SIM Swapping Attacks Explained: Why Your Phone Number Isn't a Safe Login
SIM swapping is when a criminal tricks your mobile network into moving your number to their SIM. Once they control your number, any security code sent by text lands on their phone. This article explains how the attack works, why SMS codes are weak, and how app-based MFA and a locked-down mobile account protect you.
Your phone number was never meant to be a password
Most of us treat our mobile number as something private and permanent. In reality it’s surprisingly easy for a criminal to take it away from you, and when they do, the security codes you rely on can end up on their phone instead of yours.
This is called SIM swapping (sometimes SIM hijacking or a port-out scam). It’s one of the main reasons security experts, including the NCSC, now recommend app-based authentication over codes sent by text message. Here’s how it works and what you can do about it.
What is SIM swapping?
Your SIM card is the small chip that links your phone to your mobile number. When you get a new phone or a replacement SIM, your network transfers your number to the new card. That process is meant to help you, but criminals abuse it.
In a SIM swap attack, the criminal contacts your mobile provider pretending to be you. They claim their phone was lost, stolen or damaged and ask for the number to be moved to a new SIM, one they control. If they convince the network, your phone goes dead and every call and text meant for you now arrives on their device.
They don’t need your handset. They only need to persuade a customer service agent, or an automated system, that they are you.
How criminals pull it off
SIM swapping usually starts with a bit of homework. The attacker gathers personal details about you first, often from:
- Data breaches where your name, date of birth, address and phone number have leaked.
- Social media, where answers to security questions (pet names, schools, birthdays) are frequently on display.
- Phishing messages designed to trick you into handing over account details directly.
Armed with enough information to pass the network’s identity checks, they request the swap. Some attacks also rely on bribing or socially engineering staff. Either way, the weak point is the identity check at the mobile provider, not your phone itself.
Why SMS security codes are the target
Many services send a one-time code by text message as a second step when you log in or reset a password. It feels secure because only your phone should receive it. But that assumption breaks the moment someone else controls your number.
Once a criminal has your number, they can:
- Go to your email or banking login and request a password reset.
- Receive the reset link or verification code by text, on their phone.
- Set a new password and lock you out.
Email is the biggest prize, because whoever controls your inbox can reset the password on almost everything else. This is exactly how many cases of account takeover begin.
The moment someone else controls your number, every security code sent by text lands on their phone, not yours.
App-based MFA is the safer choice
Multi-factor authentication (MFA) means proving who you are with more than just a password. The safest forms don’t depend on your phone number at all.
- Authenticator apps such as Microsoft Authenticator or Google Authenticator generate a fresh code every 30 seconds on your device. The code is created on the phone itself and never travels across the mobile network, so a SIM swap can’t redirect it.
- Push approvals send a ‘yes/no’ prompt to an app you’ve already signed into, again tied to the device rather than the number.
- Physical security keys (small USB or tap-to-use devices) are the strongest option of all and are effectively immune to this kind of attack.
The practical takeaway: wherever a service lets you choose, pick an authenticator app or a security key over text codes. We cover the wider topic in our guide to multi-factor authentication. Note that an SMS code is still much better than no second step, so don’t switch it off if it’s your only option.
How to protect your mobile account
Because the attack targets your mobile provider, some of the strongest defences live there:
- Add a PIN or passcode to your mobile account. Most UK networks let you set a separate number or password that must be quoted before any changes are made. This is one of the single most effective steps.
- Ask your provider about port-out or SIM-swap protection. Some offer extra verification before a number can be moved.
- Be sparing with personal details. The less an attacker can find about you online, the harder it is to pass identity checks. Tidy up what’s public on social media.
- Watch for sudden loss of signal. If your phone drops to ‘No Service’ for no reason, especially alongside unexpected password reset emails, contact your network immediately from another phone.
- Use a password manager so a breach of one account doesn’t expose the details criminals need. See our pick of the best password managers for UK small business.
What to do if you think you’ve been SIM swapped
Speed matters. If your phone goes dead unexpectedly and you suspect a swap:
- Contact your mobile provider from another phone and tell them you think your number has been transferred without permission.
- Secure your email first, then banking, then other accounts, changing passwords and switching to app-based MFA as you go.
- Check your bank and payment accounts for anything unfamiliar and report fraud to your bank and to Action Fraud.
- Turn on login alerts where available so you’re warned about future access.
The bottom line
SIM swapping works because a phone number is easy to move and text messages are easy to redirect. You can’t fully control your mobile provider’s checks, but you can stop relying on SMS as your main line of defence. Put a PIN on your mobile account, move your important logins to an authenticator app or security key, and keep an eye out for that tell-tale loss of signal.
If you’d like help reviewing how your business logs in and where you’re still depending on text codes, get in touch with DACROS. We help small businesses across Leeds and Yorkshire tighten up everyday security without the jargon.
Frequently asked questions
What is a SIM swap attack in simple terms?
It's when a criminal persuades your mobile network to transfer your phone number onto a SIM card they control. Your phone loses signal, and their phone starts receiving your calls and texts, including any security codes sent by SMS. They can then use those codes to break into your accounts.
How do I know if I've been SIM swapped?
The clearest sign is a sudden, unexplained loss of mobile signal or 'No Service' when you should have coverage, often followed by password reset emails or login alerts you didn't request. If your phone goes dead for no reason, contact your network straight away using another phone.
Is app-based MFA really safer than text message codes?
Yes. An authenticator app generates codes on your device itself, so they never travel across the mobile network and can't be redirected by a SIM swap. Codes from apps like Microsoft Authenticator or Google Authenticator, or a physical security key, are much harder for an attacker to intercept than SMS.
Should I stop using SMS codes altogether?
An SMS code is still far better than no second step at all. If a service only offers text codes, keep using them. But where you can choose, switch to an authenticator app or a security key, especially for email, banking and anything that controls your other accounts.
Dacros — led by Jordan Gilbert
Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.
Related guides
The backup password on the laptop you're backing up
Recovery controls fail in a way audits miss: the control quietly depends on the very thing it is meant to recover you from. We found five in our own systems in a week — here's the one question that finds them, and a two-hour fix.
Read → GuideIT and Cyber Security for Charities and Non-Profits in the UK
A plain-English guide to IT and cyber security for UK charities: protecting donor and beneficiary data, controlling volunteer access, and Cyber Essentials on a tight budget.
Read → GuideIT & Cyber Security for Solicitors and Law Firms: A Plain-English Guide
A practical guide to IT security for UK law firms: client confidentiality, SRA-aligned controls, secure email and documents, DMARC, backups and staying compliant.
Read →Want this handled for you?
Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.