Losing a phone’s signal for a few hours doesn’t sound like a financial emergency — until it turns out someone else just became your phone number. A SIM swap moves your number onto a criminal’s SIM card, and from that point on, every “forgot password” text and every two-factor code meant for you goes straight to them instead. Here’s how these takeovers happen, and why a phone number is a much bigger security weak point than most people realize.
How the Scam Works
Step 1: Gathering Enough Personal Information to Impersonate You
Scammers collect enough identifying details — name, date of birth, address, the last four digits of a social security or account number — usually from data breaches, phishing, or information posted publicly on social media, to convincingly impersonate the real account holder to a mobile carrier.
Step 2: Contacting the Carrier to Request the Swap
Posing as the account holder, the scammer contacts the mobile carrier (by phone, chat, or occasionally by bribing or tricking an employee) claiming to have lost or damaged their phone, and requests the number be moved to a new SIM card the scammer controls.
Step 3: The Real Phone Loses Service, Often Unnoticed at First
The victim’s actual phone suddenly loses signal entirely — no calls, no texts, no mobile data — which is frequently mistaken for a network outage or a phone glitch rather than recognized immediately as an active account takeover in progress.
Step 4: Draining Accounts Using Intercepted Codes
With the phone number now under their control, the scammer requests password resets and two-factor codes on banking, email, and crypto exchange accounts, receiving those codes directly since they now control the number those accounts trust — often draining funds within a very short window before the victim realizes what happened.
A Composite Example (Illustrative, Not a Real Case)
Imagine someone’s phone suddenly shows “No Service” one afternoon. Assuming it’s a network issue, they carry on with their day, only checking it again that evening — by which point their email password has been reset, their bank has sent (and had confirmed) a large transfer, and their crypto exchange account shows a completed withdrawal to an unfamiliar wallet. This scenario is a composite built from commonly reported patterns — it does not describe a real person, carrier, or event.
Red Flags That Get Missed
- Sudden, total loss of phone signal with no calls, texts, or data working, especially with no known outage in the area.
- A text from your carrier confirming a SIM card change or new device activation that you didn’t request.
- Password-reset emails for accounts you didn’t try to reset, arriving in a short burst.
- Being unable to log into an account that normally uses SMS-based two-factor authentication, because the code is now going to someone else’s device.
- Personal information (full name, date of birth, address) being unusually easy to find across your own public social media profiles.
- An account lockout notification for a service you use, arriving without any action from you.
How to Protect Yourself
- Set up a PIN or passcode with your mobile carrier specifically required for any SIM changes or account changes, if the carrier offers this (most major carriers in the US, UK, Canada, and Australia do).
- Move two-factor authentication away from SMS and onto an authenticator app or hardware security key wherever a service supports it, since app-based and hardware codes aren’t tied to your phone number at all.
- Limit how much personal information (full birthdate, address, mother’s maiden name) is publicly visible on social media, since this is exactly what’s used to pass a carrier’s identity checks.
- Treat a sudden, total loss of phone signal as a possible security event, not just an inconvenience, and check with your carrier directly if it happens unexpectedly.
- Use a unique, strong password on your email account specifically, since email is usually the master key a scammer uses to reset everything else once they control your number.
- Consider a secondary, non-phone-based recovery method (a backup email, a hardware key) for your most important accounts, so a captured phone number alone isn’t enough to break in.
If You Think Your SIM Has Been Swapped
Contact your mobile carrier immediately, using a landline or another person’s phone if needed, to report the unauthorized SIM change and have it reversed. Then contact your bank, email provider, and any exchange or financial account, changing passwords and reviewing recent activity as soon as access is restored.
Report to your country’s official fraud authority:
- United States: FTC — reportfraud.ftc.gov, and the FBI Internet Crime Complaint Center (IC3) — ic3.gov
- United Kingdom: Action Fraud — actionfraud.police.uk or reportfraud.police.uk (0300 123 2040)
- Canada: Canadian Anti-Fraud Centre — antifraudcentre-centreantifraude.ca, report at reportcyberandfraud.canada.ca
- Australia: Scamwatch (National Anti-Scam Centre / ACCC) — scamwatch.gov.au, report at scamwatch.gov.au/report-a-scam
If you’re outside these countries, search for your national consumer protection agency or fraud reporting unit — most countries now have a dedicated online reporting channel.
Frequently Asked Questions
How do scammers get enough information to pass as me to my phone carrier?
Often through data breaches, phishing, or details posted publicly on social media – full name, date of birth, and address are frequently enough to pass a basic identity check unless a carrier-side PIN is also required.
Is losing phone signal for a short time always a sign of a SIM swap?
No, network outages happen for ordinary reasons too – but a sudden, total, unexplained loss of signal is worth checking directly with your carrier rather than assuming it will resolve on its own, especially if it coincides with unexpected account activity.
Why is SMS-based two-factor authentication risky against this specific scam?
SMS codes are sent to whichever SIM currently holds your number – once a scammer controls that SIM, they receive those codes instead of you, which is exactly what makes a SIM swap effective against accounts protected only by text-message codes.
Can a carrier PIN fully prevent a SIM swap?
It significantly raises the bar by requiring something beyond basic identity details, though it isn’t absolute protection if an employee is tricked or the PIN itself is somehow compromised – moving two-factor authentication off SMS remains an important second layer.
What should I do first if I suspect my number has been swapped?
Contact your mobile carrier immediately from another phone or landline to report and reverse the unauthorized change, then move quickly to secure your email and financial accounts once your number is restored.
Browse more resources in our Scam Awareness category.
