← Privacy Guides

Accounts & identity

Defend against SIM swaps and number theft

Stop someone from moving your phone number to their SIM, and make sure that even if they do, it does not unlock your accounts.

  • Low threat
  • Time 45 minutes
  • Difficulty Easy
  • Last verified

What this protects, and what it doesn't

Protects

  • Against an attacker who talks your mobile carrier into moving your number to a SIM or eSIM they control.
  • Against port-out fraud, where your number is moved to an account at another carrier.
  • Against account takeovers that rely on one-time codes sent to your number by text message or voice call.

Does not protect

  • It cannot stop a carrier employee who ignores the protections on your account. It makes the attack harder and lets you notice it sooner.
  • It does not protect accounts that still let anyone reset the password with an SMS code. You have to change those one by one.
  • It does not protect against malware on your phone or phishing that captures codes directly from you.

Prerequisites

  • Access to your mobile carrier account (app, website or a store visit with ID).
  • A list of your important accounts: email, bank, cloud storage, password manager, messaging.
  • Optional: an authenticator app or a hardware security key.

Step by step

  1. Understand how the attack works

    A SIM swap is a normal procedure: you ask your carrier to move your number to a new SIM card or eSIM, for example when you change phones. In a fraudulent SIM swap, someone convinces your carrier to move your number to a SIM they control. In port-out fraud, they open an account with a different carrier while pretending to be you and move your number there.

    Attackers usually collect your personal details first, through phishing, data breaches or your public social media, so they can answer the carrier's identity questions. Once the number is theirs, your SIM loses its connection to the network and they receive your calls and text messages, including the one-time codes that banks and websites send to log in or reset a password.

  2. Set a PIN or password on your carrier account

    Ask your carrier to add a PIN, passcode or password to your account, so that nobody can change your SIM or move your number without it. The FTC recommends this and tells you to check your carrier's website for how to do it. The setting has a different name at every carrier (account PIN, port-out PIN, number transfer PIN, port protection). Look for it in your carrier's app or account settings, or ask in a store.

    • Use a PIN that is not your birthday, address or the last digits of your phone number. Store it in your password manager.
    • Do not reuse the PIN you use for your phone's lock screen or your bank card.
    • Ask whether your carrier also offers a lock that blocks all SIM changes and number transfers until you remove it yourself. Turn it on if it does.

    In the United States, the FCC adopted rules in November 2023 that require carriers to use secure methods to authenticate a customer before a SIM change or port-out, and to notify customers immediately when such a request is made on their account. The same rules require carriers to offer every customer, at no cost, the option to lock or freeze the account to stop SIM changes and port-outs. Compliance was set at six months after the rules took effect, or later for the parts that needed review by the Office of Management and Budget, so ask your carrier what it offers today.

  3. Move two-factor authentication off SMS

    This is the step that matters most. If your accounts do not trust your phone number, a stolen number is worth much less to an attacker. Codes sent by text message can be intercepted, so the FTC recommends an authentication app or a security key for sensitive accounts. ENISA also advises against tying your phone number to sensitive online accounts and choosing other authentication methods when they are available. CISA notes that FIDO/WebAuthn, which passkeys and security keys use, is the only widely available phishing-resistant authentication.

    1. Start with your main email account, because it can reset most other passwords. Then do your password manager, bank, cloud storage and social media.
    2. Add a passkey, a hardware security key or an authenticator app. See Passkeys and hardware security keys.
    3. Then remove SMS as a sign-in and recovery option where the service allows it. If you only add a stronger method and leave SMS on, the attacker can still choose SMS.
    4. Save each account's backup codes in your password manager or on paper in a safe place.
  4. Turn on Signal Registration Lock

    Signal accounts are registered with a phone number and an SMS or voice code. With Registration Lock on, anyone who registers your number on a new phone also needs your Signal PIN, so a stolen number alone is not enough. Set it up with Harden Signal.

    Check the other messaging apps you use for a similar setting, often called a PIN or two-step verification.

  5. Use a separate number for account recovery

    Your everyday number is easy to find: you give it to shops, contacts and websites, and it may already be in a data breach. For the few accounts that still require a phone number, consider a second number that you use only for account recovery and never share.

    • Keep it with a carrier account that has its own PIN and lock, as in the step above.
    • Keep it active. Disconnected numbers are given to new customers (the FCC says millions of US phone numbers are reassigned each year), and the next owner would receive your recovery codes.
    • A separate number lowers the risk; it does not remove it. Prefer accounts that let you recover without any phone number.
  6. Limit what an attacker can learn about you

    Carriers check your identity with personal details, so the less of them is public, the harder it is to impersonate you. ENISA advises limiting the personal information you expose on social media, and the FTC warns not to answer unsolicited calls, emails or texts that ask for personal information.

    • Remove your phone number, date of birth and address from public profiles.
    • If someone calls "from your carrier" or "from your bank", hang up and call the number on the company's website or your bill.
    • To reduce what data brokers sell about you, see Remove yourself from data brokers.
  7. Know the signs and what to do

    The most common sign is that your phone suddenly loses service: no calls, no text messages and no mobile data, even though you are somewhere with normal coverage. Other signs are a message from your carrier that your SIM was activated on a new device, a port-out or SIM change notice you did not request, or sudden password-reset emails.

    If it happens, act fast:

    1. Contact your carrier right away from another phone or in a store, and get your number back.
    2. Once you have it back, change the passwords of your important accounts, starting with email, and sign out other sessions.
    3. Check your bank, card and other financial accounts for charges or changes you did not make, and report any to the institution.
    4. Report the crime to the police. In the United States, the FTC sends people whose personal or financial data was misused to IdentityTheft.gov.

Common mistakes

  • Adding an authenticator app but leaving SMS on as a backup. The attacker will pick the weakest option.
  • Using a carrier PIN that is easy to guess from public details, such as a birth year or the end of the phone number.
  • Assuming the problem is a network outage when the phone loses service, and waiting hours before calling the carrier.
  • Giving codes or personal details to someone who calls claiming to be from your carrier or bank.
  • Letting a recovery-only number expire, so the carrier gives it to someone else.

Going further

Review your accounts once a year: which still accept SMS codes, which have passkeys, where your backup codes are. If you are a likely target (public profile, cryptocurrency holdings, an executive role), ask your carrier which extra protections it has for high-risk customers, and read ENISA's report on countering SIM swapping for how carriers handle these requests.