A phone that suddenly loses all service, no calls, no texts, no data, can be the first sign that a scammer has just taken over the number attached to a bank account, a brokerage account, or email. The scammer does not need to touch the phone itself; they convince the victim’s own cell carrier to activate that number on a new SIM card in a device they control, redirecting every text message, including the one-time codes banks and brokerages use to verify logins, password resets and large transfers.
How a Scammer Convinces a Carrier to Swap the SIM
The scam begins with a phone call or in-person visit to the target’s mobile carrier, where the scammer poses as the account holder and claims their phone was lost, stolen or damaged, requesting that the number be moved to a new SIM card. If the carrier’s representative accepts the story, sometimes after answering security questions the scammer has pieced together from data breaches, social media or a purchased identity file, the victim’s real phone stops receiving calls and texts entirely while the new device receives everything instead.
Once that swap goes through, the scammer controls the one channel most banks, brokerages and email providers use to confirm a login attempt is legitimate. Armed with a target’s login credentials, the scammer can log in to a bank account and steal money, or take over an email or social media account and change the passwords to lock the real owner out entirely.
The window between the swap and the fraud is often short. A scammer who already has a stolen password just needs the verification text to complete a reset or approve a transfer, and once inside a brokerage or bank account, funds can be moved before the account holder even notices their phone has stopped working.
Regulators have responded to the pattern directly. In 2023, the Federal Communications Commission adopted new rules requiring wireless carriers to verify a customer’s identity through secure authentication before redirecting a phone number to a new device or provider, and to notify customers immediately whenever a SIM change or port-out request hits their account. That same rulemaking also covers a close cousin of the SIM swap: port-out fraud, where a scammer poses as the victim to open an account at a different carrier entirely, then transfers the victim’s number to that new account rather than swapping it to a new SIM at the original carrier. Both attacks end the same way, with someone else’s device receiving the victim’s calls and texts, but a port-out means the number has left the original carrier altogether, which can make it slower to restore once discovered.
Free retirement updates: Keep more of your Social Security and savings with plain-English updates on the changes, deadlines, and costly mistakes retirees miss. Subscribe free.
Why Text-Message Verification Is the Weak Point
Multi-factor authentication that relies on a text message is meant to add a second layer of security beyond a password, but that layer collapses the moment a scammer controls the phone number itself. A code meant to prove “something you have” no longer proves anything once the something is sitting on the scammer’s device instead of the real owner’s.
Authentication methods that do not depend on the phone network, such as a dedicated authenticator app or a physical security key, are not affected by a SIM swap because they are tied to a device or an app rather than a phone number a carrier can reassign. Someone with meaningful savings in a brokerage or bank account that still relies solely on text-message codes is protected only as well as their cell carrier’s willingness to verify identity before swapping a SIM.
Limiting how much personal information sits in public view also matters, since a scammer building a convincing case for a carrier’s customer service line often pulls a target’s full name, address or birthdate from social media profiles or public records before ever making the call. The less identifying information available publicly, the harder it is to pass a carrier’s identity check while impersonating someone else.
Locking Down the Cellular Account Before It Happens
Anyone who suspects a scammer has gathered enough personal information to attempt a SIM swap, such as a Social Security number or bank account details exposed in a prior data breach, has a next step beyond the carrier: reporting the concern to identity-theft authorities before a swap even happens, so vulnerable accounts can be watched pre-emptively rather than only after money has already moved.
Most carriers allow a customer to add a PIN or password directly to the cellular account, a step separate from any phone’s screen lock, that must be provided before a representative can move a number to a new SIM. It is not a guarantee against a determined scammer working with an insider or an employee willing to bypass the check, but it removes the easiest version of the attack, one built purely on a convincing phone call.
Anyone whose phone unexpectedly loses all service should treat it as a possible SIM swap in progress rather than a network glitch, and contact their carrier immediately through a different device to regain control of the number. From there, checking bank, brokerage and credit card statements for unauthorized activity and changing account passwords becomes the next step, since the entire scam exists to open a short window for exactly that kind of theft.
This article was researched and drafted with the assistance of artificial intelligence.
More Financial Reading