Scams & FraudIntermediate5 min read

SIM swaps and account takeovers: locking the front door

Your phone number is the master key to your financial life — and a stranger can steal it with a phone call to your carrier.

Your phone dies mid-afternoon — no bars, 'No SIM.' Annoying, you think. Meanwhile, across town, someone who convinced your carrier to move your number onto their SIM is receiving every text meant for you — including the six-digit codes your bank, email, and crypto exchange send to 'verify it's really you.' Within hours, passwords are reset, accounts are drained, and you're on hold with customer service trying to prove you're yourself. That's a SIM swap, the sharpest tool in the account-takeover kit, and the FBI logs tens of millions of dollars in losses to it yearly.

$68M+
SIM-swap losses reported to the FBI in a single year
A multiple of the level from a few years earlier
Minutes
Time from swap to first drained account
Attackers work from a rehearsed checklist
5 min
Time to set a carrier port-out PIN
The single highest-value defense, free

How takeovers actually start

  • SIM swap: the attacker social-engineers your carrier (or bribes an insider) with your name, birthday, and address — often already leaked in data breaches — to port your number to their device. Your SMS codes become their SMS codes.
  • Credential stuffing: your email + password from an old breach, tried automatically against banks, brokerages, and retailers. Works because most people reuse passwords.
  • Phishing with real-time relay: a fake login page that forwards your credentials AND your 2FA code to the real site within seconds.
  • Email takeover first: control of your inbox means control of every 'reset password' link in your life. Your email account is the actual crown jewels.
Four hours, $19,000
A victim's phone loses service at 2pm. By 3pm the attacker has used SMS codes to reset the victim's email password, then the bank password, and added themselves as a Zelle recipient — daily limit $2,500, sent. By 4pm they're in the brokerage, initiating a $16,500 wire to an account they control. By 6pm, when the victim finally reaches the carrier from a borrowed phone, the money is moving through mule accounts. The attacker's total investment: leaked personal data costing a few dollars and one convincing phone call to a carrier rep. Every downstream break-in used the same key — SMS codes sent to a number that was no longer hers.

Hardening, in priority order

  1. Put a port-out PIN / number-lock on your mobile account today. Every major US carrier offers one (Verizon Number Lock, T-Mobile SIM Protection, AT&T passcode). This single free setting defeats most SIM swaps. Five minutes.
  2. Move 2FA off SMS wherever anything valuable lives: use an authenticator app, or better, hardware security keys or passkeys for email, bank, and brokerage. If the code never travels by text, a stolen number is useless.
  3. Fortify your primary email above everything else — unique password, strongest available 2FA, current recovery methods. It's the reset button for every other account.
  4. Use a password manager and stop reusing passwords, which neutralizes credential stuffing entirely. Prioritize: email, bank, brokerage, carrier, Amazon, payment apps.
  5. Set up account alerts (login, transfer, new payee) at your bank and brokerage — takeovers are stopped by minutes, and an instant push notification is your tripwire.
  6. Freeze your credit at all three bureaus so a takeover can't also become new loans in your name.
Sudden 'No Service' is a fire alarm
If your phone unexpectedly shows SOS/No SIM while others around you have signal — or you get a text about a SIM change you didn't request — treat it as an active attack. From any other phone or device: call your carrier to reverse the port, then immediately change your email password, then check bank and brokerage activity. The attacker's window is measured in minutes; so is your response.

Why SMS codes became the weak link

Two-factor authentication by text message was a genuine improvement over passwords alone — a decade ago. The problem is architectural: the code's security depends entirely on your phone number staying yours, and phone numbers were never designed to be identity documents. Carriers transfer them between SIMs thousands of times a day for legitimate reasons (lost phones, upgrades, new carriers), and every one of those routine processes is a door an attacker can talk their way through. Financial accounts, meanwhile, increasingly treat a phone number as proof of identity for password resets. That mismatch — a casually transferable number guarding rigorously protected money — is the entire vulnerability. It's also why the fix is specific: move the second factor onto something that can't be transferred by a phone call, meaning an authenticator app, a hardware key, or a passkey bound to your device.

Signals you're being set up

  • Password-reset emails you didn't request (someone is testing your locks).
  • 2FA codes arriving out of nowhere (they have your password; the code is the last wall).
  • Carrier notifications about account changes, new devices, or ported numbers.
  • 'Bank fraud department' calls asking you to read back a code just sent to you — that code is a reset code they triggered; reading it aloud hands over the account. Banks never ask you to read codes to them.
  • Small unfamiliar charges or a new payee you didn't add — probing before the real move.

If it happens anyway

  1. Reclaim the phone number first (carrier fraud line), then the email, then financial accounts — that order matters, because each protects the next.
  2. Call every financial institution's fraud line the same day: freeze transfers, reverse what's reversible, kill open sessions and API/third-party access.
  3. Change passwords from a known-clean device, not the possibly compromised one.
  4. File at ic3.gov and identitytheft.gov, and request the carrier's records of the swap — useful for disputes and any regulatory complaint.
  5. Afterward, do the hardening list above; victims are re-targeted, because attackers know exactly what they got the first time.
One free evening, most of the risk
The full defense — carrier PIN, authenticator apps on your five most valuable accounts, password manager, bank alerts, credit freeze — costs nothing but an evening. Account takeover is a crime of unlocked doors; attackers run automated checks and move to whoever's easiest. You don't need to be uncrackable. You need to not be the softest target on the list.

The bottom line

Modern account theft rarely involves 'hacking' anything — it's your phone number hijacked by a phone call, your reused password from a 2019 breach, your SMS codes intercepted at the carrier level. The counters are unglamorous and nearly free: lock your number, get codes off SMS, guard your email like the vault it is, and let a password manager end reuse forever. Do it before the afternoon your phone goes silent.

Check your understanding

1 of 3
Your phone suddenly shows 'No SIM' mid-afternoon while everyone around you has signal. What should you treat this as?

Not quite — try again.

The Worth letter

Get smarter about money every week

One email, no spam — practical guides and Worth updates. Unsubscribe anytime.

Put this into practice

Worth tracks your accounts, budgets, and goals — so the concepts in this article aren't just theory.

Start free trial