Skip to main content
Category: Fraud Typologies

SIM Swapping

Also known as: SIM hijacking, SIM swap attack, SIM swap fraud, SIM splitting, simjacking, port-out scam, unauthorized SIM change
Simply put

SIM swapping is a type of fraud in which a criminal arranges to have a victim's phone number transferred to a SIM card the criminal controls, usually by tricking the victim's mobile provider. Once the number is moved, the attacker can begin receiving the victim's calls and text messages, including one-time codes sent for account verification. This can allow the attacker to take over accounts that rely on phone-based verification.

Formal definition

SIM swapping is an account takeover technique in which an attacker causes a target's mobile phone number to be transferred, or ported, to a SIM under the attacker's control, typically through social engineering of the mobile carrier or its retail channels rather than through a technical compromise of the device. Because the number then routes calls and SMS to the attacker, this defeats SMS one-time passcodes and other phone-number-bound out-of-band verification, undermining SMS-based multi-factor authentication. Note that the same underlying carrier service, retaining a phone number when changing devices or carriers, is legitimate; the fraud lies in the unauthorized transfer. This term describes an authentication-channel compromise and is distinct from card-present or card-not-present payment card fraud; its effectiveness depends on how heavily a targeted account relies on phone-number-based authentication factors.

Why it matters

SIM swapping matters because it targets a weak point that many organizations still rely on for identity verification: the phone number. When an account uses SMS one-time passcodes or voice calls for verification or as a second authentication factor, control of the phone number can be enough for an attacker to receive those codes and take over the account. Because the attack works by transferring the victim's number to a SIM the attacker controls, the compromise happens at the carrier level rather than on the victim's device, so the victim may not immediately realize what has occurred.

Who it's relevant to

Fraud and Risk Analysts
SIM swapping is an account takeover technique, distinct from card-present and card-not-present payment card fraud, that compromises the authentication channel rather than the payment instrument. Analysts should recognize that a successful SIM swap can precede downstream account takeover and should account for the limitations of phone-based verification when assessing risk signals.
Authentication and Security Engineers
Because SIM swapping is intended to intercept SMS one-time passcodes and other phone-number-bound verification, engineers evaluating multi-factor authentication should weigh the exposure of SMS-based factors. The attack undermines the assumption that possession of a phone number reliably proves possession of a specific device; no single control eliminates this risk, and mitigations should be considered in the context of the broader authentication design.
Compliance and Identity Verification Teams
Teams that design customer verification flows should understand that phone-number-based verification can be defeated by unauthorized SIM transfers. This is relevant when deciding how much trust to place in SMS or voice channels for step-up verification or account recovery, and when documenting the residual risks of those channels.
Mobile Carriers and Their Retail Channels
Because SIM swap fraud typically relies on social engineering of the carrier or its retail channels to authorize an unauthorized number transfer, carriers are directly relevant to detecting and preventing the fraud. Controls around how legitimate device and carrier changes are verified may help reduce, though not guarantee elimination of, unauthorized transfers.

Inside SIM Swapping

SIM Swap Attack
A form of account takeover in which an attacker persuades or deceives a mobile carrier into transferring a victim's phone number to a SIM the attacker controls, often using social engineering, stolen personal data, or insider assistance.
SMS-Based OTP Interception
The core payoff of a SIM swap: once the number is ported, one-time passcodes and authentication messages delivered by SMS or voice are received by the attacker, undermining any factor that relies on possession of the phone number.
Targeted Authentication Factor
SIM swapping specifically attacks SMS or voice as an out-of-band delivery channel used in multi-factor authentication and step-up flows; it does not defeat factors that are independent of the phone number, such as hardware security keys or app-based cryptographic authenticators.
Downstream Account Compromise
After capturing SMS-based codes, an attacker may reset passwords and take over email, banking, or payment accounts, enabling card-not-present fraud, unauthorized transactions, or credential harvesting. The resulting fraud is governed by card brand and network rules, which vary by region.
Carrier and Identity Verification Weaknesses
The attack exploits the identity-proofing controls of the mobile carrier rather than any PCI DSS system; the vulnerability lies in how the carrier verifies the requester before reassigning a number.

Common questions

Answers to the questions practitioners most commonly ask about SIM Swapping.

Is SIM swapping the same thing as SIM cloning?
No. SIM swapping and SIM cloning are distinct attacks that are frequently conflated. SIM swapping is a social-engineering and account-takeover technique in which an attacker convinces or coerces a mobile carrier to transfer a victim's phone number to a SIM the attacker controls, without any physical access to the original SIM. SIM cloning, by contrast, involves copying the cryptographic identifiers from a SIM to create a duplicate. In SIM swapping the vulnerability lies in the carrier's account-provisioning and identity-verification processes, not in the SIM hardware itself.
Does using multi-factor authentication mean an account is safe from SIM swapping?
Not necessarily. The risk depends on which factor is used. SIM swapping specifically targets SMS-based and voice-call one-time passcodes, so multi-factor authentication that relies on a phone number as the delivery channel may be undermined once an attacker controls the number. Multi-factor authentication using factors not tied to the phone number, such as authenticator-app time-based codes, FIDO or hardware security keys, or push-based approvals bound to a device, is intended to be more resistant to this attack. Describing a control as 'MFA' alone does not indicate whether it mitigates SIM swapping; the factor type and delivery channel determine that.
How can an organization reduce reliance on SMS-based authentication that is exposed to SIM swapping?
Organizations can offer and encourage phishing-resistant or device-bound authentication factors, such as authenticator-app codes, FIDO2/WebAuthn security keys, or push approvals tied to a registered device, rather than defaulting to SMS or voice one-time passcodes. Where SMS remains available as a fallback, it can be treated as a lower-assurance factor and paired with additional signals. The appropriate approach depends on the user population, regulatory context, and the sensitivity of the protected accounts, and no single factor eliminates all account-takeover risk.
What detection signals may indicate a SIM swap has occurred before or during account takeover?
Signals that may help flag a possible SIM swap include recent SIM-change or number-port events reported through carrier or telecom-intelligence services, a sudden change in device or SIM identifiers, loss of connectivity patterns, and correlated high-risk actions such as password resets, contact-detail changes, or new-payee additions shortly after such events. These signals produce both false positives, for example legitimate device upgrades, and false negatives, so they are generally used to raise risk scores or trigger step-up verification rather than to make standalone decisions.
What step-up controls can be applied when a SIM-swap risk signal is detected?
When a SIM-swap risk signal is present, an organization may impose a cooling-off or delay period before sensitive changes take effect, require re-authentication through a channel not tied to the phone number, restrict high-risk actions such as adding payees or changing recovery details, and route the event to manual review. The goal is to add friction proportional to the assessed risk while limiting disruption to legitimate users. These measures are intended to reduce, not guarantee prevention of, successful takeover.
How does SIM swapping relate to payment and cardholder-account fraud workflows?
SIM swapping is primarily an account-takeover enabler rather than a direct compromise of cardholder data. By capturing SMS or voice one-time passcodes, an attacker may bypass step-up authentication used in some card-not-present flows and in account-management portals, potentially enabling unauthorized transactions or changes to recovery information. Fraud and risk teams typically account for it within account-takeover and authentication-risk models, coordinating with carrier signals where available. Liability and dispute outcomes for any resulting fraudulent transactions are governed by applicable card brand and network rules, which vary by region and change over time.

Common misconceptions

Using SMS-based multi-factor authentication guarantees an account cannot be taken over.
SMS one-time passcodes are tied to a phone number, not to the cardholder. A successful SIM swap redirects those codes to the attacker, so SMS-based MFA may be bypassed. It helps reduce some risks but does not eliminate account takeover, and generally offers weaker assurance than app-based or hardware authenticators.
SIM swapping is a failure of the merchant's or processor's PCI DSS environment.
SIM swapping targets the mobile carrier's identity-verification process and the victim's phone account, which are typically outside the merchant's or processor's PCI DSS scope. It is an authentication and account-takeover risk rather than a compromise of stored cardholder data within the payment environment.
Any multi-factor authentication defeats SIM swapping.
Only factors that depend on the phone number, such as SMS or voice OTP, are affected by a SIM swap. Multi-factor authentication using channel-independent factors, such as cryptographic hardware keys or app-based authenticators, is intended to be resistant to this specific attack, though no single control eliminates fraud.

Best practices

Prefer authentication methods that are independent of the mobile phone number, such as hardware security keys or app-based cryptographic authenticators, over SMS or voice one-time passcodes where feasible.
Treat SMS-delivered codes as a lower-assurance factor and avoid relying on them as the sole step-up control for high-risk actions such as password resets or payment credential changes.
Monitor for indicators consistent with account takeover, such as a sudden loss of mobile signal followed by password-reset or authentication events, while accounting for false-positive and false-negative trade-offs in any detection rule.
Layer additional risk signals, such as device reputation, behavioral analytics, and transaction velocity checks, so that a single compromised phone number does not by itself grant account or payment access.
Coordinate incident response and customer verification procedures for suspected SIM swap cases, recognizing that resulting chargeback and liability outcomes are governed by card brand and network rules that vary by region.
Encourage customers to enable carrier-side protections against unauthorized number porting where available, while noting these controls are implemented by the mobile carrier and are outside the payment environment.