Learn › Take back control

SIM swaps: when your phone number walks away

Last reviewed 2026-07-29

Why your phone number is a master key

Your phone number was never designed to be a security credential, but it functions like one anyway. Banks, email providers, and social platforms routinely send one-time codes by text message to confirm it’s really you, and many let you reset a forgotten password with nothing but access to that number. The FCC’s guide to SIM swap and port-out fraud puts it plainly: “your mobile phone number may be the key to your most important financial accounts,” since “text messages are often used by banks, businesses and payment services to verify your identity when you request updates to your account.” Whoever holds your number, even briefly, can walk through that door.

A SIM card moving between phones with an alert

How takeovers actually happen

There are two distinct scams the FCC treats as related but separate.

Both routes let an attacker intercept your calls and SMS codes without touching your physical phone. The same FCC advisory also notes threat actors using tactics like emergency-disclosure requests to pull information from carriers, and cites a Department of Homeland Security review finding bad actors compromising telecom infrastructure directly to intercept authentication codes.

Insider fraud is documented, not hypothetical. In one federal case, a manager at a wireless carrier’s Orlando office used his employee access to “bypass the provider’s security protocols,” letting a group swap victims’ SIM cards without calling in as the victim — the Department of Justice reported the scheme stole more than $509,475 in cryptocurrency before four men were sentenced to prison.

eSIM technology, now standard on newer phones, closes off the physical-theft version of this attack — eSIMs are “hardwired inside the phone” and can’t be pulled out and moved to another device — but it does nothing to stop a social-engineered swap or a port-out, which happen on the carrier’s side. “Port-out scams remain a security concern” even with an eSIM, the FCC notes.

What the FCC’s rules require — and their actual status

In November 2023 the FCC adopted new rules requiring carriers to authenticate customers before SIM changes and port-outs, notify customers immediately, offer a free account lock, train staff, and help remediate fraud — the FCC’s Report and Order sets out the framework, summarized in the FCC’s enforcement advisory. Carriers must:

The FCC writes that these protections “can act as a shield for domestic violence survivors by preventing bad actors, such as abusers, from taking control of a survivor’s phone or phone number.”

Here’s the honest version of where things stand: these rules are adopted, but the compliance date has been unsettled for two years — don’t assume every carrier is already legally required to comply. The rules originally carried a July 8, 2024 compliance date, but the FCC’s Wireline Competition Bureau waived that deadline, “result[ing] in a single synchronized timeframe”: the whole package becomes mandatory once the Office of Management and Budget finishes its Paperwork Reduction Act review and the FCC publishes a Federal Register notice announcing the compliance date. The Federal Register’s regulatory tracker for this rulemaking still lists “Next Action Undetermined,” with no compliance-date notice on record. Carriers may implement pieces voluntarily, but as of July 2026 no confirmed date has made the package mandatory — turn on a carrier’s lock feature regardless, not because the mandate is confirmed in force.

Turning on your carrier’s lock feature

Even without a confirmed compliance date, several major carriers already offer free lock features you can turn on today. Two documented examples:

If your carrier isn’t listed here, search its support site for “port lock,” “number lock,” “SIM protection,” or “port freeze” to see what it already offers.

The intimate-adversary problem: family plans

None of the protections above fully help if the threat is the person who legally administers your line. On a shared family plan, the primary account holder can typically see billing details, manage lines, and request account changes. Both carriers build this in: only T-Mobile’s Primary Account Holder can remove Port Out Protection once added, and only Verizon’s Account Owners or Account Managers can toggle Number Lock. If the person you’re worried about holds that role, a lock they also control isn’t a real barrier — though an authorized user can still add protection to their own line without the administrator’s help.

If you’re on a shared plan with someone unsafe, the practical fix is getting your own line, not just adding settings to a shared one. See A new phone, a clean start for how the Safe Connections Act lets survivors of domestic abuse and related crimes separate their line from a shared plan. Pair that with a full account-security pass — new passwords, non-SMS two-factor authentication, and a recovery-access review — covered in Securing your accounts when someone knows you.

Signs it’s happening to you

The clearest sign is sudden, complete loss of cell service: no bars, no calls, no texts, when your phone should otherwise be working normally. That’s different from a dead zone or an outage — a swap or port-out kills your line entirely, because it no longer belongs to your SIM. Other signs: unexpected “your SIM has changed” or “your number has been ported” notifications you didn’t request, login alerts or password-reset emails you didn’t trigger, or accounts suddenly showing you logged out everywhere.

What to do if you lose service unexpectedly

  1. Get to Wi-Fi and contact your carrier immediately, using a different phone or browser-based chat if you have to, and ask them to investigate and lock the account against further changes.
  2. Change your carrier account password and PIN once you regain access, from a device you know is secure.
  3. Check financial and email accounts for unauthorized resets or logins, and follow that provider’s own account-recovery process directly.
  4. File a report. The FCC recommends contacting local law enforcement and filing a police report, filing an identity theft report with the FTC, and placing a fraud alert with one of the three major credit bureaus, which will share it with the other two.
  5. Ask your carrier for documentation of the fraud — it can help if you need to dispute fraudulent charges or accounts opened in your name.

If the loss of service coincides with other signs of monitoring or control by someone you know, treat this as part of a larger pattern, and read Safety first: before you remove anything before changing settings that person might notice.

No lock or setting makes a phone number un-stealable — authentication still depends on a human at a call center getting it right every time. But between the carrier account locks available today, the FCC’s rules once they take full effect, and getting off a shared plan with the wrong person, you can close off most of the paths that don’t require anyone to touch your physical device at all.