Breaches & Passwords

How to Protect Yourself From SIM-Swap Attacks

By the RedactZero Team · July 25, 2026 · 9 min read

The short version

A SIM swap is when someone talks your mobile carrier into moving your phone number to a SIM they control, which hands them every text message code you receive. The three defenses that matter, in order: turn on your carrier's free account lock for SIM changes and number transfers, move your two-factor codes off SMS to an authenticator app or security key, and cut down what people-search sites publish about you, because your address history, birth date, and relatives are the answers an impersonator uses to pass a verification call.

What a SIM swap actually is

A SIM swap happens when someone convinces your mobile carrier to move your phone number onto a SIM card or eSIM profile they control. There is no malware and no stolen handset. Once the transfer goes through, your phone quietly drops off the network and their device starts receiving your calls and texts.

The FBI's Internet Crime Complaint Center describes three routes attackers take: impersonating the customer to a support agent, bribing a carrier employee, and phishing carrier staff to get inside their systems. Port-out fraud is the close cousin, where the attacker poses as you, opens an account at a different carrier, and has your number transferred over to it.

Either way, the prize is the same. Your number is the reset button for your email, your bank, and anything else that texts you a code.

Why your public data is what makes it work

Carrier verification usually comes down to questions only you should be able to answer. That assumption breaks when the answers are published for free. People-search sites list your full name, age, current and past addresses, phone numbers, and a tidy list of relatives, which turns a security question into a lookup.

Regulators have said as much in writing. The FCC's SIM swap rules explicitly bar wireless carriers from authenticating customers with "readily available biographical information, account information, recent payment information, or call detail information," precisely because that material is too easy for an impersonator to obtain.

This is the uncomfortable link between data brokers and phone fraud. The profile that makes you findable also makes you impersonable. If you want the longer version of why your family shows up alongside you on those pages, see our post on why relatives appear in people-search results.

How common is SIM swapping, really

Reported SIM-swap fraud is low in volume compared with phishing, but costly per victim, and the FBI's figures have been falling for three years. The Internet Crime Complaint Center logged 971 SIM-swap complaints in 2025 with roughly $17.4 million in reported losses, down from 1,075 complaints and $48.8 million in 2023.

YearSIM-swap complaintsReported lossesAverage per complaint
20231,075$48,798,103About $45,400
2024982$25,983,946About $26,500
2025971$17,366,758About $17,900

Source: FBI Internet Crime Complaint Center, 2025 IC3 Annual Report, three-year complaint and loss comparison tables. Averages are calculated from those figures.

Read those numbers carefully. They only count complaints filed with IC3, so the real total is higher, and a falling trend is not the same as a solved problem. What the table does show is scale: a single successful swap has historically cost the victim tens of thousands of dollars.

The warning signs

The first symptom is usually silence. Your phone shows no service or SOS while other phones around you have full bars, and calls and texts stop arriving even though nothing about your device changed. The second is a notification you did not ask for, telling you a SIM change or number transfer was requested.

Treat any of these as a possible swap in progress:

Carriers are required to notify you immediately when a SIM change or port-out is requested, so an unexpected notice of that kind is a real signal, not spam. Do not ignore it and do not click links inside it. Go to the carrier yourself.

What to do in the first hour

Speed matters because the attacker is racing your one-time codes. Work from a second device such as a laptop, a tablet, or a family member's phone. Reverse the transfer first, then close off the accounts a code could open, then create a record. Order matters more than doing every step perfectly.

  1. Call your carrier's fraud line from another phone. Say the words "unauthorized SIM change" or "unauthorized port-out." Ask them to reverse the transfer, restore the number to your device, and lock the account against further changes.
  2. Change your primary email password and sign out of all active sessions. Email is the master key to everything else.
  3. Contact your bank, brokerage, and any crypto exchange directly, using the number on your card or statement. Ask them to flag the account and block transfers pending verification.
  4. Swap SMS codes for an authenticator app on your most important accounts before you do anything else with them.
  5. Write down times and details while they are fresh, then file a report at ic3.gov, which is the FBI's own reporting channel for this crime.

Once the immediate fire is out, work through the broader recovery checklist in what to do right after a data breach, since a swap is usually followed by attempts on your other accounts.

Turn on your carrier's free account lock

This is the single highest-value step, and most people have never heard of it. A carrier-level lock blocks SIM changes and number transfers until you deliberately turn it off, so a support agent cannot be talked into moving your number. Under the FCC's rules, providers must offer this to every customer, prepaid and postpaid, at no cost.

CarrierFree featureWhat it blocksWhere to turn it on
AT&TWireless Account LockSpecific transactions and account changes across every device and line on the wireless accountThe AT&T app, under the profile icon
T-MobileSIM Protection and Port Out ProtectionSIM Protection blocks moving your number to another device; Port Out Protection blocks transfers to another carrierT-Life or T-Mobile.com, added per line
VerizonNumber Lock and SIM ProtectionNumber Lock blocks moves to another line or carrier; SIM Protection blocks SIM and device changesThe Security page in My Verizon, or dial *611

Source: each carrier's own support pages, checked July 25, 2026. Feature names and menu locations change, so confirm with your carrier.

Two details worth knowing. Verizon's own guidance notes that Number Lock does not prevent SIM or equipment changes, so turn on both features rather than one. And Verizon says disabling SIM Protection starts a short waiting period, about 15 minutes, before changes can process, which is a deliberate speed bump against a rushed attacker.

On a smaller carrier or an MVNO, do not guess. Call support and ask by name whether they offer an account lock, SIM change protection, port-out protection, or a separate number transfer PIN. If the first agent does not know, ask for someone who does.

Move your two-factor codes off SMS

A SIM swap only pays off because so many accounts still text their security codes. Moving those codes to an authenticator app or a hardware security key takes your phone number out of the equation entirely, so an attacker who controls the number gains nothing on those accounts. The FBI recommends exactly this.

Work in priority order rather than trying to convert everything at once:

Where a site refuses to drop SMS entirely, at least remove your phone number as an account recovery method, and save the printed backup codes somewhere offline. A hardware security key is the strongest option available to consumers, but a free authenticator app already closes the specific hole a SIM swap opens.

Take your number and address off people-search sites

Reducing what brokers publish attacks the problem at its source. It shrinks the pool of correct answers an impersonator can offer a support agent. The FBI's guidance on SIM swapping tells consumers plainly to limit the personal information they share online, and it names phone numbers and addresses specifically.

Every major US people-search site has a free opt-out. The usual flow is to find your listing, submit its URL on the site's removal form, and confirm through an emailed link, which takes five to ten minutes per site. We publish dated, step-by-step opt-out guides for 57 major brokers, including the high-traffic ones like Whitepages and TruePeopleSearch.

Expect maintenance rather than a one-time fix. Brokers continually re-ingest public records and buy data from each other, so listings commonly reappear within three to six months. California residents have a shortcut: the state's free DROP platform sends one deletion request to every registered broker at once. If you want a starting map of where you are exposed, RedactZero's free exposure scan lists the brokers likely to carry a US adult and stores nothing you type.

Harden what a stolen number could reach

Assume for a moment that a swap succeeds anyway. The damage depends entirely on how much your phone number unlocks, and that is something you control. Spend twenty minutes auditing the accounts where your number is still a recovery method, a login, or a way to authorize a transfer.

Useful moves: set a spoken password or verbal PIN on your bank account so a phone call alone cannot move money; turn on withdrawal address whitelists and withdrawal holds at any crypto exchange; enable transaction alerts by email rather than text; and check the recovery settings on your email account, since a stale forwarding rule or recovery number is a quiet back door.

One behavioral note from the FBI's guidance is worth repeating: avoid discussing financial assets, and especially cryptocurrency holdings, on social media. Public bragging is how targets get selected in the first place. Trimming your general online trail helps too, and our guide to reducing your digital footprint covers that in a weekend.

What the FCC actually requires of carriers

On November 15, 2023 the FCC adopted a Report and Order aimed squarely at this crime. It requires wireless providers to use secure authentication before redirecting a number to a new device or provider, to notify customers immediately whenever a SIM change or port-out is requested, and to offer free account locks against both.

The order also bars carriers from authenticating on readily available biographical or account information alone, requires them to keep records of SIM change requests and authentication failures, and tells them to publish notice of the protections they offer where customers can find it.

The timing is messier than the substance. The original compliance date of July 8, 2024 was pushed back by the FCC's own Wireline Competition Bureau in July 2024, which synchronized all of the rules to the completion of federal paperwork review, and industry filed a petition asking for more time. If the exact deadline matters to you, check the FCC's compliance-date notice for this docket rather than trusting a summary. The practical point stands either way: all three national carriers publish a free lock today, so turn yours on.

What a lock does not do

A carrier lock stops the ordinary version of this attack, where someone calls in and talks their way past an agent. It does not stop everything, and it is not a reason to skip the other two defenses.

What it will not cover: a bribed or compromised carrier employee working inside the system, an attacker who already has your email password and does not need your phone at all, or an account you left on SMS codes with your number as the recovery method. Locks also apply per line or per account, so on a family plan every line needs its own protection.

There is also a small friction cost. You must turn the lock off before a legitimate upgrade, a new eSIM, or a real switch to another carrier, and some carriers only let the primary account holder do that. That is the feature working as intended.

See what a scammer could look up about you

Run a free exposure scan to see which data brokers likely list your name, address, and phone, plus any breaches tied to your email. No account, nothing stored.

Run a free exposure scan

Frequently asked questions

What is a SIM-swap attack?

A SIM swap is when someone convinces your mobile carrier to move your phone number onto a SIM card or eSIM profile they control. Your phone loses service and their device starts receiving your calls and texts, including one-time security codes.

How do I know if I have been SIM swapped?

The usual first sign is your phone showing no service or SOS while other phones nearby work normally. The second is a message you did not ask for saying a SIM change or number transfer was requested. Unrequested password-reset emails are another warning.

What should I do first if my number was stolen?

Use another device to call your carrier's fraud line and ask them to reverse the transfer and lock the account. Then change your email password and sign out all sessions, then contact your bank. Report it to the FBI at ic3.gov.

Do all US carriers offer a free SIM or port-out lock?

The FCC's 2023 order requires wireless providers to offer all customers, prepaid and postpaid, the option to lock their account against SIM changes and port-outs at no cost. AT&T, T-Mobile and Verizon each publish a free lock. Smaller carriers vary, so ask yours by name.

Does an authenticator app stop a SIM swap?

It does not stop the swap itself, but it removes the payoff. Codes from an authenticator app or a hardware security key are generated on your device, so an attacker holding your phone number cannot receive them. The FBI recommends authentication apps and security tokens over texted codes.

Can removing myself from people-search sites prevent a SIM swap?

It removes the raw material rather than the crime. Impersonators need your address history, date of birth, and relatives to sound convincing to a support agent, and people-search sites publish exactly that for free. Fewer public answers means fewer ways to pass a verification call.

Is a port-out PIN the same as my account PIN?

Often not. Some carriers issue a separate number transfer PIN used only to authorize moving your number to another provider. Verizon, for example, has customers generate a Number Transfer PIN in My Verizon. Ask your carrier which PIN protects transfers and set it to something unique.

Are eSIMs safer than physical SIM cards?

Not by themselves. The fraud happens in the carrier's account system, not on the plastic, so a number can be moved to an attacker's eSIM profile just as easily. What helps is the carrier lock, which applies to eSIM profile changes as well as physical SIM swaps.

Sources: FCC Report and Order FCC 23-95, Protecting Consumers from SIM Swap and Port-Out Fraud (WC Docket 21-341), and Wireline Competition Bureau order DA 24-649 on compliance timing; FBI Internet Crime Complaint Center, 2025 IC3 Annual Report and its February 2022 public service announcement on SIM swapping; the official AT&T, T-Mobile, and Verizon support pages for their account lock features, checked July 25, 2026.