They Did Not Steal Your Phone. They Stole Your Number.
By NorwegianSpark Editorial · Published August 8, 2026 — written with AI assistance and reviewed by the NorwegianSpark SA editorial team.
Your phone stops working. No signal, no calls, no texts. You assume it is a network problem.
In a SIM swap, it is not. Someone has persuaded your mobile provider to move your number onto a SIM card they control. From that moment every call and text meant for you arrives with them — including the verification codes protecting your email, your bank and everything those can reset.
How the attack actually works
The technical part is trivial; the human part is the attack. Someone contacts your provider claiming to be you with a lost or damaged phone, and asks for the number to be transferred to a new SIM.
To pass the identity check they use information gathered beforehand: your address and date of birth, the last digits of a payment card, answers to security questions. Much of that is available from old breach data, public records or social media. In some cases the provider's own staff have been bribed or tricked.
Your phone loses service the instant the transfer completes. That sudden, unexplained loss of signal — while other devices in the house still work fine — is the warning sign, and the window to act is short.
Why this defeats SMS two-factor authentication
Two-factor authentication by text is meaningfully better than a password alone, and for many people it is the only second factor they use. But it rests on an assumption that a SIM swap breaks: that the number belongs to you.
Once the attacker holds the number, they can trigger "forgot password" on your email account, receive the reset code, and take the account that every other account recovers through. Email is the master key, and SMS is the lock most people put on it.
This is why security guidance has steadily moved away from SMS as the preferred second factor — not because it is useless, but because it depends on a system you do not control and cannot audit.
What to change, in order of impact
- Move your important accounts off SMS codes. An authenticator app generates codes on the device itself, with no phone number involved. A hardware security key is stronger still. Do email first — it protects everything downstream.
- Add a port-out PIN or account lock with your mobile provider. Most carriers offer a separate PIN or a "port freeze" that must be given before any number transfer. It is free, takes one call, and directly blocks the attack.
- Reduce what is publicly known about you. Date of birth, address history and the names used in security questions are the raw material. Data-broker removal and tightening social profiles reduce the supply.
- Stop using guessable security answers. Your mother's maiden name is not a secret. Treat these as passwords and store random answers in your password manager.
If it happens to you
Act on the assumption that minutes matter.
- Call your provider from another phone immediately and report the number as fraudulently transferred. Ask them to reverse it and freeze the account.
- From a different device, change your email password and revoke active sessions. Email first, always.
- Then your bank and financial accounts, and tell them a SIM swap has occurred — they can watch for fraudulent transfers.
- Report it to your national fraud or cybercrime body, and to the provider in writing so there is a record.
The uncomfortable summary
You cannot fully prevent an attack that depends on someone else's customer-service process. What you can do is stop your most important accounts from depending on that process — which is really just one instruction: get your email off SMS codes today.
Affiliate disclosure
This article contains affiliate links. If you purchase through them, CyberTechVault earns a commission at no extra cost to you. Our assessments are based on vendors' published documentation, independent lab results and security disclosures — not on hands-on testing by us. Affiliate relationships never decide what we recommend.
Full disclosure: /affiliate-disclosure.