A SIM swap attack never touches your phone. No malware, no stolen device, no cracked password at the start. The attacker goes after your mobile carrier instead, and if they succeed, every SMS meant for you, including your two-factor login codes, arrives on their device instead of yours. Your phone just goes quiet.
That is what makes SIM swapping so dangerous: the strongest password in the world doesn't help when the attacker can receive your "verification" texts. This post explains how the attack actually unfolds, why SMS-based 2FA is the specific weak link, and the four defenses that matter, ranked by how much protection each one buys you.
How a SIM swap actually unfolds
Your phone number is not tied to your physical SIM card. It is an entry in your carrier's database, and carriers move numbers between SIM cards all the time. That is a legitimate, necessary feature: it is how you keep your number when your phone is lost, stolen, or upgraded.
A SIM swap abuses that feature. In broad strokes:
- The attacker gathers personal details about you. Names, birthdays, addresses, and account details circulate in data breach dumps and on social media. None of it is secret in practice.
- They contact your carrier pretending to be you. A convincing story ("I lost my phone, I need my number moved to a new SIM") plus a few correct personal details is often enough to pass a support agent's identity check. In some cases attackers bribe or recruit insiders instead of tricking them.
- The carrier ports your number to the attacker's SIM. Your phone drops off the network. Theirs lights up with your number.
- SMS codes and calls now reach the attacker. They trigger password resets and 2FA prompts on your email, bank, and crypto accounts, and the confirmation codes go straight to them.
The whole attack can run its course in under an hour, and the first accounts hit are usually email and banking, because your email unlocks password resets for everything else.
Why SMS 2FA is the weak link
Two-factor authentication is supposed to prove you hold something the attacker doesn't. SMS 2FA fails that test in a specific way: the "something you have" is not your phone, it is your phone number, and your number is controlled by a third party whose support staff can be socially engineered.
Compare that with TOTP, the time-based codes generated by an authenticator app. A TOTP secret lives on your device and nowhere else. There is no carrier in the loop, no support agent who can be talked into handing it over, and no network transmission to intercept. A successful SIM swap gives the attacker your texts and calls, but it gives them nothing from an authenticator app, because the codes never travel through the phone network at all. If you are still choosing an app, our comparison of the best authenticator apps covers the honest tradeoffs.
To be clear about limits: TOTP protects you from SIM swaps and code interception, but it is not phishing-proof. A fake login page can still trick you into typing a valid code. Hardware security keys and passkeys close that gap too; see 2FA vs passkeys for when each makes sense. For most people, moving from SMS to TOTP is still the single biggest jump in protection available today.
Your defense plan, ranked by impact
1. Move your 2FA from SMS to an authenticator app
This is the defense that removes the prize. If your important accounts use app-generated codes instead of texted ones, a successful SIM swap gets the attacker a phone number and very little else. Start with your email account, then banking, then everything holding money or identity. Most services let you switch under security settings: open two-factor authentication, choose "authenticator app", and scan the QR code. Then, critically, disable SMS as a 2FA method where the service allows it; leaving SMS enabled as a fallback leaves the weak link in place. We maintain setup guides for over 2,000 services if you want service-specific pointers. Authenticator by Vidus6 generates these codes entirely on-device and works offline, so there is no server-side copy of your secrets to attack.
2. Lock down your carrier account
Most carriers offer some combination of an account PIN, a port-freeze (also called number lock or port-out protection), and a SIM-change lock. These add a barrier that a smooth-talking attacker has to get past before your number can move. Call your carrier or check its security settings, enable every lock they offer, and pick a PIN that is not your birthday or address, since those are exactly the details attackers already have. This defense is real but weaker than #1, because it depends on carrier staff actually enforcing it.
3. Remove your phone number as a recovery method
2FA is only half the story. Many services will reset your password via a code texted to your recovery number, which means a SIM swapper can skip your password entirely. Audit the recovery options on your email and financial accounts and replace phone-number recovery with recovery codes stored somewhere safe. Our guide to managing 2FA recovery codes covers where to keep them. Some services insist on keeping a phone number; where you can't remove it, the carrier locks from step 2 matter more.
4. Use unique passwords everywhere
A SIM swap is most devastating when combined with a reused password from an old breach: the attacker logs in with the leaked password and clears the SMS check with your hijacked number. Unique passwords from a password manager mean the attacker has to break each account separately, which usually stops the chain at account one.
Early warning signs of a SIM swap
Speed matters enormously during an attack in progress. Watch for:
- Sudden, total loss of signal in a place you normally have coverage, especially if other phones around you work fine. This is the classic sign your number just moved.
- Unexpected texts from your carrier about a SIM change, port request, or account change you didn't make. Never ignore these.
- Password-reset emails you didn't request, or login alerts from unfamiliar devices.
- Being logged out of accounts or finding your credentials suddenly rejected.
If you see these together, call your carrier immediately from another phone, tell them you suspect an unauthorized SIM change, then change your email password from a device that is still logged in and check your account recovery settings for changes.
FAQ
Is SMS 2FA better than nothing?
Yes. SMS 2FA still blocks the common case of a stolen password being tried from a random botnet. The problem is that it fails precisely when you are individually targeted, which is when you need 2FA most. Treat it as a floor, not a solution.
Does a SIM swap affect my authenticator app codes?
No. TOTP secrets are stored on your device, not tied to your phone number. An attacker who hijacks your number gains nothing from your authenticator app. That is the entire point of switching.
Are eSIMs safe from SIM swapping?
Not inherently. An eSIM removes the physical card, but the attack targets the carrier's account systems, not the plastic. The same carrier locks and the same move away from SMS 2FA apply.
The bottom line
You cannot fully control your carrier's help desk, so build your security to survive it: TOTP codes instead of SMS, carrier locks as a speed bump, no phone-number recovery on critical accounts, and unique passwords to break the chain. Do the first item this week; it converts a SIM swap from an account takeover into a minor inconvenience. When you are ready to switch, Authenticator by Vidus6 is free on iPhone, iPad, Mac, and Android.


