# What is SIM Swapping?

> SIM swapping is the fraudulent transfer of a victim’s phone number to an attacker-controlled SIM card, handing the attacker the victim’s calls and text messages — including one-time codes and account-recovery links.

- Canonical URL: https://yellowcube.eu/glossary/sim-swapping/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

The attacker convinces a carrier to port or reissue the number using stolen personal information, insider access, or social engineering. Once the number moves, every SMS- and call-based factor routes to the attacker: password resets, MFA codes, bank confirmations. The victim typically learns of it by losing service or as accounts are compromised in sequence.

The attack specifically weaponizes SMS as an authentication channel. Defenses operate on both sides: carriers add port-out verification and account PINs, while services reduce reliance on SMS — preferring authenticator apps, passkeys, and recovery paths that do not collapse when a phone number changes hands.

### Key points

- **Attack path:** Personal data from breaches or social media, carrier social engineering or bribery, fraudulent port-out or eSIM activation, then SMS-intercepted resets and codes.
- **User defenses:** Carrier account PINs and port locks, authenticator-based MFA instead of SMS where offered, alerting on unexpected loss of service, and prompt contact with the carrier on suspicion.
- **Organizational controls:** Do not let SMS recovery override stronger authentication for high-value accounts, flag recovery events after number changes, and treat SIM-swap reports as account-takeover incidents.
- **Important limitation:** Protecting the carrier account does not help if an employee or retail channel can be manipulated. Conversely, SMS factors are the weakness — removing them from the recovery path reduces what a successful swap yields.

### Related terms

[Account takeover (ATO)](<https://yellowcube.eu/glossary/account-takeover/>) · [Multi-factor authentication (MFA)](<https://yellowcube.eu/glossary/multi-factor-authentication/>) · [Account recovery](<https://yellowcube.eu/glossary/account-recovery/>) · [Smishing](<https://yellowcube.eu/glossary/smishing/>) · [Social engineering](<https://yellowcube.eu/glossary/social-engineering/>)

### Sources

[FBI IC3 PSA 2022-02-08: Criminals Increasing SIM Swap Schemes](https://www.ic3.gov/PSA/2022/PSA220208) · [FBI IC3 PSA 2024-04-11: Cyber Criminals Target Victims Using Social Engineering Techniques](https://www.ic3.gov/PSA/2024/PSA240411)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

