166 terms · 75/46/45
Threat № 025 · class: identity

SIM Swapping

SIM swapping does not attack the phone but the phone number. The attacker persuades, or bribes, a mobile operator to move the number to a new SIM card, citing a lost phone or a damaged card. They usually come armed with personal details from leaked databases and phishing. The moment the number moves to their card, the real phone loses signal and every call and message goes to the attacker.

Term

description · examples · notes

SIM swapping does not attack the phone but the phone number. The attacker persuades, or bribes, a mobile operator to move the number to a new SIM card, citing a lost phone or a damaged card. They usually come armed with personal details from leaked databases and phishing. The moment the number moves to their card, the real phone loses signal and every call and message goes to the attacker.

Description

The damage comes through what arrives. Confirmation codes sent by SMS and password resets over SMS now reach the attacker. They request a reset on the mail account, the bank, the crypto wallet, receive the code by message, and take the account. Cryptocurrency holders and high-profile targets are especially exposed. The weak point is not the device but the shallow identity check at the operator.

The defense rests on not using SMS as a second factor. Authenticator apps and hardware keys (FIDO2) do not depend on a phone number. With the operator it is worth setting a PIN or a port-out lock. A phone number should not be publicly tied to sensitive accounts. And one warning: a sudden loss of signal for no reason can mean a number transfer is already under way.

Examples

  • An attacker holding leaked details calls the operator, reports a lost SIM card, and receives and activates a new one. Through SMS-based MFA they empty a crypto wallet.
  • A targeted executive: the number moves to the attacker's card, the mail reset codes are intercepted, the account is taken.
  • A phone suddenly shows no network where there should be one — a possible sign that a number transfer is already in progress.

Notes

  • It attacks the operator and the number, not the phone — the security of the device itself does not help here.
  • The strongest argument against SMS confirmation: an app and a hardware key do not depend on a phone number, so a SIM swap does not touch them.

Mentioned in the news

Composite
Wikipedia

Techniques

carried out with 2

Techniques used to carry it out. Select one to open its page.

Defenses

countered by 4