Cybersecurity glossary

What is SIM Swapping?

Learn what SIM swapping is, how attackers hijack phone numbers to intercept SMS OTP and resets, real-world impact, and defenses that reduce reliance on SMS authentication.

Identity and accessUpdated July 23, 2026
Also known asSIM jackingSIM swap fraudPhone number takeover

Definition

SIM swapping (or SIM jacking) is a social-engineering and carrier-process attack in which an adversary convinces a mobile operator to move a victim’s phone number to a SIM the attacker controls, enabling interception of calls, SMS one-time passwords, and account-recovery messages.

Why your phone number became an identity key

Carriers treat MSISDNs as stable identifiers. Apps treat SMS as a trusted second factor. SIM swapping abuses that shared assumption: control the number, control the codes.

It remains one of the most damaging consumer and VIP account-takeover techniques.

How a SIM swap attack typically runs

1

Target selection

Attackers pick users with valuable email, finance, or crypto accounts tied to SMS.

2

Personal data collection

OSINT, breaches, and phishing gather answers carriers might accept.

3

Carrier social engineering

Support is convinced to port or swap the number to attacker-controlled SIM.

4

Victim loses service

Phone drops network; SMS and calls route to the attacker.

5

Account takeover

Password resets and SMS MFA codes unlock email, banks, and more.

What SIM swap enables

SMS OTP interception

Real-time MFA codes arrive on the attacker’s handset.

Recovery hijack

Password reset flows that trust the phone number fall first.

Email pivot

Mailbox takeover cascades into every linked service.

Financial fraud

Bank and brokerage SMS approvals become attacker-controlled.

Number reputation abuse

Trusted contacts receive phishing from the victim’s number.

Persistence

Changed recovery numbers keep the attacker in the loop.

Defenses by layer

LayerControlEffect
AuthenticatorPasskeys / security keysRemoves SMS from the login path
Account recoveryNo SMS-only recoveryCloses the common bypass
CarrierPort freeze / account PINRaises swap friction
MonitoringNumber-change alertsFaster incident response

Practical checklist

  • Prefer phishing-resistant MFA; demote or remove SMS factors for high-risk users.
  • Ensure authenticator apps and passkeys are not silently overridden by SMS recovery.
  • Enable carrier-side SIM/port protection PINs and notify-on-change features.
  • Treat sudden loss of mobile service as a potential security incident.
  • Lock down email first—it is the usual pivot after number takeover.
  • Rate-limit and alert on bursts of SMS OTP requests.
  • Train support staff not to move MFA to SMS based on caller requests alone.
  • For enterprises, avoid using personal phone SMS as the only VIP MFA path.

The practical takeaway

SIM swapping steals the phone number that many apps still treat as a second password. Once SMS is attacker-controlled, OTP MFA and SMS recovery unravel quickly.

Move valuable accounts to passkeys or hardware keys, strip SMS from recovery, and harden carrier account controls before you need them.

Related security terms

Frequently asked questions

What is SIM swapping in simple terms?

Criminals trick your mobile carrier into activating your phone number on their SIM card. Your phone loses service, and they receive your texts and calls—including login codes.

Why do attackers want your phone number?

Many banks, email providers, and crypto platforms still send SMS OTPs or password-reset codes to that number.

How do attackers convince carriers?

Social engineering support agents, bribing insiders, abusing weak identity checks, or using leaked personal data to pass knowledge-based authentication.

What are early warning signs?

Sudden loss of mobile service, unexpected carrier emails about SIM changes, and MFA codes you did not request.

Does using an authenticator app stop SIM swap?

App TOTP helps if SMS is not a fallback. If account recovery still prefers SMS, SIM swap can bypass the app.

What should high-risk users do?

Move to passkeys/security keys, remove SMS from MFA and recovery where possible, enable carrier PINs/port locks, and monitor number-change alerts.

Is VoIP number takeover the same?

Related. Attackers may also hijack numbers via port-out fraud or cloud telephony accounts that receive SMS.

References

Explore authoritative guidance and frameworks related to sim swapping.

Explore every security definition

Return to the glossary to search by term, alias, starting letter, or security category.

Browse glossary