triggers password resets on your email, bank, crypto exchange, and social media. The reset codes come to their phone. They change passwords, add their own 2FA, and lock you out. Then they wire out money, sell off crypto, or pivot to your contacts for further scams.
Minute-by-Minute Attack Timeline
| Time | What’s Happening |
|---|---|
| 0:00 | You notice your phone has no signal. You restart it. Nothing changes. |
| 0:10 | Carriers may send a “SIM updated” or “transfer complete” confirmation to your email. |
| 0:20 | Attacker triggers password resets on your email and primary accounts. |
| 0:45 | Banking apps receive unauthorized transfer requests. |
| 1:30 | Attacker locks you out of email and uses it to attack your contacts. |
| 3:00 | Crypto wallets, cloud storage, and social media fall one by one. |
This is the window where fast action matters. If you react before the 1:30 mark, you can often stop the bleeding.
Warning Signs Your Number Has Been Hijacked
The first warning sign of a SIM swap attack is sudden, complete loss of cell service that does not come back after a restart. Most other signals arrive after the damage has begun, which is why speed matters.
The Tell-Tale Signs to Watch For
No service when you should have it: Your phone displays “No Service,” “SOS Only,” or an empty signal indicator, and switching airplane mode on and off does not bring it back.
Calls and texts stop coming through: Friends may message you on WhatsApp asking why your phone is off.
Carrier notifications: Some carriers email or text you when a SIM swap is processed, sometimes just before or just after the attacker acts.
Login alerts you did not request: Email providers and banks may send confirmation of password resets or new device sign-ins.
Account lockouts: You suddenly cannot log in to email, banking, social media, or crypto apps because passwords or recovery methods have changed.
Unfamiliar transactions or withdrawals: Check bank and credit card apps immediately if you suspect a swap, even if you can still log in.
Battery draining quickly: Some victims report unusual battery drain in the minutes right before a swap attempt.
One Reddit user described it simply: “I lost signal during a meeting. By the time I called my carrier, my Gmail was gone, my Coinbase was empty, and they were already messaging my contacts pretending to be me.” If your phone goes dark and you did not request any change, treat it as an emergency.
How to Lock Down Your Phone Number Before an Attack Happens
To lock down your phone number, add a carrier port-out PIN, enable your carrier’s SIM Protection feature, and switch all SMS-based 2FA to app-based authenticators. No single step is bulletproof, but stacking them drops your risk dramatically.
1. Add a Port-Out PIN or Account Passcode
Call your carrier and request a port-out PIN, account passcode, or “Number Transfer PIN.” This PIN is required before anyone can move your number to another SIM or carrier. Without it, social engineering becomes much harder. Store this PIN in a password manager, not in your phone’s notes app.
2. Enable Your Carrier’s SIM Protection Feature
All three major US carriers now offer a free “SIM Protection” or “Wireless Account Lock” feature. Enabling it blocks SIM swaps and number ports until you enter the protection PIN in person or through your verified account. Activation typically takes less than five minutes (see carrier-specific steps below).
3. Move All 2FA Off SMS and Onto Authenticator Apps
App-based authenticators like Authy, Google Authenticator, or 1Password do not rely on your phone number. Even if an attacker steals your number, they cannot read those codes. Use SMS 2FA only as a last resort.
SMS-Based 2FA vs App-Based 2FA
| Feature | SMS-Based 2FA | App-Based 2FA |
|---|---|---|
| Vulnerable to SIM swap | Yes | No |
| Works offline | No | Yes |
| Phishable | Yes (interception attacks) | No |
| Setup difficulty | Easy | Easy to moderate |
| Recommended | No | Yes |
4. Use a Hardware Security Key Where Possible
For high-value accounts (banking, crypto, primary email), a physical hardware key like a YubiKey or Titan Key adds a layer that cannot be intercepted remotely. The key sits in your physical possession, so even a perfect SIM swap fails.
5. Reduce Your Personal Data Footprint
Attackers need data to social engineer your carrier. Lock down your social media profiles, remove birthdate, address, and phone number from public sites, and request that data brokers remove your records. Each bit you strip away makes the recon phase slower and noisier.
6. Set Up Account Activity Alerts
Turn on login notifications for email, banking, and crypto accounts. The faster you hear about a suspicious login, the faster you can react. Many victims only learn about the swap after money has already moved.
Carrier-Specific SIM Protection Setup
Each major US carrier offers a SIM Protection feature that blocks number transfers without your private PIN. Here is how to enable it on Verizon, AT&T, and T-Mobile, plus what to know about eSIM security.
Verizon SIM Protection
Open the My Verizon app or sign in at verizon.com.
Go to Account, then Account Security.
Select “SIM Protection” and toggle it on.
Create a 6 to 10-digit PIN you will remember but is not tied to your birthday.
Verify with your account passcode.
From that point, any in-store or phone-based SIM change requires both your account PIN and the SIM Protection PIN. Verizon will also send a confirmation text or email whenever a swap is attempted.
AT&T Wireless Account Lock
Sign in to your AT&T account via the app or att.com.
Open Account, then “My Digital Features.”
Choose “Wireless Account Lock” and turn it on.
Set a unique passcode and a separate “Number Transfer PIN.”
Save and verify the changes.
AT&T added Wireless Account Lock after its 2020 legal troubles with crypto investor Michael Terpin. The feature also blocks number porting, not just SIM swaps, which closes another common attack vector.
T-Mobile SIM Protection
Open the T-Mobile app or log in at t-mobile.com.
Tap your profile, then “Account,” then “Line Settings.”
Select “SIM Protection” and turn it on.
Set a strong PIN separate from your account PIN.
Confirm by entering the PIN twice.
T-Mobile also offers a “Number Transfer PIN” under the same menu, which prevents port-out scams. Enabling both gives you the strongest defense T-Mobile currently offers.
eSIM Security Considerations
eSIMs are digital SIM cards stored inside your phone’s hardware. They are not immune to SIM swap attacks. Attackers can still convince a carrier to assign your number to a new eSIM on a device they own. The defenses listed above apply to both physical SIMs and eSIMs. Treat your number, not your card type, as the asset to protect.
What to Do If You’re Hit by a SIM Swap Attack?
If you suspect a SIM swap attack, call your carrier from another phone immediately, freeze your financial accounts, and treat every password as compromised. The first hour is the most important.
Immediate First Hour Actions
Call your carrier from a different phone. Ask them to suspend SIM changes and port-outs on your account.
Lock or freeze your bank and credit card accounts. Use the mobile apps or call the number on the back of your card.
Reset passwords from a trusted device. Start with email, then banking, then crypto and social media.
Enable app-based 2FA immediately on every account that still allows it.
Place a fraud alert with the credit bureaus. Equifax, Experian, and TransUnion all support one-call fraud alerts that propagate to the others.
Filing Reports and Getting the Carrier to Act
File a police report and an identity theft report with the FTC at IdentityTheft.gov. Share those report numbers with your carrier’s fraud department in writing. Insist on a paper trail. Some carriers have been ordered by courts to compensate victims when their internal employees were involved.
Realistic Recovery Timeline
| Stage | What to Expect |
|---|---|
| Day 1-2 | Regain control of your number and primary email. |
| Week 1 | Reset passwords across all accounts; fraud alerts filed. |
| Week 2-3 | Banks investigate transfers; crypto exchanges review transactions. |
| Month 1-3 | Disputes resolved or denied; some funds may be unrecoverable. |
Recovery is rarely fast. Many Reddit users describe a three-week sprint just to plug the holes, with full financial recovery taking months. Treat that timeline as motivation to lock things down before an attack happens.
Frequently Asked Questions About SIM Swap Attacks
How do I tell if someone has SIM swapped me?
The biggest sign is sudden, complete loss of cell service that does not return after a restart. You may also receive unexpected password reset emails or login alerts from your bank, email, or social media accounts. If your phone is dead and money is moving, treat it as a SIM swap emergency.
Can someone SIM swap me even if I have a PIN?
Yes, if the attacker convinces a carrier employee to bypass the PIN, sells your info to a co-conspirator inside the carrier, or tricks you into revealing the PIN through phishing. A carrier PIN raises the bar but is not a guarantee, which is why stacking multiple defenses matters.
How do I stop someone from porting my mobile number?
Set up a Number Transfer PIN or port-out PIN through your carrier, enable SIM Protection or Wireless Account Lock, and remove your phone number from public data broker sites. These steps force any port request to fail without your private PIN.
How do I block SIM cloning?
SIM cloning is different from SIM swapping. To block cloning, set a SIM card PIN in your phone’s security settings so the card cannot be used without it, and report any unexplained loss of service to your carrier immediately. App-based 2FA also limits the damage because codes do not go through your SIM at all.
Final Thoughts on Locking Your Number Down in 2026
A SIM swap attack is one of the few scams where the phone in your pocket turns against you. The good news: every major carrier now offers the tools to stop it, and they cost nothing. Turn on SIM Protection today, switch to app-based 2FA on your most important accounts, and set a port-out PIN you have never used anywhere else. If you do those three things before an attack happens, you remove roughly 90% of the risk we see in real victim reports.