A single phone call to a mobile carrier is sometimes all it takes for a criminal to take over someone’s phone number completely. With this type of cyberattack, known as a SIM swap attack, an attacker gains control of the number and can then intercept text messages, reset passwords and gain access to financial accounts, cryptocurrency wallets and social media accounts.
According to the FBI, SIM swap fraud was the cause of more than $68 million in reported losses in 2021. As of 2025, it ranks among the FBI’s top five cyber threats and continues to be a concern as more accounts rely on phone-based verification. Understanding how SIM swapping works, what warning signs to watch for and how to protect your accounts can help individuals and businesses to reduce their cyber risk.
What is a SIM swap attack?
A SIM swap attack, also known as SIM hijacking, SIM splitting or a port-out scam, is a type of cyber fraud in which an attacker convinces a mobile service provider to transfer a victim’s phone number to a subscriber identity module (SIM) that the attacker controls.
Every mobile phone relies on a SIM card to connect to a mobile carrier’s network. When a cybercriminal successfully transfers a customer’s phone number to a new device, the victim’s mobile phone loses service, and the attacker begins receiving all phone calls, text messages and one-time passcodes that are sent to that number.
This matters because many sensitive accounts, ranging from email to social media to banking, use SMS-based two-factor authentication as a security layer. SIM swapping allows attackers to intercept SMS-based authentication, effectively bypassing that layer of protection. Once they are in control of the victim’s number, criminals can trigger password resets, intercept authentication codes and drain financial accounts or cryptocurrency wallets within minutes.
Legitimate SIM transfers happen every day when customers upgrade their phones or replace damaged SIM cards. SIM swap fraud, however, happens when a criminal uses stolen personal information, fake documents or other tactics to convince a carrier that they are the account holder. In other words, the attack targets weaknesses in the carrier’s identity verification process, not the phone itself.
SMS Authentication vs. App-Based Security
SMS-based two-factor authentication is vulnerable to SIM swap attacks because the verification codes are sent to the device associated with the phone number, meaning that if an attacker completes a SIM swap, they may receive those codes. SMS authentication can also be vulnerable to other forms of interception and phishing.
Authenticator apps and hardware security tokens offer stronger protection because they do not rely solely on the carrier network. Even if an attacker takes control of a phone number, they won’t automatically gain access to the authentication codes generated elsewhere.
Unfortunately, many organizations still rely on SMS authentication because it’s so simple and widely available. Moving to stronger authentication methods may require additional costs and training for users.
How SIM Swap Attacks Work
SIM swapping doesn’t always involve sophisticated hacking. In many cases, attackers simply gather enough information to convincingly pose as someone else. They may collect personal details through phishing, social media or other sources, and then use that information to trick a mobile carrier into giving them control of the victim’s phone number.
- Information Gathering: Attackers collect personal details from social media, data breaches, phishing attacks and public records to impersonate the victim.
- Carrier SIM Transfer: Criminals pose as the account holder and use this information to convince the mobile carrier to transfer the victim’s phone number to a new SIM card or eSIM.
- Account Takeover: Once the attacker controls the number, they can intercept SMS verification codes and password reset messages in order to access sensitive accounts.
- Theft and Cover-Up: Attackers may steal funds, transfer cryptocurrency or compromise personal and business accounts. Then, they may change recovery settings, disable alerts or take other steps to delay detection.
Common SIM Swap Attack Targets
SIM swap attacks disproportionately target individuals and organizations where the potential financial return is high or where cyber defenses are weak. Some of the most common targets include:
- High-Net-Worth Individuals: Executives, celebrities, investors and other individuals with a high net worth may be targeted because of their financial assets and public visibility.
- Cryptocurrency Holders: Crypto investors face added risk because transactions can be difficult to reverse or recover following a cyberattack.
- Influencers: Attackers may target valuable social media accounts with large followings, verified status or lucrative brand partnerships.
- Business Accounts: Accounts using SMS authentication may be vulnerable, especially if tied to an employee’s personal phone number.
- Small Business Owners: Using personal phones for business banking can expose both personal and business accounts.
- Individuals with Weak Account Security: Publicly available personal information or compromised data can make social engineering easier.
How SIM Swap Attacks Compare to Other Cyber Threats
SIM swap fraud is different from many other cyber threats because it targets your mobile phone number rather than a computer or network. Understanding how it differs from other common cyber scams can make it easier for individuals and businesses to recognize the warning signs and take steps to protect their accounts.
SIM Swapping vs. Phishing Attacks
Phishing attacks typically rely on tricking someone into clicking a malicious link, visiting a fake website or sharing sensitive information. On the other hand, SIM swap attacks target the victim’s mobile account and may happen without the victim doing anything at all. Often, the first warning sign is sudden loss of cellular service.
Despite their differences, phishing and SIM swapping frequently work together in multi-stage fraud schemes. Criminals often use phishing to steal data, such as account passwords, financial details or a Social Security number, that they later use to impersonate the victim when contacting their mobile carrier.
SIM Swapping vs. Account Credential Theft
Password theft typically gives an attacker access to a specific account, while SIM swapping can put several accounts at risk because the attacker gains control of the phone number used for password resets and verification codes.
This is what makes SIM swap fraud especially concerning. Even strong, unique passwords may not be enough if an account relies on text messages for verification or recovery.
Why Attackers Choose SIM Swapping Methods
Several factors make SIM swapping an increasingly attractive method for cybercriminals:
- Single Point of Compromise: A successful SIM swap attack can bypass multiple security layers across many accounts simultaneously, making it far more efficient than gaining unauthorized access to accounts one at a time.
- Widespread SMS Reliance: Many financial institutions, cryptocurrency exchanges and online services continue to depend on SMS-based multi-factor authentication, creating a broad attack surface.
- Real-Time Access: Attackers receive authentication codes in real time during account takeover attempts, enabling them to act before detection systems can respond.
- Low Technical Barrier: SIM swapping often relies more on stolen personal information and impersonation rather than advanced technical skills.
- Rapid Financial Theft: Attackers can quickly transfer cryptocurrency or other digital assets before the victim even recognizes the attack.
Protecting Against SIM Swap Attacks
Defending against SIM swap fraud requires a combination of carrier-level protections, stronger authentication methods and ongoing vigilance. Both individuals and businesses can take meaningful steps to reduce their exposure, such as:
- Set a unique PIN with your mobile carrier. Enable account PINs, port locks or other SIM protection features to help prevent unauthorized changes.
- Use app-based two-factor authentication instead of SMS. Authentication apps or security tokens are not affected by SIM swaps. Consider only using SMS as a backup method.
- Limit personal information shared online. Avoid publicly sharing phone numbers, birthdates, financial information or other details that could support social engineering attacks.
- Monitor accounts for suspicious activity. Watch for unexpected password resets, account changes or loss of cellular service. Contact your carrier immediately if you suspect a SIM swap.
- Educate employees. Train employees, particularly those in HR, finance and IT, to recognize social engineering scams and follow secure authentication practices.
- Consider cyber insurance coverage. Personal or commercial cyber insurance may help cover certain losses related to account takeover, identity theft or fraud. Make sure to review your policy terms, requirements and exclusions with your insurance advisor.
Is your mobile security prepared for evolving threats?
SIM swap attacks can put both individuals and businesses at risk by giving criminals access to financial accounts, personal information and business systems. Stronger authentication, carrier-level security and employee education can help to reduce this exposure.
Higginbotham works with individuals, families and businesses to understand their risks and find coverage that fits their needs. Whether you’re looking for personal or commercial cyber insurance, our team can help you explore your options. Connect with a Higginbotham insurance and risk management advisor today to learn more.




