SIM Swap Attacks Are Rising Fast: How to Recover Your Number and Lock Down Your Accounts

Your phone number was never meant to be a security credential, but for most people it quietly became one anyway. Banks text you a code to log in. Email providers use it as a fallback recovery method. Social media accounts, cryptocurrency exchanges, and even government portals lean on that same ten-digit string as proof that you are who you say you are. That convenience is exactly what makes SIM swap fraud so damaging when it works: a criminal who convinces your carrier to move your number onto a SIM card they control inherits every one of those trust relationships in a matter of minutes.
This is not a fringe threat anymore. The FBI's Internet Crime Complaint Center (IC3) logged 982 SIM swap complaints in 2024 with reported losses of roughly $26 million, and industry trackers report that incidents jumped by around 48% in 2025, with global losses tied to SIM swap and related account-takeover fraud now estimated above $2.7 billion. The pattern is international: the UK recorded close to 3,000 unauthorized SIM swaps in a single year, a surge of more than 1,000% compared to prior reporting periods, and Australian regulators logged a 240% jump in people seeking help after a swap, with roughly nine in ten of those attacks happening without the victim clicking a link or entering a password anywhere. The weak point isn't your phone's software. It's the phone call to a call-center agent who can be talked into moving your number.
How a SIM Swap Actually Happens
Despite the name, most modern SIM swap attacks don't involve a physical SIM card at all anymore. An attacker gathers enough personal information about you — often from a previous data breach, a phishing text, or plain social-media oversharing — to pass a carrier's identity check. They then either walk into a store, call support, or in some cases, exploit an online self-service portal to request that your number be ported to a new device or a new carrier entirely. Once that transfer completes, your old phone loses signal, and every SMS-based verification code that would normally arrive on your device now lands in the attacker's hands instead.
From there the attack cascades. Email is usually the first target, because an inbox is the master key to almost everything else: a "forgot password" flow on your bank, your crypto exchange, or your social accounts can often be satisfied with a code sent to that same phone number or a reset link sent to an email account the attacker now controls. Within an hour, someone who has never met you can be inside your finances.
Warning Signs You're Being Targeted
- Your phone suddenly shows "No Service" or "SOS Only" with no explanation, especially after receiving an odd text or call asking you to verify account details.
- You receive an unexpected text from your carrier confirming a SIM change, number port, or plan modification you didn't request.
- You get locked out of email or social accounts and password-reset attempts fail or say a reset was already requested.
- You receive login notifications from unfamiliar devices or locations for accounts tied to your phone number.
What to Do the Moment You Suspect a Swap
Speed matters more than anything else here. Use any working internet connection — Wi-Fi calling on another device, a laptop, a borrowed phone — to call your carrier's fraud line immediately and report an unauthorized SIM swap or port-out. Ask them to freeze the account and reverse the transfer. At the same time, log into your primary email from a trusted device and change its password, then check the recovery phone number and forwarding rules, since attackers often quietly add a forwarding address so they keep seeing your mail even after you regain control.
Next, work through your financial accounts in order of risk: banking apps, crypto exchanges, payment apps, then anything storing a saved card. Change passwords and check for unfamiliar linked devices or new payees. If money has already moved, contact your bank's fraud department directly and file a report with the FTC at IdentityTheft.gov, which also generates the paperwork many banks require to reverse fraudulent transfers.
The Fix That Actually Prevents This: Stop Relying on SMS
The single most effective change you can make is moving two-factor authentication away from text messages entirely. An authenticator app — Google Authenticator, Authy, or the built-in options in a password manager — generates codes locally on your device and is completely unaffected by a SIM swap, because it has nothing to do with your phone number. Hardware security keys go a step further and are effectively immune to remote takeover. If a service still only offers SMS-based codes, that's worth flagging as a real limitation, not a minor inconvenience.
Carriers also let you set a port-out PIN — a separate passcode required before any transfer of your number can be processed, distinct from your regular account password. Every major US and UK carrier supports this, and it should be treated as mandatory rather than optional. Combine that with placing a verbal password or extra security question on the account, since call-center agents are the actual attack surface in most successful swaps. It's also worth turning on account alerts for any changes to SIM, port status, or plan details, so you learn about a swap in seconds rather than when your phone goes silent.
Does an eSIM Make This Better or Worse?
Physical SIM cards can technically be cloned or reissued in a store visit, but the vast majority of real-world attacks happen through account-level social engineering, not the swap of a physical card — which means an eSIM alone doesn't close the gap, since the transfer still happens on the carrier's backend rather than in your hand. Where eSIM does help is in reducing one specific attack path: it removes the option for someone to walk into a store with a fake ID and a blank SIM card and ask for a replacement, since there's no physical card to hand over. It's a smaller improvement than switching your two-factor authentication off SMS, but it's a real one, and it's part of why eSIM-only phones are becoming the default rather than the exception on new flagship devices.
Recovery Beyond the First 24 Hours
Once immediate access is restored, spend an afternoon auditing every account that has ever used your phone number for account recovery. Replace SMS-based recovery with an authenticator app or a secondary email wherever the option exists. Check your credit reports for new accounts opened in your name, since identity thieves who successfully swap a number often use the stolen access window to open credit lines before you notice. Placing a credit freeze with the major bureaus costs nothing and blocks new-account fraud even if your identity details are already circulating.
It's also worth reviewing how your phone number is used day to day — dual-SIM and eSIM setups, discussed in our practical guide to running separate work and personal lines, can reduce blast radius by keeping financial and recovery accounts tied to a number that isn't shared publicly on a resume or business card. And if your device itself is ever lost or stolen alongside a swap attempt, understanding what protection plans actually cover, as we break down in our guide to phone insurance and protection plans, can matter just as much as the account security above. For a broader look at how these threats intersect with everyday privacy settings, see our comparison of how Android and iOS handle app permissions and tracking.
The Bottom Line
SIM swap fraud isn't a hypothetical risk reserved for crypto whales and celebrities anymore — the complaint data shows steady growth year over year, and the attacks increasingly succeed without the victim doing anything wrong at all. The defense doesn't require exotic tools: a port-out PIN, an authenticator app instead of SMS codes, and a habit of treating an unexplained loss of signal as a five-alarm event rather than a dead zone will stop the overwhelming majority of these attacks before they can cascade into your bank account.