The attacker convinces a carrier to port or reissue the number using stolen personal information, insider access, or social engineering. Once the number moves, every SMS- and call-based factor routes to the attacker: password resets, MFA codes, bank confirmations. The victim typically learns of it by losing service or as accounts are compromised in sequence.
The attack specifically weaponizes SMS as an authentication channel. Defenses operate on both sides: carriers add port-out verification and account PINs, while services reduce reliance on SMS — preferring authenticator apps, passkeys, and recovery paths that do not collapse when a phone number changes hands.
Key points
Attack pathPersonal data from breaches or social media, carrier social engineering or bribery, fraudulent port-out or eSIM activation, then SMS-intercepted resets and codes.
User defensesCarrier account PINs and port locks, authenticator-based MFA instead of SMS where offered, alerting on unexpected loss of service, and prompt contact with the carrier on suspicion.
Organizational controlsDo not let SMS recovery override stronger authentication for high-value accounts, flag recovery events after number changes, and treat SIM-swap reports as account-takeover incidents.
Important limitationProtecting the carrier account does not help if an employee or retail channel can be manipulated. Conversely, SMS factors are the weakness — removing them from the recovery path reduces what a successful swap yields.