S.M.M.

Stop Manipulating Me · A Field Guide to Psychological Influence

ENTRY No. T24.11
CATEGORY Internet Scams
CLEARANCE Public / Essential
EDITION 01
Dossier · Manipulation Tactic

SIM Swapping

Access Fraud · Phone-Number Hijack · Common
Red Flag
How It WorksSEC 01

SIM swapping weaponizes the fact that a phone number was never designed to be an identity credential — yet countless services use SMS for password resets and one-time codes. The attacker convinces your mobile carrier, through help-desk manipulation, impersonation using data gathered from breaches, or a bribed insider, to reassign your number to a SIM they control. From your side, the first sign is often that your phone abruptly loses all cellular service while the attacker begins receiving your texts and codes.

The con is essentially a carrier-authentication bypass. It differs from account takeover generally because it attacks the phone number as a recovery factor rather than the login directly — and it is frequently the enabling step for takeover. It also differs from ordinary help-desk fraud in its target: the victim of the social engineering is the carrier, not you.

SIM swapping skews toward high-value targets — people with significant crypto holdings, executives, valuable social handles — because the effort per target is higher, but the payoff can be catastrophic and, for crypto, irreversible. Its defining feature: control of your number quietly becomes control of everything that trusts your number to prove it’s you.

Warning SignsSEC 02
  • Sudden loss of service. Your phone shows "no service" / SOS-only for no reason, while others' phones work in the same place.
  • Unexpected carrier messages. Notices about a SIM change, eSIM activation, or number-port request you didn't initiate.
  • A flurry of reset alerts. A wave of password-reset and login-alert emails arriving at once.
  • Account lockouts. Being suddenly unable to log in to your most valuable accounts.
  • Odd activity reported by contacts. People say your number "called or texted" them strangely.
Frequently Paired WithSEC 03
  • Account Takeover · T24.10
    A swap is a primary enabler of it
  • Help-Desk Manipulation · T14.19
    The carrier social-engineering route
  • Vishing · T14.8
    The voice channel used on agents
  • Phishing · T14.2
    Harvests the data used to impersonate you
How the Scam UnfoldsSEC 04
  • Stage 01 · Impersonation
    The attacker social-engineers your carrier (or bribes an insider) to move your number to a SIM they control.
  • Stage 02 · Cutover
    Your phone abruptly loses all service while your calls, texts, and one-time codes flow to the attacker.
  • Stage 03 · Drain
    They reset SMS-anchored logins and empty crypto, bank, and email accounts — for crypto, often irreversibly.
Counter-ProtocolSEC 05
Defense: Your number should not be able to reset your email, bank, or wallet.
  • Add a carrier account PIN and a port-freeze / number-lock, and enable change notifications — the single highest-leverage step.
  • Move high-value accounts off SMS onto passkeys, FIDO2 security keys, or at minimum an authenticator app.
  • Remove phone-number recovery where an app or key is available, and use unique passwords via a manager.
  • Treat sudden "no service" as an attack in progress. Call the carrier from another line, then protect email, bank, and crypto first.
  • Report to the carrier's fraud line, IC3, IdentityTheft.gov, and your bank and crypto institutions immediately.