Imagine your phone is sitting right there in your pocket, fully charged, never out of your sight, and yet a criminal has just taken control of your phone number. Your calls and texts start going to them instead of you, and you may not even notice at first. It sounds impossible, but it is a real and increasingly common attack called SIM swapping, and it is especially dangerous for anyone whose accounts, business or personal, are protected by codes sent over text message. Which, for most of us, is a lot of accounts.
Here is why this one deserves your attention: your phone number has quietly become a master key to your digital life. So many services send login codes and password-reset links by text that whoever controls your number can often unlock your email, your banking, and your business accounts. SIM swapping is how criminals steal that key without ever laying a finger on your phone. Let me explain how it works, how to know if it is happening, and, most importantly, the simple changes that make you far harder to hit.
What SIM swapping actually is
Your phone number is not really tied to your physical phone. It is tied to your SIM, the small chip (or these days often a built-in eSIM) that your mobile carrier links to your number and your account. Whoever's SIM your carrier associates with your number receives your calls and texts. And that association is something your carrier can change, which is the whole vulnerability.
In a SIM swap attack, a criminal contacts your mobile carrier pretending to be you and convinces them to move your phone number to a new SIM, one in a device the criminal controls. To pull this off, they use personal information about you, often gathered from data breaches, social media, and public records, to pass the carrier's identity checks. Once the carrier makes the switch, your number now lives on the criminal's device. Your own phone typically loses service, and every call and text meant for you, including those all-important verification codes, now goes to the attacker.
Notice what this really is: it is not a hack of your phone or a virus. It is social engineering aimed at your phone company, tricking a human at the carrier into handing over your number, which is exactly the kind of manipulation we describe in our overview of social engineering. The criminal attacks the weakest link in the chain, the carrier's identity check, rather than your device.
Why stealing your number is so powerful
You might wonder why a criminal would want your phone number badly enough to go to this trouble. The answer is what that number unlocks. Over the years, phone numbers became a default way to verify identity online. Countless services send a code by text to confirm it is really you, and many let you reset a forgotten password using a text message. That convenience is exactly what the attacker exploits.
Once the criminal is receiving your texts, they can request password resets and login codes for your accounts and receive them directly. That can mean your email, which is the recovery point for nearly everything else, your banking and financial accounts, and your business systems. In effect, SIM swapping is a way around the text-message form of two-factor authentication, because the "second factor," the code sent to your phone, is now going to the criminal. This is why the attack is so prized by criminals and so damaging to victims: control of one phone number can cascade into control of a whole digital life. For a business owner, whose number may guard business banking and email, the stakes are especially high.
The warning signs
Because a SIM swap happens at the carrier level, there are a few tell-tale signs worth knowing, and noticing them quickly matters.
The clearest sign is a sudden, unexplained loss of cell service on your phone, no signal, no ability to call or text, sometimes showing something like "SOS" or "no service," when nothing about your situation should cause that. That can mean your number was just moved to another device. Other signs include unexpected notifications from your carrier about account or SIM changes you did not make, being suddenly unable to log into accounts, or alerts about password resets or logins you did not initiate. If your phone abruptly goes dark on the network for no good reason, do not just assume it is a glitch. Treat it as a possible SIM swap and act quickly.
What to do if it happens
If you suspect your number has been hijacked, speed is everything, because the criminal is racing to use it. Contact your mobile carrier immediately, using another phone or another method since your own may be offline, to report the SIM swap and regain control of your number. Then move to protect the accounts that number guards: from a secure device, change the passwords on your most important accounts, starting with your email and your banking, and turn on stronger protections where you can. Contact your bank right away if financial accounts may be exposed, and watch closely for fraud or further account takeovers. As with most fraud, the faster you respond, the more damage you can prevent.
How to protect yourself before it happens
The reassuring part is that a few specific steps make SIM swapping far less likely to hurt you. These are worth doing now, especially for a business owner.
The most important change is to stop relying on text-message codes for your important accounts and use an authenticator app instead, wherever it is offered. An authenticator app generates login codes right on your device, and crucially, those codes are tied to the app, not to your phone number. That means even if a criminal steals your number through a SIM swap, they do not get your authenticator codes, because those never travel over the phone network. App-based verification, or a physical security key, sidesteps the entire SIM-swap problem. To be clear, text-message codes are still far better than no second factor at all, so do not turn off SMS protection if that is all an account offers, but move your most valuable accounts, email, banking, business systems, to an authenticator app where you can. This is the natural next step from simply turning on multi-factor authentication, choosing the stronger form of it.
Second, lock down your mobile carrier account itself. Most carriers let you add a PIN, passcode, or port-freeze that they must verify before making any changes to your SIM or transferring your number. Setting this up means a criminal cannot swap your SIM just by talking their way past a representative, because they would also need that secret. Call your carrier or check your account settings and turn this protection on. It is one of the single best defenses against a SIM swap.
Third, be mindful of the personal information criminals use to impersonate you, since much of it comes from data breaches and oversharing. You cannot control every leak, but limiting what you broadcast and protecting your key accounts reduces what an attacker has to work with. And finally, keep your email and important accounts protected with strong, unique passwords and app-based verification, so that even if your number is compromised, those accounts have more than the phone number standing guard.
How we think about it
SIM swapping is a great example of why the strength of your protections, not just their presence, matters, which is central to how we think about security at Red Door Shield, through a simple framework we call KIT: Keep, Inspect, Trust. Keep what is valuable secure, with the stronger, app-based verification and carrier protections that keep a stolen number from unlocking your accounts. Inspect what is happening, staying alert to the warning signs like sudden loss of service so a swap is caught fast. And trust through validation, recognizing that your phone number alone is not a trustworthy key, and backing your important accounts with something a SIM swap cannot steal. We help businesses move to the stronger protections that make attacks like this far less dangerous.
What ready looks like
Picture your important accounts protected by an authenticator app rather than text codes, your mobile account locked with a carrier PIN, and you alert to the warning signs. A criminal manages to steal your phone number through a SIM swap, and it gets them almost nothing, because your banking, email, and business accounts are guarded by codes that never went to your phone number in the first place, and your carrier would not have made the swap without a PIN they do not have. The attack that devastates the unprepared runs into a wall.
That is what ready feels like against SIM swapping. Not assuming your phone number is a safe key, but making sure that even if it is stolen, it does not open the doors that matter.
SIM swapping is unsettling precisely because it happens without touching your phone, turning your own number against you. But the defense is squarely in your hands: move your key accounts to an authenticator app, put a PIN on your carrier account, and watch for the warning signs. Those few steps take away most of the danger. If you want help moving your business to stronger protections that stand up to attacks like this, our free Business Security Assessment is the place to start, and it is a conversation worth having today.
Ready to see where your business stands?
Get your free Business Security Assessment today. No tricks, no jargon, no obligation, just a clear, honest look at your security and what to do next.
Get Your Free AssessmentNot sure where your business actually stands?
Take our free Business Security Assessment. In under 10 minutes, you will know exactly where your gaps are and what it would take to close them.
Get My Free Security Assessment

