Table of Contents
- How the swap actually happens
- The warning sign that arrives right before it
- What carriers are now required to do
- The one setting that stops most attempts: a carrier port-out PIN
- Why an authenticator app survives a SIM swap and a text code doesn't
- If a SIM swap just happened to you
- A note on how to use this
- Frequently asked questions
A SIM swap is when an attacker convinces your mobile carrier to move your phone number onto a SIM card they control, not one physically in your phone. Once that happens, calls and text messages meant for you, including one-time verification codes from your bank, go to the attacker instead. This matters directly for banking because many accounts still use a text message as the second step of login verification, and a SIM swap defeats that specific protection without the attacker ever touching your device or knowing your phone's passcode. The fix that matters most is a carrier-side port-out lock, plus preferring an authenticator app over text messages wherever your bank allows it.
How the swap actually happens
A SIM swap targets your mobile carrier's account, not your phone's hardware or software. An attacker who already has some of your personal information (often gathered from a data breach, a phishing message, or information posted publicly) contacts your carrier, or manipulates an online account portal, and convinces the carrier that they are you requesting a new SIM card. If it works, the carrier deactivates your existing SIM and activates the new one, and your phone number now routes to the attacker's device.
This is a social and administrative attack against a company's customer-service process, not a technical hack of your phone. That distinction matters because it means the strongest defenses are things you can set up on your carrier account, not antivirus software or a stronger phone passcode.
The warning sign that arrives right before it
The clearest sign a SIM swap has just happened to you is sudden, unexplained loss of cell service: no bars, "No Signal," or an inability to make calls or send texts, when you haven't changed anything and aren't out of coverage. If this happens and you have no obvious explanation (a known outage, a new phone setup you're expecting), treat it as a possible SIM swap and act immediately: contact your carrier from another phone or a landline, and check your bank and email accounts for anything unusual, since text-based codes may already be compromised.
What carriers are now required to do
In the United States, the Federal Communications Commission introduced a compliance mandate that took effect on 8 July 2024, requiring wireless carriers to authenticate customers more strictly before processing a SIM swap or port-out request, and to notify customers immediately through an existing, pre-verified contact method (such as the previous device or the previous email on file) whenever such a request is made. In practical terms, this means a legitimate SIM swap or port-out request should now trigger a notification you can catch and stop if it wasn't you. This is a real improvement, but it is a floor, not a guarantee. The strongest layer is still the one you set up yourself.
The one setting that stops most attempts: a carrier port-out PIN
Most major carriers now let you set a dedicated PIN or passcode that must be provided before a SIM swap or number port can proceed, separate from your regular account password. This is worth setting up specifically, because it closes the exact gap the FCC rule addresses from the customer's side: even if someone has your name, address, and other personal details, a correctly configured port-out PIN stops the swap at the carrier's front door. Check your carrier's account security or "SIM protection" settings and add this if it isn't already active; it typically takes a few minutes.
Why an authenticator app survives a SIM swap and a text code doesn't
This is the direct link to why two-factor authentication choices matter, covered in more depth in our guide on two-factor authentication for banking. A text-message code is delivered to your phone number, which is exactly what a SIM swap redirects. An authenticator app (like the code-generating apps offered by many banks and third parties) generates codes locally on your specific device, tied to that device's own security setup, not to your phone number. A SIM swap does nothing to an authenticator app, because the app never depended on your carrier in the first place. If your bank offers a choice between SMS codes and an authenticator app, this is the concrete, mechanical reason the app is the stronger option, not a vague preference for "more security."
If a SIM swap just happened to you
If you suspect your number has just been swapped, move quickly:
- Contact your carrier immediately from another phone, a landline, or their website chat, and report the unauthorized SIM change.
- Check your bank, email, and any account that uses SMS codes for unusual activity or login attempts, and change those passwords from a device you're confident is secure.
- Set a port-out PIN once your number is restored, so this specific gap doesn't reopen.
- Watch for follow-on account-recovery attempts on other accounts for the next several days, since an attacker who briefly controlled your number may have used that window to reset passwords elsewhere.
If any account details or money were also exposed during this, our guide on what to do if you gave a scammer your bank details covers the fuller containment sequence.
A note on how to use this
This page explains the SIM swap mechanism in general terms; carrier processes and specific settings vary, so check your own carrier's current security options directly. Please also read our full Disclaimer. FinMateMastery does not sell mobile security products and is not affiliated with any carrier named for illustration.
Frequently asked questions
What is a SIM swap, in plain terms?
It's when someone convinces your mobile carrier to move your phone number to a SIM card they control, instead of the one in your phone. Once done, your calls and texts, including bank verification codes, go to them instead of you.
How do I know if I've been SIM swapped?
The clearest sign is sudden, unexplained loss of phone service: no signal, no calls or texts going through, with no ordinary explanation like a known outage. If this happens, contact your carrier from another device right away.
Does a SIM swap require the attacker to have my physical phone?
No. It's an attack on your carrier account, carried out by phone, chat, or an online portal, not a hack of your device itself.
Does turning off SMS two-factor authentication protect me from SIM swaps?
It removes one specific consequence (a stolen text code), but the swap itself still happens at the carrier level. The stronger combination is a carrier port-out PIN to stop the swap from happening, plus an authenticator app instead of SMS for any account where you have the choice.
Are carriers required to protect against SIM swaps now?
In the US, a Federal Communications Commission rule effective 8 July 2024 requires carriers to authenticate SIM-swap and port-out requests more strictly and to notify customers when one occurs. This raises the baseline but is not a substitute for setting your own port-out PIN.