SIM Swapping Explained: What to Do When Your Number Is Stolen
If your phone has suddenly lost service — no bars, "No Service" or SOS mode, while other phones in the same room work normally — treat it as a SIM swap until proven otherwise, and move in this order. Call your mobile carrier from a different line, tell them you believe your number has been transferred without authorization, and ask them to restore it and place a port-out lock on the account. Then, from a device you trust, change the password on your primary email account and sign out of all its sessions. Then contact your bank and any brokerage or cryptocurrency platform and ask them to freeze transfers pending verification. The window that matters is measured in minutes, not days: the number is stolen precisely because it is the key to everything else, and the attacker knows the clock is running too.
That is the emergency procedure. The rest of this explains why a phone number became the weakest link in a wealthy household's security, and what to change so that losing one stops being a catastrophe.
What a SIM swap actually is
Your mobile number is not stored in your phone. It is an entry in your carrier's records that points to a particular SIM — and that entry can be repointed. There are legitimate reasons for this: people lose phones, upgrade devices and change carriers, and the industry is built to make moving a number easy.
A SIM swap is that ordinary process, invoked by someone who is not you. The attacker persuades the carrier that they are the account holder and that the number should be moved to a SIM in their possession. Sometimes the persuasion is documentary, assembled from personal details that are easier to obtain than most people assume. Sometimes it is simpler than that: retail and call-centre staff have been bribed or recruited, and insider-assisted swaps are a well-documented part of the problem rather than a theoretical one.
The moment it completes, two things happen at once. Your phone loses service, because a number can only live on one SIM. And every message sent to that number — including the six-digit codes that guard your email, your bank and your exchange accounts — arrives on a stranger's handset.
Why wealth changes the arithmetic
SIM swapping is not indiscriminate. It requires effort per target: research, a pretext, sometimes a corrupted insider. That cost only makes sense against accounts worth taking, which is precisely why the technique concentrates on people with significant liquid assets, cryptocurrency holdings, or a public profile that makes both easy to infer.
The research is rarely difficult. A prominent person's mobile number circulates further than they realize — through business filings, school and club directories, charity registrations, household staff, past assistants, and the data brokers that aggregate all of it into a purchasable profile. The details commonly used to verify identity with a carrier are, for a public figure, frequently a matter of record.
The result is an asymmetry worth stating plainly: the security of a great deal of money can rest on a customer-service interaction at a mobile phone shop, conducted by someone who has never met you, against a person who has studied you.
The signs, including the quiet ones
The obvious sign is the abrupt loss of service, and it is often the only one you get. But it frequently arrives at an inconvenient hour by design — a Friday evening or during travel, when a carrier store is closed and a lost signal is easy to blame on the network.
Quieter precursors are worth knowing. A message from your carrier confirming a change you did not request, or thanking you for an upgrade you did not order, deserves a phone call rather than a shrug. So does a sudden burst of password-reset emails, which often precedes a swap while the attacker maps which accounts are attached to the number. And an unexpected request from your carrier to confirm a PIN or account detail — particularly one that arrives by email or text rather than through the app — is worth treating as hostile until you have verified it through a channel you initiated.
The first hour, in order
Restore the number first. Nothing else can be secured while an attacker is receiving your verification codes, and every reset you attempt in the meantime hands them another opportunity. Call from another line, state clearly that this is an unauthorized transfer, and ask both for restoration and for a port-out lock so it cannot immediately recur.
Take the email next. The mailbox is the recovery point for nearly everything else, so it is the intruder's first stop and must be your second. New password, all sessions signed out, and a careful check for forwarding rules and newly added recovery addresses — the artifacts an intruder leaves so that they keep access after you have changed the password.
Then the money. Call your bank, your brokerage and any exchange on a number you look up independently rather than one supplied to you, and ask for outbound transfers to be held pending verification. Wire and crypto transfers are the two categories where minutes genuinely decide recoverability, and a hold placed early is far easier than a reversal attempted late.
Finally, preserve the record while you go: the time service dropped, the carrier's confirmation messages, the reset emails, any transfers you did not authorize. If a claim follows — and with financial losses one usually does — that record is what the claim rests on.
Making the number stop mattering
The durable fix is not a better password. It is arranging your accounts so that possession of your phone number is no longer possession of your identity.
Start at the carrier. Every major provider offers some form of number lock, port freeze or transfer PIN, and these are the highest-value fifteen minutes available in personal security. They are usually not enabled by default, and they should be set on every line in the household, not only the principal's.
Then move your second factor. SMS codes are better than nothing and worse than everything else; an authentication app breaks the link to the number entirely, and a hardware security key breaks the link to the phone as well. For the accounts that actually matter — primary email, banking, brokerage, exchange, password manager — a hardware key is the control that makes this class of attack fail outright rather than fail slowly.
Then untangle the number from your recovery paths. Many people have long since moved to app-based authentication while leaving their phone number sitting in the account as a fallback recovery method, which preserves exactly the weakness they thought they had removed. Removing the number, or replacing it with a separate line used for nothing else and published nowhere, closes that door.
Finally, reduce what can be learned about you. Data-broker removal is tedious and imperfect, but the verification details used against carriers come from somewhere, and shrinking that supply measurably raises the cost of targeting you.
The household is the perimeter
A number takeover in a wealthy household does not have to target the principal to be effective. A spouse's number may sit on shared financial accounts. An adult child's phone may hold family photographs, travel plans and enough correspondence to make a convincing impersonation. An assistant's line frequently receives the codes for calendars, travel bookings and, in some households, payment approvals.
Any of these is a viable route to the same outcome, and each tends to be secured to a lower standard than the principal's own devices. Locks and hardware keys are worth extending to everyone whose phone touches the family's money, calendar or correspondence — including household staff, whose devices are almost never in scope for anyone.
SIM swapping is one of the few serious attacks with a genuinely reliable defense. It is not clever software; it is a lock at the carrier, a hardware key on the accounts that matter, and a phone number that no longer unlocks anything. Set those, and an attacker who successfully steals your number finds they have stolen a telephone.
If your number has been taken over now, say so when you write — active incidents are prioritized. Account takeover recovery covers SIM-swap attacks end to end, from carrier restoration through to the account hardening that prevents recurrence, and a personal cybersecurity assessment is the usual way to find the rest of the chain before anyone tests it.
When you’re ready, the conversation is confidential.
Request a Confidential Consultation