SIM-swap protection is not a setting on the SIM card. It is a chain of controls across the mobile carrier, primary email account, financial accounts and recovery methods. A criminal who persuades a carrier to move your number to another SIM or port it to another provider can receive calls and text messages intended for you. If important accounts use SMS for password resets or multi-factor authentication, control of the number can become control of the digital identity.
No single carrier PIN or authenticator app makes the risk disappear. The practical goal is to make an unauthorised transfer harder, make the phone number less valuable as an authenticator, detect loss of service quickly and have a recovery route that does not depend on the compromised number.
Quick answer:** Put a unique PIN or password and any available port-out or number lock on the carrier account. Move primary email, banking and cloud recovery away from SMS where stronger options exist. Store carrier and financial emergency contacts offline. If service suddenly dies, contact the carrier from another channel first, then protect email, money and identity in that order.
What a SIM swap and port-out attack actually changes
The FCC distinguishes two related attacks. In SIM swapping, the attacker causes the victim’s service to be associated with a SIM or device controlled by the attacker. In port-out fraud, the attacker opens an account at another carrier and transfers the victim’s number to it. In both cases the number moves; the original phone may show no service or emergency calls only.
The number is valuable because many services still send login codes and password-reset messages by SMS. The attacker may already know a password from phishing, a reused credential or a breach. The number becomes the second step needed to enter an account or reset it. That is why changing the mobile device alone does not solve the problem.
The current NIST digital-identity guidance treats use of the public telephone network for out-of-band authentication as a restricted authenticator. CISA’s mobile communications guidance tells highly targeted users to migrate away from SMS-based MFA and prefer FIDO-based authentication where feasible. This does not mean an SMS code is worse than no second factor in every consumer situation; it means valuable accounts should offer and use stronger choices.
The SIM-swap defence ladder
Apply the controls from the bottom up. Higher layers remain valuable even if a lower layer fails.
| Layer | Control | What it reduces | Residual weakness |
|---|---|---|---|
| Carrier identity | Unique account password and non-obvious account PIN | Casual social engineering and reused-credential access | Insider error or weak carrier process may remain |
| Number movement | Port-out lock, number lock or transfer freeze where offered | Unauthorised movement to another SIM or carrier | Availability and naming vary by provider |
| Alerts | Notifications for SIM changes, ports and account-profile edits | Time to detect a change | Alert may be sent to the affected number only |
| Authentication | Passkey, FIDO security key or authenticator app instead of SMS | Value of intercepting text codes | Recovery settings may still fall back to SMS |
| Recovery | Offline recovery codes and a second trusted channel | Dependence on the lost number | Codes must be stored securely and kept current |
| Financial control | Transaction alerts, transfer limits and bank voice passphrase where supported | Speed and size of financial loss | Bank procedures vary |
| Organisational control | Separation between public contact number and privileged recovery number | Exposure of the number used for sensitive accounts | Requires disciplined records and device management |
Prepare the carrier account first
Sign in using the carrier’s official app or website, not a link in an unexpected message. Set a password used nowhere else. Create the strongest account PIN the provider permits; avoid birthdays, postcodes and repeated digits. Ask what the carrier calls its number-transfer control. Terms include port freeze, number lock, transfer lock and port-out protection. Confirm whether it blocks both a move to another device and a port to another provider, because those can be separate actions.
Ask how the lock is removed. A control that can be disabled with the same weak security questions is less valuable than one requiring a separate PIN, in-store identification or another verified channel. Record the carrier’s fraud number, international support number and account identifier offline. A traveller whose only copy is inside an online account may be unable to retrieve it when the number and email are under attack.
Do not publish the private number used for high-value recovery. Executives, family offices and founders often need a public number for availability. That number does not have to be the recovery key for email, financial systems and domain registration.
Remove SMS from the accounts that can reset everything else
Start with primary email. Email can reset dozens of other services, so it deserves the strongest available authentication and independent recovery. Add a passkey or FIDO security key when supported. An authenticator app is a meaningful improvement over SMS for SIM-swap risk, although it remains vulnerable to phishing if a user enters a live code into a fraudulent site.
Then secure:
password manager;
Apple, Google or Microsoft identity account;
banking, brokerage and payment accounts;
cloud storage and work collaboration systems;
domain registrar and social-media accounts;
cryptocurrency accounts and wallets that use centralised recovery;
airline, hotel and loyalty accounts that store value or identity data.
For each account, inspect the recovery path after adding stronger MFA. Some services keep SMS enabled as a fallback. CISA specifically warns that enrolling an authenticator does not always remove SMS. Delete the weaker recovery method where the service permits it, or reduce what the account can do if SMS remains mandatory.
VERTU’s passkey, authenticator app and hardware security key guide explains the differences between these methods. The secure mobile phone guide covers device selection, but a secure handset cannot compensate for a carrier account that will release the number to an attacker.
Warning signs that require immediate action
Loss of service has ordinary causes: an outage, damaged SIM, billing problem, roaming error or device fault. Treat it as a possible account takeover when it is sudden, unexplained and accompanied by one or more of these signs:
an unexpected carrier message about a SIM activation, eSIM or port request;
password-reset emails you did not initiate;
financial or email login alerts from unfamiliar devices;
a carrier-account profile change;
calls reaching another person or going directly to an unfamiliar voicemail;
the phone showing emergency calls only while nearby users on the same network have service.
Do not spend the first hour repeatedly restarting the phone. One restart and a basic outage check are reasonable. If the evidence points to a number transfer, start the incident plan.
The first 30 minutes after suspected SIM swapping
The sequence matters because email and money can be attacked while the victim negotiates with the carrier.
Minute 0–5: establish an independent channel
Use another phone, a trusted secure internet connection or an in-person carrier location. Call the carrier’s known fraud number, not a number from a text message. State clearly that you suspect an unauthorised SIM change or port-out. Ask the provider to freeze further account changes, restore the number to the legitimate SIM and preserve the transaction record.
Write down the time, representative, reference number and exact action promised. If travelling, tell the provider the location and the channel on which you can be reached without the compromised number.
Minute 5–10: protect the primary email
From a known-clean device, change the primary email password, revoke unfamiliar sessions and confirm that forwarding rules, recovery addresses and security keys have not changed. Use a recovery code or hardware key rather than waiting for an SMS. If access is already lost, start the provider’s account-recovery process and warn organisational administrators through a verified channel.
Minute 10–20: freeze financial movement
Call banks, brokerages and payment providers from verified numbers. Ask them to flag account takeover, block new payees or transfers and review recent activity. Do not reveal authentication codes to an inbound caller claiming to help. A real fraud team can route the case after you contact the institution independently.
If a cryptocurrency exchange or custodial service is involved, use its account-compromise process immediately. For self-custodied assets, the mobile number may affect email or cloud recovery rather than the blockchain key itself; secure those dependencies.
Minute 20–30: contain the identity chain
Change or secure the password manager, cloud identity, domain registrar and social accounts. Revoke active sessions. Check whether SMS was added as a new recovery method. Tell close colleagues and family not to trust unusual messages or money requests from the number until the incident is closed.
Create an incident log. Capture screenshots of legitimate alerts, but do not circulate documents containing full account numbers. The log will help with bank disputes, carrier escalation, insurance or law-enforcement reports.
What to do after the number is restored
Restoration is containment, not proof that the incident is over. Ask the carrier for written confirmation of what changed and when. Replace the account PIN and password. Re-enable the number lock using a fresh credential. Check call forwarding, voicemail PIN and authorised users.
Review the primary email’s login history and forwarding rules again. Search for security alerts that may have been deleted or archived. Rotate recovery codes. Remove unknown passkeys, app passwords and connected applications. Review financial transactions and credit reports according to the services available in your jurisdiction.
The FTC advises victims to check bank, card and other financial accounts for unauthorised changes and use IdentityTheft.gov when identity information may be compromised. Reporting also creates a record that can support later disputes.
A travel-specific SIM-swap plan
International travellers have a harder diagnosis because roaming failure looks like account takeover. Before departure, save the carrier’s international fraud contact, account number and eSIM recovery process. Do not keep the only hardware security key in checked luggage. Carry two independent ways to reach primary email and banking services.
A dual-SIM phone can improve connectivity resilience, but it does not protect the primary number’s carrier account. Likewise, an eSIM removes a small physical card; it does not remove social engineering from the transfer process. The protection still comes from carrier controls, authentication design and recovery readiness.
Sources and verification
Federal Communications Commission order on SIM swapping and port-out fraud
NIST SP 800-63B: Authentication and Authenticator Management
Sources were checked on 22 July 2026. Carrier controls and account-recovery options vary by country and provider. Verify the exact feature names and emergency channels with each service.
Final decision
The phone number should be a contact route, not the master key to a digital life. Carrier locks make unauthorised movement harder. Passkeys, security keys and authenticator apps reduce the value of intercepted texts. Offline recovery routes keep the legitimate owner operational when the number fails. Combine all three, then rehearse the first 30 minutes. That is stronger SIM-swap protection than any single toggle can provide.




