SardineCon SF/2026

Learn More

O que é SIM swap?

SUBSCRIBE

A SIM swap is the hijacking of a victim's mobile number by tricking or bribing the carrier into moving it to an attacker-controlled SIM, so text one-time codes and calls reach the fraudster and enable account takeover. It defeats the SMS codes that many accounts still rely on, and it is often set up by phishing for the personal data needed to pass carrier checks.

What is a SIM swap, in plain English?

A SIM swap moves a victim's phone number onto a SIM the attacker controls. Legitimately, carriers do this when you upgrade a phone or replace a lost SIM. In a SIM swap attack, the fraudster impersonates the victim to the carrier, or bribes an insider, and gets the number reassigned to their own SIM. From that moment, calls and texts meant for the victim arrive on the attacker's device.

The prize is the victim's one-time codes. Because so many services send verification codes and reset links by SMS, controlling the number lets the attacker reset passwords and pass two-factor checks for email, banking, and crypto accounts. The victim, meanwhile, sees their own phone lose all service, usually the first and only sign that something is wrong.

SIM swap is typically preceded by phishing or data gathering to collect the personal details, name, date of birth, account information, and sometimes a PIN, needed to convince the carrier. In the fraud stack it is a form of number hijacking and a close relative of port-out fraud, and it is a leading enabler of account takeover, especially for crypto holders.

How a SIM swap attack works

  1. Gather — Collect the details. The attacker phishes or buys the victim's personal data to answer the carrier's identity questions.
  2. Impersonate — Trick or bribe the carrier. Posing as the victim, or paying an insider, they request the number be moved to a new SIM.
  3. Capture — Receive the codes. Once the swap completes, texts and calls, including one-time codes, land on the attacker's phone.
  4. Take over — Reset and drain. They reset passwords and pass SMS verification to seize email, banking, and crypto accounts.

SIM swap versus port-out fraud

What changes

Port-out fraud

SIM swap

The mechanism

Number ported to a different carrier

Number reassigned to a new SIM on the same carrier

Who is tricked

The gaining carrier's porting process

The current carrier's support or a bribed insider

Common setup

Stolen details and a port PIN

Phishing for personal data and any account PIN

Key defense

Port-freeze or port-out PIN

Carrier account PIN and moving off SMS codes

What it looks like in practice

In practice

A crypto holder is phished into revealing personal details through a fake exchange security alert. Days later, the attacker calls the victim's mobile carrier, poses as the victim using those details, and reports a lost phone, asking to activate a new SIM.

The victim's phone abruptly loses signal. Within minutes the attacker triggers password resets on the victim's email and exchange account, receiving each SMS code on the swapped SIM, and moves the crypto out. By the time the victim realizes their dead phone is more than an outage, the accounts have been drained and the SMS codes did nothing to stop it.

Why it matters for operators

SIM swap turns the phone number, treated by many systems as a trusted identity anchor, into the single weakest link. Once the number is hijacked, SMS-based two-factor stops protecting anything, and the attacker inherits the reset paths across a customer's most valuable accounts. The most durable defense is to reduce reliance on the number: move customers to app-based or phishing-resistant authentication such as FIDO2 and passkeys, and encourage carrier account PINs and port protections.

On the detection side, the signature is a burst of high-risk activity right after a SIM change: password resets, new-device logins, and beneficiary edits clustered in a short window, often preceded by phishing. Treating a recent SIM change as a risk signal, stepping up verification before honoring resets, and weighting these signals heavily for crypto and high-balance customers buys time to catch the takeover in progress.

What to watch for

  • Sudden loss of service. A customer whose phone goes dead with no signal may have had their number swapped to another SIM.
  • Reset bursts after a SIM change. A run of password resets and new-device logins soon after a SIM change points to hijacking.
  • Prior phishing. Recent phishing targeting the customer often precedes a swap, since the attacker needs personal data to pass carrier checks.
  • SMS codes on new devices. One-time codes satisfied on a device the customer does not recognize suggest the number moved.
  • High-value targets. Crypto holders and large-balance customers are prime targets, so weight SIM-change signals more heavily for them.

Quick questions

How is a SIM swap different from port-out fraud?

Both hijack the number, but a SIM swap reassigns it to a new SIM within the same carrier, while port-out moves it to a different carrier through the porting process. The effect is the same: the attacker receives the victim's texts and calls.

Why does it defeat two-factor authentication?

Because SMS codes follow the number. Once the number is on the attacker's SIM, every account that verifies by text becomes reachable, so SMS-based two-factor no longer protects the victim.

How do attackers pass the carrier's checks?

They gather personal data beforehand, usually by phishing, to answer identity questions, and sometimes bribe or trick a store or support employee. Any account PIN or security detail they obtain makes the swap easier.

What is the first sign for the victim?

A sudden and unexplained loss of mobile service, because the number no longer belongs to their device. A burst of account alerts and password-reset notices often follows quickly.

How can it be prevented?

Set a carrier account PIN and port protection, and move critical accounts off SMS to app-based or phishing-resistant authentication. Reducing dependence on the phone number is the most effective defense.

Why are crypto users targeted so often?

Crypto transfers are fast and irreversible, and many exchanges rely on SMS verification. A successful swap can let an attacker reset access and drain holdings before the victim can react, making these users high-value targets.

Go deeper

  • FTC Consumer Advice: Scams ↗ — US consumer guidance on current scams and fraud, and how to report them.
  • FBI IC3 ↗ — The FBI Internet Crime Complaint Center. Fraud reporting and annual trend reports.

O que saber junto com SIM swap