Hijacking a victim’s mobile number to bypass authentication and take control of online accounts

Introduction
Our mobile phone number has become an important part of modern digital security. Our mobile number is tied to many security-related activities.
It is commonly used to:
- Receive SMS authentication codes
- Recover forgotten passwords
- Verify account ownership
- Receive security alerts
- Authenticate online banking transactions
- Register accounts and services
This makes a mobile phone number a very attractive target for attackers.
SIM swapping is an attack in which an attacker convinces a mobile network provider to transfer a victim’s phone number to a SIM card controlled by the attacker.
Once the transfer is successful, the victim’s phone stops receiving calls and text messages, while the attacker begins receiving them instead.
The attacker has effectively hijacked the victim’s telephone number.
What is a SIM?
A SIM (Subscriber Identity Module) is used by a mobile network to identify and authenticate a subscriber. Traditionally, this was provided by a physical SIM card inserted into a mobile phone.
Modern devices can also use an eSIM, which provides the same basic function electronically rather than through a removable physical card.
The SIM allows the mobile network to associate a device with a subscriber’s mobile number and services. This effectively means that control over the SIM can effectively mean control over the associated telephone number.
What is SIM swapping?
SIM swapping, sometimes called SIM hijacking or SIM port-out fraud, occurs when an attacker persuades a mobile provider to move a victim’s telephone number onto a SIM controlled by the attacker.
If successful, the victim may suddenly lose their mobile service.
The attacker meanwhile, receives:
- Phone calls
- SMS messages
- Authentication codes
- Password-reset messages
- Other communications associated with the number
How does SIM swapping work?
SIM-swapping attacks often involve social engineering rather than exploiting the SIM card itself.
The attacker first gathers information about the victim from places such as:
- Social media
- Previous data breaches
- Public records
- Phishing
- Previous compromises
- Information shared online
The attacker then contacts the victims mobile provider while pretending to be the legitimate account holder. They may claim that:
- Their phone has been lost
- Their SIM card has stopped working
- They have purchased a new phone
- They need to activate a replacement SIM
The attacker attempts to convince the provider to transfer the number to their SIM.
If successful, the number moves from the victim’s device to the attacker’s device.
There have even been cases where organised gangs have placed insiders into mobile phone company call centres to carry out these attacks with ease.
Account takeover
SIM swapping is particularly dangerous when the attacker already knows, or can obtain, the victim’s username and password. If this is the case, then the attacker may then attempt to take over:
- Email accounts
- Banking accounts
- Cryptocurrency accounts
- Social media accounts
- Cloud services
- Business accounts
The telephone number just becomes another component of the attack.
Password reset attacks
SIM swapping can also be used against password-recovery systems.
Many service offer a “forgot Password” option to help reset account details.
If used, the service sends a reset code to the registered telephone number.
However, if the attacker controls that number, they will now receive the reset code and as such be able to effectively lock the legitimate user out of their accounts
This is why recovery mechanisms are just as important as the primary authentication system.
Cryptocurrency targets
Cryptocurrency accounts can be particularly attractive targets because successful account compromise may provide access to valuable assets. An attacker might attempt to use a stolen telephone number to:
- Reset account credentials
- Defeat SMS-based authentication
- Access an exchange account
- Change account settings
- Initiate withdrawals
However, modern cryptocurrency services may use additional authentication and withdrawal controls that can limit the impact of a successful SIM swap.
Signs of a SIM swap
One of the most important warning signs of a SIM swap attack is the sudden loss of mobile service.
For example, the victim may suddenly see:
- No network connection
- No ability to make calls
- No ability to send SMS messages
- “Emergency calls only”
- Unexpected SIM activation notifications
At the same time, the victim may receive alerts from online services via email indicating that:
- A password was changed
- A login occurred
- Authentication settings changed
- A recovery method was modified
A sudden loss of mobile service combined with unexpected account activity should be treated as a potential security incident.
How you can protect against SIM swapping
Organisations and individuals alike are common targets for SIM swap attacks, so you should avoid relying on telephone numbers as the only authentication mechanism.
Instead, stronger authentication methods should be used wherever possible.
- Use Phishing-Resistant MFA – Authentication methods such as FIDO2 security keys (Yubikeys are one example) and passkeys provide significantly stronger protection than SMS-based authentication. These do not depend on control of the victim’s telephone number.
- Avoid SMS as the Primary MFA Method – SMS-based authentication is better than having no additional authentication, but it has weaknesses. Where possible, switch to either hardware security keys, passkeys, authenticator applications, and strong device-based authentication.
SMS should not be considered the strongest available form of MFA. - Protect Mobile Provider Accounts – Users should establish strong security controls with their mobile provider where available. These may include setting account PINs, additional identity verification, enabling port-out protection, SIM-swap protection, and other account security notifications.
he exact controls available will depend on the mobile provider. - Protect Personal Information – Attackers may use publicly available information to make social-engineering attacks more convincing. Users should therefore be careful about publicly exposing information such as full date of birth, address, telephone numbers, other account information, and other personal identifiers.
Information that appears harmless individually can become useful when combined with information obtained elsewhere. - Monitor Account Activity – You should monitor accounts for unusual authentication activity such as unexpected password resets, new MFA registrations, changes to recovery information, new device registrations, Logins from unusual geographic logins, and multiple failed authentication attempts
Remember that a SIM swap attack may be only one component of a larger account-takeover campaign.
What should you do if you suspect a SIM swap?
If you suddenly loses mobile service and suspect your number has been transferred, you should contact your mobile provider using another telephone as quickly as possible.
You should also:
- Secure important online accounts.
- Change all passwords.
- Remove unauthorised authentication methods.
- Check account recovery settings.
- Review recent account activity.
- Contact financial institutions if financial accounts may be affected.
Speed is important because the attacker may attempt to exploit the newly acquired number immediately.
Conclusion
SIM swapping is a powerful example of how social engineering, telecommunications and account security can intersect.
The attacker does not necessarily need to compromise the victim’s phone – Instead, they attempt to convince the mobile provider to transfer the victim’s telephone number to a SIM controlled by the attacker.
Once successful, the attacker may receive calls and SMS messages intended for the victim and potentially use them to bypass SMS-based authentication or password-recovery mechanisms.
The most effective defence is to avoid treating a telephone number as a strong proof of identity.
You should use phishing-resistant MFA, passkeys, hardware security keys and strong account-recovery controls wherever possible.
The key lesson is simple:
If your security depends on control of a telephone number, an attacker who can steal that number may be able to steal your account too.