SIM-swap is an attack where a fraudster transfers your SIM card to their phone. After that, all your SMS, calls, and push notifications via the mobile network go to them — including 2FA codes from your bank and crypto exchanges.

How It Happens

Most often — through social engineering at a mobile carrier's office. The attacker arrives with forged documents, requests a SIM replacement (claiming the original was lost), and takes the new SIM. Within 10–20 minutes, your card stops working.

Another variant: port-out of the number to another carrier — also based on forged documents. In this case, your number completely leaves your original network.

A third, rarer method: bribing a carrier employee. Several high-profile cases in the US and Russia have shown that the insider channel also works.

What the Attacker Does Next

With your SIM, they:

  • Initiate password recovery for your email via SMS.
  • Log into your banking app, confirming transactions with SMS codes.
  • Access your crypto exchange (if you use SMS 2FA) and withdraw funds.

The window of opportunity is hours. If you notice your phone suddenly stops working for no apparent reason — it could be a SIM-swap, and you need to react urgently.

Protection 1: Remove SMS from Critical 2FA

The main measure. If your bank, exchange, and key email accounts use an authenticator app or hardware key instead of SMS — SIM-swap becomes powerless. The attacker gets the SIM but not the access.

Protection 2: Set a PIN Code on Your SIM Account with the Carrier

Most carriers allow you to set a password or code word on your account. Without it, no operations (including SIM replacement) should proceed. Check with your carrier how to enable this and how strictly they enforce the rule.

Protection 3: Use a Separate Secure Number

Buy a second SIM, never publish its number anywhere, and use it only for critical accounts. The number on your website, email signature, or social media — is not this one. Harder to find means harder to attack.

Protection 4: Don't Link Your Number to Account Recovery

In Google, Apple, Microsoft security settings, verify that recovery uses an authenticator or recovery codes, not SMS. Many think they've disabled SMS, but it remains as a backup channel.

If It Has Already Happened

Call your carrier immediately from another phone, demand SIM blocking and contact their security department. Simultaneously change passwords on critical accounts (bank, email, exchange). If you suspect financial transactions — call the police, gather evidence; banks do investigate such cases (especially if SIM-swap is easily proven).

VirtCardPay

A virtual card in 2 minutes

Pay for subscriptions, AI tools, travel, and international stores. Top up via USDT-TRC20 with no acquiring fees.

Open in Telegram Learn more about the service →
This material is for informational purposes only and is not financial advice. Data and service terms may change, so check primary sources before making a payment or investment decision. Mentions of third-party brands and services do not imply official partnership, support, or endorsement by VirtCardPay.
Back