SIM swapping weaponizes the fact that a phone number was never designed to be an identity credential — yet countless services use SMS for password resets and one-time codes. The attacker convinces your mobile carrier, through help-desk manipulation, impersonation using data gathered from breaches, or a bribed insider, to reassign your number to a SIM they control. From your side, the first sign is often that your phone abruptly loses all cellular service while the attacker begins receiving your texts and codes.
The con is essentially a carrier-authentication bypass. It differs from account takeover generally because it attacks the phone number as a recovery factor rather than the login directly — and it is frequently the enabling step for takeover. It also differs from ordinary help-desk fraud in its target: the victim of the social engineering is the carrier, not you.
SIM swapping skews toward high-value targets — people with significant crypto holdings, executives, valuable social handles — because the effort per target is higher, but the payoff can be catastrophic and, for crypto, irreversible. Its defining feature: control of your number quietly becomes control of everything that trusts your number to prove it’s you.