SIM swaps and account takeovers: locking the front door
Your phone number is the master key to your financial life — and a stranger can steal it with a phone call to your carrier.
Your phone dies mid-afternoon — no bars, 'No SIM.' Annoying, you think. Meanwhile, across town, someone who convinced your carrier to move your number onto their SIM is receiving every text meant for you — including the six-digit codes your bank, email, and crypto exchange send to 'verify it's really you.' Within hours, passwords are reset, accounts are drained, and you're on hold with customer service trying to prove you're yourself. That's a SIM swap, the sharpest tool in the account-takeover kit, and the FBI logs tens of millions of dollars in losses to it yearly.
How takeovers actually start
- SIM swap: the attacker social-engineers your carrier (or bribes an insider) with your name, birthday, and address — often already leaked in data breaches — to port your number to their device. Your SMS codes become their SMS codes.
- Credential stuffing: your email + password from an old breach, tried automatically against banks, brokerages, and retailers. Works because most people reuse passwords.
- Phishing with real-time relay: a fake login page that forwards your credentials AND your 2FA code to the real site within seconds.
- Email takeover first: control of your inbox means control of every 'reset password' link in your life. Your email account is the actual crown jewels.
Hardening, in priority order
- Put a port-out PIN / number-lock on your mobile account today. Every major US carrier offers one (Verizon Number Lock, T-Mobile SIM Protection, AT&T passcode). This single free setting defeats most SIM swaps. Five minutes.
- Move 2FA off SMS wherever anything valuable lives: use an authenticator app, or better, hardware security keys or passkeys for email, bank, and brokerage. If the code never travels by text, a stolen number is useless.
- Fortify your primary email above everything else — unique password, strongest available 2FA, current recovery methods. It's the reset button for every other account.
- Use a password manager and stop reusing passwords, which neutralizes credential stuffing entirely. Prioritize: email, bank, brokerage, carrier, Amazon, payment apps.
- Set up account alerts (login, transfer, new payee) at your bank and brokerage — takeovers are stopped by minutes, and an instant push notification is your tripwire.
- Freeze your credit at all three bureaus so a takeover can't also become new loans in your name.
Why SMS codes became the weak link
Two-factor authentication by text message was a genuine improvement over passwords alone — a decade ago. The problem is architectural: the code's security depends entirely on your phone number staying yours, and phone numbers were never designed to be identity documents. Carriers transfer them between SIMs thousands of times a day for legitimate reasons (lost phones, upgrades, new carriers), and every one of those routine processes is a door an attacker can talk their way through. Financial accounts, meanwhile, increasingly treat a phone number as proof of identity for password resets. That mismatch — a casually transferable number guarding rigorously protected money — is the entire vulnerability. It's also why the fix is specific: move the second factor onto something that can't be transferred by a phone call, meaning an authenticator app, a hardware key, or a passkey bound to your device.
Signals you're being set up
- Password-reset emails you didn't request (someone is testing your locks).
- 2FA codes arriving out of nowhere (they have your password; the code is the last wall).
- Carrier notifications about account changes, new devices, or ported numbers.
- 'Bank fraud department' calls asking you to read back a code just sent to you — that code is a reset code they triggered; reading it aloud hands over the account. Banks never ask you to read codes to them.
- Small unfamiliar charges or a new payee you didn't add — probing before the real move.
If it happens anyway
- Reclaim the phone number first (carrier fraud line), then the email, then financial accounts — that order matters, because each protects the next.
- Call every financial institution's fraud line the same day: freeze transfers, reverse what's reversible, kill open sessions and API/third-party access.
- Change passwords from a known-clean device, not the possibly compromised one.
- File at ic3.gov and identitytheft.gov, and request the carrier's records of the swap — useful for disputes and any regulatory complaint.
- Afterward, do the hardening list above; victims are re-targeted, because attackers know exactly what they got the first time.
The bottom line
Modern account theft rarely involves 'hacking' anything — it's your phone number hijacked by a phone call, your reused password from a 2019 breach, your SMS codes intercepted at the carrier level. The counters are unglamorous and nearly free: lock your number, get codes off SMS, guard your email like the vault it is, and let a password manager end reuse forever. Do it before the afternoon your phone goes silent.
Check your understanding
1 of 3Not quite — try again.
Get smarter about money every week
One email, no spam — practical guides and Worth updates. Unsubscribe anytime.
Put this into practice
Worth tracks your accounts, budgets, and goals — so the concepts in this article aren't just theory.
Start free trial