Glossary

SIM swap

A SIM swap moves a phone number to a new SIM. In SIM swap fraud, a criminal does it to receive the victim's calls and one-time passcodes. How it works and how to defend.

Last updated

An account's two-factor phone number is changed to a VoIP number; the change is flagged and an extra verification step is required.An account's two-factor phone number is changed to a VoIP number; the change is flagged and an extra verification step is required.

A SIM swap is the transfer of a mobile phone number from one SIM card or eSIM profile to another. Operators do it every day for customers who lose or replace a phone. In SIM swap fraud, a criminal tricks or bribes someone at the operator into moving the victim's number to a SIM the criminal controls. From that moment, the criminal receives the victim's calls and text messages, including one-time passcodes.

How does SIM swap fraud work?

The number stays the same, but the SIM behind it changes. In network terms, the operator links the victim's MSISDN to a new IMSI. The victim's phone loses service, and the attacker's phone starts receiving everything sent to the number.

The US FBI's Internet Crime Complaint Center describes the usual methods as social engineering, insider threat and phishing aimed at operator staff (IC3 public service announcement, February 2022). It reported that in 2021 it received 1,611 SIM swapping complaints with adjusted losses of more than $68 million. Attackers then use SMS codes to reset passwords for e-mail, bank and cryptocurrency accounts.

A close relative is the port-out scam, where the attacker moves the number to another operator instead. See mobile number portability.

What are regulators doing?

In November 2023 the FCC adopted rules on SIM swap and port-out fraud. They require US wireless providers to use secure methods to authenticate a customer before moving a number to a new device or provider, and to notify customers immediately when a SIM change or port-out request is made on their account.

NIST's digital identity guidelines (SP 800-63B-4) treat one-time codes sent over the phone network as a restricted authenticator. They tell verifiers to consider risk indicators such as a device swap, SIM change or number porting before sending a code that way.

What are the warning signs for a business?

  • A password reset or 2FA change shortly after the customer reports "no service", or with no prior contact at all.
  • A login from a new device and location right after an SMS code was sent.
  • A recent port of the number to another operator, especially just before a sensitive action.
  • Support contacts asking to change the phone number on an account under time pressure.

How can you reduce the risk?

  1. Don't rely on SMS alone for high-value actions. Offer app-based authenticators, passkeys or hardware keys.
  2. Step up verification when a number was recently ported or swapped, or when other session signals look unusual.
  3. Delay sensitive changes such as a new payout account or a new 2FA number, and notify the old contact details.
  4. Log the checks you ran and when, so disputes can be investigated.

How does MobileValidate help?

MobileValidate does not currently offer a SIM-change check. It provides signals that help with related risks:

  • The carrier lookup returns the current carrier and, when the number was ported, the original_carrier. A port shortly before a password reset is worth a second look.
  • The upcoming HLR lookup will report whether the number is reachable and ported. It will never return the IMSI or other network identifiers.

See account security for a workflow that combines these signals with your own session data.

Frequently asked questions

Is every SIM swap fraud?

No. People swap SIMs legitimately when they lose a phone, move to an eSIM or replace a damaged card. A swap is a risk signal only when it is recent and combined with other unusual activity.

How is a SIM swap different from a port-out scam?

A SIM swap moves the number to a new SIM at the same operator. A port-out scam moves it to a different operator. Both hand the victim's number to the attacker.

Does MobileValidate offer a SIM swap check?

Not today. MobileValidate reports porting and line type, which help with related risks. For SIM-change dates you need a service that obtains them from the operator with the subscriber's consent.

All articles