Social Engineering & FraudMANIPULATIVE

SIM-Swap Fraud

What it is

Social engineering of a mobile carrier (or a bribed insider) to transfer a victim's phone number to the attacker's SIM, intercepting calls and texts, including the one-time codes that guard bank and crypto accounts.

How it works

A SIM swap attacks the weak link in phone-based security: the carrier's customer-service process. The attacker, armed with personal details from breaches, social media, or phishing, contacts the carrier posing as the victim and requests that the number be moved to a new SIM, or pays an insider to do it. Once the number ports, every call and SMS, crucially the one-time passcodes many banks and exchanges still send by text, arrives on the attacker's device, enabling account takeover and password resets. The tactic exposes why SMS is a weak second factor: possession of the number, not the person, is what the code proves. Lee and colleagues tested five major U.S. carriers in 2020 and found their authentication procedures could be defeated, allowing swaps. The FBI reported 1,611 SIM-swap complaints and more than 68 million dollars in losses for 2021 alone, a steep rise from prior years. The victim's first sign is often a phone that suddenly loses service for no reason.

Real-world examples

  • A crypto investor's phone abruptly shows "no service"; within minutes attackers who ported the number drain exchange accounts secured only by SMS codes.
  • Lee and colleagues demonstrated in 2020 that all five major U.S. prepaid carriers used authentication that could be defeated to authorize a SIM swap.
  • The FBI logged 1,611 SIM-swap complaints and over 68 million dollars in losses in 2021, up sharply from about 12 million dollars across the prior three years.
  • High-profile account takeovers, including a 2019 hijack of a major tech CEO's own social account, have been traced to SIM swapping.

Ethical guidelines

  • Hijacking someone's phone number by deceiving a carrier or bribing staff is fraud and identity theft; there is no legitimate version.
  • Carriers bear responsibility for weak porting authentication, and regulators increasingly require stronger identity checks before a number is moved.
  • Services that rely on SMS as a security factor owe customers stronger, phishing-resistant options.

How to defend against it

  • Move your important accounts off SMS codes to an authenticator app or, better, a hardware security key or passkey, which a swapped number cannot intercept.
  • Add a port-out PIN or "number lock" with your mobile carrier so the number cannot be transferred without a secret you set.
  • Treat a sudden, unexplained loss of cell service as a possible attack: contact your carrier immediately from another line and check your key accounts.
  • Reduce the personal data attackers use to impersonate you, and be alert that a carrier "verification" call you did not initiate may itself be the attack.
  • Keep bank and exchange alerts on by email as well, so a takeover in progress is visible even if your texts are hijacked.

From the Defense Playbook

Every playbook entry states how strong its evidence is and when not to use it. Browse the full playbook.

References

  1. Lee, K., Kaiser, B., Mayer, J., & Narayanan, A. (2020). An Empirical Study of Wireless Carrier Authentication for SIM Swaps. Proceedings of the Sixteenth Symposium on Usable Privacy and Security (SOUPS 2020), USENIX · link
    Testing of five U.S. carriers finding authentication procedures that could be defeated to authorize SIM swaps.
  2. Federal Bureau of Investigation, Internet Crime Complaint Center (2022). Criminals Increasing SIM Swap Schemes to Steal Millions of Dollars from US Public (PSA I-020822-PSA). FBI IC3 · link
    1,611 SIM-swap complaints and more than 68 million dollars in reported losses in 2021.
Last reviewed
Suggest a correction

Detect SIM-Swap Fraud in any text

Paste any message, email, or article into our free Manipulation Detector to see if SIM-Swap Fraud or other techniques are being used on you.

Related Articles