Your phone loses signal. Not a weak bar — no service at all, in a place where you always have coverage. You assume a network problem and get on with your day.
Someone has convinced your carrier that they are you and that they need your number moved to a new SIM. They now receive your calls and your texts, including every SMS verification code. Within minutes they are resetting passwords on accounts that use your number for recovery, starting with your email, and from there everything else.
What changed in 2026
- Carrier protections improved and remained optional. Port-out PINs and number locks became widely available and still require you to enable them.
- SMS continued its decline as an authentication method. More services deprecated it, though it remains widespread as a recovery option.
- Social engineering got better. Voice cloning made impersonating a customer to a support agent considerably more effective — see deepfake scam protection.
- eSIM adoption cut both ways. Provisioning changed the attack surface without removing the underlying weakness, which is carrier account access.
Why the attack works
Your phone number was never designed as a security credential. It is a routing identifier, and it can be moved between devices and carriers by design — that is what number portability means.
The attacker's job is to convince a carrier employee to perform a legitimate operation on your behalf. They may have personal details from a breach or your public profile, they may claim a lost phone, and increasingly they may sound like you.
What makes it so damaging is the position SMS occupies. It is not just a second factor on some accounts; it is the recovery mechanism on many. An attacker who controls your number can often reset a password outright, which means the number alone is sufficient rather than merely helpful.
Locking it down
Set a port-out PIN or number lock with your carrier. This is the single most effective action and it is free. Every major carrier offers some version — a PIN required for account changes, or a lock preventing transfers entirely. It takes minutes in an app or a call, and it means a social-engineering attempt fails at the first step.
Do this now if you have not. It is the highest ratio of protection to effort in this entire area.
Use a PIN that is not derivable. Not your birth year, not the last four of anything, not something in your public profile.
Reduce what your number can do. Go through your important accounts and, where a better option exists, switch away from SMS. An authenticator app is not vulnerable to a SIM swap. A security key is not vulnerable to a SIM swap or to phishing — see security keys explained.
The subtlety: adding a better method does not help if SMS remains enabled as an alternative. An attacker uses the weakest enabled path. Where a service lets you remove SMS after adding something stronger, remove it.
Prioritise email. Your email account is the recovery path for nearly everything, so protecting it well matters more than protecting any individual service.
Consider a separate number for recovery. A number that is not published anywhere, not used for calls, and not associated with you publicly is much harder to target. Some people use a secondary line purely for account recovery.
The first ten minutes
If you lose service unexpectedly and suspect a swap, speed matters more than certainty.
Contact your carrier immediately — from another phone, or via their app on wifi. Tell them you suspect a SIM swap and ask them to lock the account and reverse any recent change.
Get into your email from another device and change the password. If you can still access it, you are ahead of the attacker.
Change passwords on financial and critical accounts, in order of what an attacker would reach first.
Check for changes you did not make — new recovery addresses, new devices, forwarding rules on your email. Attackers frequently add a forwarding rule so they keep receiving your mail after you regain control, and it is easy to miss.
Do not wait to be sure. A network outage costs you nothing to over-react to. A swap costs a great deal to under-react to.
If accounts were compromised, the full recovery sequence in identity theft recovery applies.
Common mistakes
- No port-out PIN. Free, fast, and the main defence.
- A guessable PIN. Derived from public information.
- Keeping SMS as a fallback after adding better methods. The weakest enabled path is your real security level.
- Treating a signal drop as a glitch. It is the only warning you get.
- A publicly known recovery number. Findable means targetable.
- Not checking email forwarding rules afterwards. Persistent access hiding in plain sight.
- Assuming eSIM is immune. The weakness is carrier account access, not the physical SIM.
FAQ
Is SMS 2FA better than nothing?
Yes, clearly — it still defeats an attacker with only your password. It is simply the weakest common option, and it should not be the protection on accounts that matter when better options exist.
Can an eSIM be swapped?
Yes. The attack targets your carrier account rather than the physical card, so eSIM provisioning is subject to the same social engineering.
What if my carrier will not add a lock?
All major carriers offer some form of it, usually under account security in the app. If you genuinely cannot get one, that is a reasonable argument for switching carriers.
Does a VoIP number help?
It removes the carrier social-engineering vector and introduces the security of that provider's account instead. Better in some respects, and it is not a solution on its own — some services also reject VoIP numbers for verification.
Where to go next
For the authentication methods that make your number irrelevant, read security keys explained and passkeys vs 2FA. For the impersonation techniques that make this attack easier, deepfake scam protection.