They Did Not Steal Your Phone. They Stole Your Number.
By NorwegianSpark Editorial · Published August 8, 2026 — written with AI assistance and reviewed by the NorwegianSpark SA editorial team.
Your phone stops working. No signal, no calls, no texts. You assume it is a network problem.
In a SIM swap, it is not. Someone has persuaded your mobile provider to move your number onto a SIM card they control. From that moment every call and text meant for you arrives with them — including the verification codes protecting your email, your bank and everything those can reset.
How the attack actually works
The technical part is trivial; the human part is the attack. Someone contacts your provider claiming to be you with a lost or damaged phone, and asks for the number to be transferred to a new SIM.
To pass the identity check they use information gathered beforehand: your address and date of birth, the last digits of a payment card, answers to security questions. Much of that is available from old breach data, public records or social media. In some cases the provider's own staff have been bribed or tricked.
Your phone loses service the instant the transfer completes. That sudden, unexplained loss of signal — while other devices in the house still work fine — is the warning sign, and the window to act is short.
Why this defeats SMS two-factor authentication
Two-factor authentication by text is meaningfully better than a password alone, and for many people it is the only second factor they use. But it rests on an assumption that a SIM swap breaks: that the number belongs to you.
Once the attacker holds the number, they can trigger "forgot password" on your email account, receive the reset code, and take the account that every other account recovers through. Email is the master key, and SMS is the lock most people put on it.
This is why security guidance has steadily moved away from SMS as the preferred second factor — not because it is useless, but because it depends on a system you do not control and cannot audit.
What to change, in order of impact
- Move your important accounts off SMS codes. An authenticator app generates codes on the device itself, with no phone number involved. A hardware security key is stronger still. Do email first — it protects everything downstream.
- Add a port-out PIN or account lock with your mobile provider. Most carriers offer a separate PIN or a "port freeze" that must be given before any number transfer. It is free, takes one call, and directly blocks the attack.
- Reduce what is publicly known about you. Date of birth, address history and the names used in security questions are the raw material. Data-broker removal and tightening social profiles reduce the supply.
- Stop using guessable security answers. Your mother's maiden name is not a secret. Treat these as passwords and store random answers in your password manager.
If it happens to you
Act on the assumption that minutes matter.
- Call your provider from another phone immediately and report the number as fraudulently transferred. Ask them to reverse it and freeze the account.
- From a different device, change your email password and revoke active sessions. Email first, always.
- Then your bank and financial accounts, and tell them a SIM swap has occurred — they can watch for fraudulent transfers.
- Report it to your national fraud or cybercrime body, and to the provider in writing so there is a record.
A worked example of the chain
Follow the sequence, because each step is unremarkable and the damage is entirely in the order.
Someone assembles a profile: your full name and address from public records or an old breach, your date of birth from a social media post, the last four digits of a card from a receipt or a different leak, and your mobile number, which you have given to dozens of companies.
They contact your provider as you, describe a broken handset, and request the number be moved to a new SIM. The identity questions are answered from the profile. The transfer is approved.
Your phone loses signal. If you are asleep, or in a meeting, or simply assume it is a network fault, the clock is already running.
They open your email provider's login page, enter your address, and choose "forgot password". A code arrives on the number they now control. They set a new password. Your email is theirs.
From email, everything else follows, because almost every service on earth recovers through it. Bank, cloud storage, social accounts, the password manager if its recovery runs through email.
The step that breaks this chain is not the first one. It is the reset code. If your email account required a code from an app on your device, or a tap on a hardware key, the number they stole is worthless for the part that matters. Everything upstream still happened, and nothing downstream could.
What to ask your mobile provider
Protections exist, they are usually free, and they are almost never offered unprompted. Call and ask specifically:
- Can you add a port-out PIN or transfer PIN to my account? This is a separate secret required before any number transfer. Do not reuse a PIN you use elsewhere, and store it in your password manager.
- Can you place a port freeze or number lock on my account? Some providers offer an outright block that has to be lifted deliberately before any transfer.
- What identity checks are required for a SIM change, and can the requirements be raised on my account?
- Can you add a note requiring in-store identification for changes to this account? Not every provider will, but some will.
- What alert will I receive if a SIM change is requested, and to which channel?
That last question matters more than it looks. An alert sent only by text arrives on the SIM being deactivated. An alert by email gives you a chance to act.
Being honest about SMS two-factor
It would be easy to read this and conclude that SMS codes are useless. They are not, and overcorrecting causes its own harm.
A password alone is defeated by a leak from any service where you reused it, which is an enormous and constant risk affecting people every day. SMS two-factor defeats that entirely, because a leaked password is no longer sufficient. Against the common threat it works.
What it does not survive is an attacker who specifically targets you and is willing to work at it. SIM swapping takes effort and exposes the attacker to a paper trail, so it is aimed at accounts worth the trouble — high-value financial and cryptocurrency accounts most visibly, but also anyone whose email is a route into something valuable.
So the sensible position is layered rather than absolute. Keep SMS where it is the only option offered, because it beats nothing. Move to an app or a hardware key wherever the option exists, starting with the accounts that reset everything else. And do not let the absence of a perfect option anywhere become a reason to leave a good option unused elsewhere. There is more detail in our two-factor authentication guide, and passkeys remove the code entirely for services that support them.
The limits of what you can control
Two uncomfortable truths belong here.
The first is that the decisive step happens inside a company you do not work for, following a process you cannot inspect, executed by a person you will never meet. No amount of personal diligence removes that. A port-out PIN raises the bar considerably, but it is still a control the provider enforces or does not.
The second is that reducing the raw material is slow work. Your date of birth and address history are already in circulation, and removing them is a grind rather than a fix — our guide to removing your data from brokers is honest about how partial that process is.
Which is why the recommendation lands where it does. You cannot reliably stop the transfer. You can make the transfer not matter for the accounts that count, and that part is entirely within your control and takes about twenty minutes.
The uncomfortable summary
You cannot fully prevent an attack that depends on someone else's customer-service process. What you can do is stop your most important accounts from depending on that process — which is really just one instruction: get your email off SMS codes today, and add the port-out PIN while you are thinking about it. The authenticator apps and hardware keys that replace SMS are covered in our security tool comparison.
Affiliate disclosure
This article contains affiliate links. If you purchase through them, CyberTechVault earns a commission at no extra cost to you. Our assessments are based on vendors' published documentation, independent lab results and security disclosures — not on hands-on testing by us. Affiliate relationships never decide what we recommend.
Full disclosure: /affiliate-disclosure.
Continue reading
privacy
It Sounded Exactly Like Your Daughter
Voice cloning needs seconds of audio and the result is convincing enough to fool parents. Why the technology broke a lifelong instinct, and the family safeword that fixes it.
privacy
The Delivery Text Is Not From the Delivery Company
Scam texts work because they arrive at exactly the moment you are expecting a parcel. The patterns behind them, and the one habit that defeats nearly all of them.
guides
Best Antivirus for Mac 2026: Which One to Pick
The best antivirus for Mac in 2026: whether macOS needs third-party protection, how we chose our picks, and reviews of Bitdefender, Norton and Avast.
