← all articles

SIM Swap Fraud and What a Carrier Lock Actually Does

What sim swap fraud actually is

A SIM swap is when someone convinces your mobile carrier to move your phone number onto a SIM card they control, without your involvement. Once that happens, calls and texts meant for you go to their device instead. If your phone number is tied to account recovery or two-factor codes anywhere, they now have a shot at those too. Your phone still works for Wi-Fi calling and apps you’re logged into, but the cellular number itself has quietly changed hands.

This isn’t a hack in the Hollywood sense. Nobody is breaking encryption or exploiting a software bug in your phone. It’s a fraud against your carrier’s customer support process, and it works because that process was built to help people who lost their phone, not to stop people impersonating someone who didn’t.

Why phone numbers became a security chokepoint

Phone numbers ended up load-bearing for security almost by accident. SMS was cheap, universal, and didn’t require an app, so it became the default second factor for banks, email providers, and exchanges. Password reset flows followed the same logic: “forgot your password? we’ll text you a code.”

The problem is that a phone number isn’t actually something you possess in a cryptographic sense. It’s an entry in a database at your carrier that says which SIM currently owns that number. Anyone who can get the carrier to change that entry effectively takes over everything downstream that trusts the number, without ever touching your device.

How the swap happens in practice

Most SIM swaps start with information gathering, not technical exploitation. Attackers piece together your name, phone number, billing address, and answers to common account-recovery questions from data breaches, social media, or straightforward searching. Some of this is bought on forums where breached datasets get traded.

With that in hand, they contact the carrier, usually through phone support or a retail store, and claim to be you reporting a lost phone or upgrading to a new SIM. If the carrier’s verification relies on things like your date of birth, last four of your SSN, or account PIN, and any of that has leaked before, the attacker can pass the check. In some documented cases, attackers have also bribed or coerced carrier employees directly, which sidesteps the verification question entirely, since the person approving the swap already has account access.

Once the number ports over, the attacker starts triggering “forgot password” flows on your email, bank, or crypto exchange accounts. The SMS codes go to their SIM. If your email recovery also hinges on that same phone number, they can often chain into other accounts from there, resetting one credential after another.

What a carrier lock actually does under the hood

A carrier lock, sometimes called a port-out PIN, port freeze, or number lock depending on the provider, is a flag set on your account that requires an additional, separate authentication step before any SIM change or number port is processed. Practically, this usually means:

  • A PIN or passcode that’s distinct from your general account password, which support staff and automated systems are required to check before touching the SIM assignment.
  • In some cases, a temporary block that prevents any port-out request from being approved at all until you personally lift it, often only in person or through a verified in-app request.
  • With some carriers, an additional identity check, like requiring the request to come from the device already on the account, or requiring a waiting period before a port completes.

Mechanically, this works by adding friction at the one step attackers need: convincing a support rep or automated system to reassign your number. If the rep is required to ask for a port-out PIN you never gave them, and they don’t have it, the swap doesn’t happen through the normal support channel.

What it does not fix

A carrier lock raises the bar at the front door. It does not remove every other way in.

It doesn’t protect you if the PIN itself leaked, say from a data breach, a phishing page mimicking your carrier, or you reusing it as a password elsewhere. A PIN is still just a shared secret, and shared secrets can be stolen the same way passwords can.

It doesn’t stop insider fraud. If a carrier employee has legitimate system access and is bribed, coerced, or simply chooses to bypass the check, the lock doesn’t factor in, because the fraud happens above the layer the PIN protects.

It doesn’t fix the underlying design problem, which is that a phone number was never meant to be a strong identity credential. Even with a locked SIM, if your email and financial accounts still accept SMS codes as their only second factor, you’re one successful bypass away from the same outcome. The carrier lock protects the number. It doesn’t protect everything downstream that trusts the number.

It also isn’t universal. Not every carrier offers the same version of this feature, and enrollment is often opt-in, meaning it does nothing for you until you specifically turn it on.

Reducing your reliance on the phone number

The more durable fix isn’t a single setting, it’s reducing how many places treat your phone number as proof of identity. A few concrete moves, each incremental rather than a silver bullet:

Move two-factor authentication from SMS to an authenticator app where the option exists. Apps like Google Authenticator or Authy generate codes locally on your device using a shared secret established at setup, so there’s no SMS message for an attacker to intercept even if your number is compromised. The tradeoff is you have to manage device backups yourself instead of relying on your carrier.

Where a service supports it, use a hardware security key or passkey instead of a code-based second factor. These rely on public-key cryptography tied to the specific device and the specific website, which means a SIM swap has nothing to intercept, there’s no code being sent anywhere.

Check whether your email recovery options still list your phone number as a fallback, and if so, whether that’s the only fallback. An email account that can be reset purely by SMS is a single point of failure for everything else tied to that email.

Enable your carrier’s port-out lock if it’s offered, and treat the PIN it uses like a real credential: unique, not reused, and not something you’d type into a page you reached by clicking a text message link.

None of these steps individually makes you untouchable, and no combination of them guarantees you can’t be swapped. What they do is remove the easy paths, so an attacker needs more than a phone call and a guessed birthdate to get anywhere.

Who actually needs to worry about this

Most people are a low-value target for a SIM swap, because the effort to research and execute one only pays off if there’s something worth stealing on the other end. The people who show up repeatedly in reported cases are cryptocurrency holders with visible wallet balances or exchange accounts, people with recognizable online followings whose social accounts have resale value, and executives or public figures whose email access is worth more than a typical balance.

If none of that describes you, a carrier lock plus moving off SMS-based 2FA where practical is probably enough attention to give this. If it does describe you, particularly if you hold crypto on an exchange or in a way that SMS still gates access to, it’s worth treating the phone number as the weakest link in the chain and building around it rather than relying on it.

If your carrier account, email, or exchange logins get compromised, contacting the carrier and the affected platforms directly to regain control and report the incident is the practical first step. Anything involving loss recovery or legal action is a separate question for the platforms’ fraud teams or a professional, not something to work out from a blog post.

Want more explainers like this one, written the same way, mechanism first, no fear-selling? Head back to the homepage for the rest of what we cover.

from the team
Want a real mobile IP, not a datacenter VPN endpoint?

Shared VPN exit nodes get flagged and blocked. Singapore Mobile Proxy runs real 4G/5G mobile IPs that give you a residential-grade address carriers still trust.

see how it works →
read on
More from The Privacy Wire

VPN and tool reviews, realistic opsec guides, and privacy news for people who want to protect their data.

browse all articles →