SIM Swap Protection: Why Text Codes Fail and How to Harden Your Phone Number
How SIM swaps work, why they defeat SMS-based 2FA, and a layered setup, carrier PIN, app codes, hardware keys, that removes your number as a single point of failure.
Published · Updated · 7 min read
A SIM swap is not phone hacking. It is account takeover of your phone number: an attacker convinces or bribes a carrier to move your number to a SIM they control, and from that moment calls and texts to you arrive at their handset. Because so many recovery flows still treat a texted code as proof you are you, a swapped number quickly becomes access to your email, your bank and the reset paths for everything else.
The defense is not to hide your number better. Your number already circulates in breach lists, so decouple sensitive actions from it entirely.
How a swap actually happens
The attacker already knows your name, number and often a recent address, all common broker or breach fields. They contact carrier support posing as you, report a lost phone, supply enough confirmatory pieces to pass a weak knowledge check, and request activation on a new SIM. Where social pretext fails, insiders at retail channels or outsourced support centers are recruited with modest payments. Neither path requires sophisticated technique, just access to customer service tooling that was designed for convenience over resistance.
Once the port completes, the victim's handset shows No Service or SOS only, while the attacker's device completes logins protected only by SMS. Most swaps cluster around high-value targets for a few hours and then reverse, the window is short but the downstream account takeovers persist because password resets and second-factor interceptions already succeeded.
Why SMS one-time codes are the wrong anchor
SMS was never designed as an authenticator. It transits multiple carriers and interconnection exchanges with limited end-to-end integrity, and carrier customer service is an unavoidable trusted party who can reassign it. That is why security guidance now ranks SMS lowest among second factors: it stops bulk credential stuffing but fails against number-targeted attackers, who are precisely the ones pursuing higher-value accounts.
Use SMS only where the service offers nothing else. Treat any 'we sent you a code' flow that cannot be changed to an app or key as a remediation priority after enabling stronger factors elsewhere.
Layer one: make the number hard to move
Carriers offer account-level protections that frontline support must check before any port. These vary by name, Number Transfer PIN, Number Lock, Port-out protection, but functionally require a separate PIN or in-app approval before the number leaves. Enable every available lock and replace any default or birth-year PIN with a generated one stored in your password manager.
- Log into your carrier account and turn on Number Lock / Transfer Lock if present; otherwise add a dedicated Port-out PIN.
- Add a distinct account PIN and a separate billing passcode, neither derived from birthdays or addresses present in broker data.
- Require in-store photo ID for SIM changes if your carrier supports it, and remove authorized users who no longer need account access.
- Ask support to annotate the account with 'no SIM changes without callback to on-file number', not universally enforced but logged for dispute resolution.
Layer two: move sensitive factors off SMS
Even a well-locked number should not gate your primary email or financial accounts. Migrate those services to authenticator-app codes (TOTP) or, better, hardware security keys and passkeys, which are origin-bound and cannot be forwarded via number compromise. Keep SMS as a backup factor only for low-value services, and ensure email, the real recovery hub, never relies on a text code alone.
Practical ordering helps adoption: move your password manager and primary email to a hardware key first, then banking and cloud consoles to app codes, then long-tail accounts as you touch them. Save recovery codes for each service on paper, stored separately from your phone.
If you see SOS only unexpectedly
Loss of service without a known outage is the signal to act. From another device, log into your carrier account and re-lock the number if possible, then immediately rotate passwords for email and financial services from a trusted network, revoke active sessions and review forwarding rules and newly added recovery numbers. Place a fraud alert with the credit bureaus the same hour, swapped numbers are often followed by application-fraud attempts that reuse the same identity pieces.
Notify the carrier's fraud team with precise timestamps, file a report if directed, and request a detailed record of which channel authorized the swap. Most carriers restore numbers within hours and open abuse tickets that block further ports while investigation proceeds.
Your phone number is an identifier, not a secret and not a possession proof. Lock its portability at the carrier, move critical logins to app or hardware factors that do not touch telephony, and keep paper recovery codes where only you can find them.