CipherWatch All articles
Threat Awareness

Your Phone Number Is a Target: The Rise of SIM Hijacking and How to Fight Back

CipherWatch

In March 2023, federal prosecutors in the Eastern District of New York unsealed charges against members of a criminal group that had allegedly stolen more than $400 million in cryptocurrency through a single SIM swap operation targeting one victim. The case drew headlines, but it represented only the most dramatic end of a threat spectrum that reaches far deeper into everyday American life than most people realize.

SIM swapping—sometimes called SIM hijacking or port-out fraud—is a form of identity theft in which an attacker convinces a mobile carrier to transfer a victim's phone number to a SIM card under the attacker's control. Once that transfer is complete, the attacker receives every call and text message intended for the victim. In a world where SMS-based two-factor authentication (2FA) guards access to banking portals, email accounts, and investment platforms, control of a phone number is effectively a skeleton key.

How the Attack Actually Works

Understanding SIM swapping begins with understanding how mobile carriers handle account changes. When a customer loses a phone, breaks a device, or upgrades their handset, they contact their carrier—in person, by phone, or online—to transfer their number to a new SIM card. This is a routine, legitimate process that carriers perform millions of times each year.

Attackers exploit this process by impersonating the target. To do so convincingly, they first gather personal information: full name, billing address, account number, and the last four digits of a Social Security number. Much of this data is already available through prior data breaches, public records, or targeted phishing campaigns against the victim. Armed with these details, the attacker contacts the carrier—sometimes speaking to a representative directly, sometimes submitting a fraudulent online request—and requests a SIM transfer.

The outcome depends largely on how rigorously the carrier's representative verifies the caller's identity. Industry critics and affected consumers have long argued that verification standards at major US carriers have been inconsistently applied, creating exploitable gaps. A 2019 investigation by Motherboard documented how easily reporters were able to have phone numbers transferred using only basic personal information—a finding that prompted regulatory scrutiny but did not eliminate the underlying vulnerability.

In some documented cases, attackers have gone further, bribing carrier employees directly. A 2021 Justice Department indictment alleged that a former T-Mobile employee accepted thousands of dollars in cryptocurrency to perform unauthorized SIM swaps from inside the company's systems. Insider threats of this kind are particularly difficult for consumers to defend against through individual action alone.

Real Victims, Real Consequences

The human cost of SIM swapping extends well beyond cryptocurrency losses, though those cases tend to receive the most coverage. In 2020, a California man filed a lawsuit against AT&T after attackers used a SIM swap to drain his cryptocurrency holdings of approximately $1.8 million. In 2018, a Boston College student lost $300,000 in digital assets through a similar attack targeting his T-Mobile account.

Less publicized are the thousands of smaller-scale incidents reported annually to the FBI's Internet Crime Complaint Center (IC3). In its 2022 report, the IC3 noted that SIM swapping complaints resulted in losses exceeding $72 million that year—a figure that almost certainly undercounts the true scope, since many victims do not report incidents or do not realize how their accounts were compromised.

For victims, the experience is disorienting. The first sign of an attack is often a sudden loss of cell service—the moment the carrier completes the unauthorized transfer. From that point, the attacker moves quickly, using SMS-delivered 2FA codes to reset passwords on email accounts, banking platforms, and any other service tied to the compromised number. By the time the victim reaches their carrier to report the issue, significant damage may already be done.

Why SMS-Based 2FA Is the Weak Link

The broader context here is important. SMS-based two-factor authentication was designed to add a security layer on top of passwords—and it does. An account protected by SMS 2FA is meaningfully harder to compromise than one protected by a password alone. The problem is that the SMS channel itself was never designed with strong security guarantees. Text messages can be intercepted through SS7 network vulnerabilities, SIM swapping, or device-level malware.

The security community has raised concerns about SMS 2FA for years. The National Institute of Standards and Technology (NIST) deprecated SMS-based out-of-band authentication in its 2016 digital identity guidelines, noting the channel's susceptibility to interception. Despite this, SMS 2FA remains the default—and often the only available option—on many major platforms, including some financial institutions.

This creates a structural vulnerability that individual users cannot fully resolve on their own. But there are meaningful steps that significantly reduce exposure.

Carrier-Level Protections: What to Request Today

The most direct defense against SIM swapping is adding friction at the carrier level—making it harder for an attacker to impersonate you successfully.

AT&T offers a feature called Extra Security, which requires an additional passcode before any account changes can be made. Customers can enable this through the myAT&T app or by contacting customer service.

T-Mobile provides Account Takeover Protection, which blocks unauthorized SIM transfers and port-out requests. Enabling this feature requires a visit to a retail store or a call to customer support.

Verizon allows customers to set a port-out PIN, which must be provided before a number transfer is approved.

Google Fi and other mobile virtual network operators (MVNOs) vary in their account protection options; check your provider's security settings directly.

In all cases, enabling these protections requires proactive action from the account holder. They are not activated by default.

Moving Beyond SMS: Stronger Authentication Alternatives

The most effective long-term defense against SIM swapping is reducing reliance on SMS 2FA wherever possible. Several alternatives offer substantially stronger security.

Authenticator apps such as Google Authenticator, Authy, or Microsoft Authenticator generate time-based one-time passwords (TOTP) locally on your device. Because these codes are generated offline and are not transmitted via SMS, a SIM swap does not grant an attacker access to them.

Hardware security keys conforming to the FIDO2 or WebAuthn standard—products such as YubiKey or Google's Titan Key—offer the strongest available protection. Authentication requires physical possession of the key, which cannot be replicated remotely.

Passkeys, the emerging standard backed by Apple, Google, and Microsoft, eliminate passwords and SMS codes entirely in favor of cryptographic authentication tied to your device. Adoption is growing rapidly, and major platforms are increasingly supporting them.

Where SMS 2FA cannot be avoided, using a Google Voice number or a separate, non-publicized phone number for authentication purposes adds a layer of separation between your public identity and your authentication channel.

A Practical Checklist for US Readers

Protecting yourself from SIM swapping does not require technical expertise. The following steps can be completed by any smartphone user.

The Regulatory Landscape

Following a surge in reported SIM swap cases, the Federal Communications Commission (FCC) finalized rules in late 2023 requiring carriers to implement more robust authentication procedures before processing SIM swaps or number port-out requests. The rules also mandate immediate customer notification when such a change is initiated. While these measures represent progress, enforcement and implementation timelines remain subjects of ongoing industry discussion.

Consumers should not wait for regulatory action to protect themselves. The tools to reduce SIM swap risk exist today—they simply require deliberate activation.

All Articles

Related Articles

One Vault to Rule Them All: The Real Truth About Password Manager Security

One Vault to Rule Them All: The Real Truth About Password Manager Security