A phone number stopped being just for calls long ago. It receives bank OTP codes, WhatsApp login codes, email recovery links, and e-wallet confirmations. Whoever controls your number, even for a few hours, can open many doors at once.

A SIM swap is how that number gets taken over. The attacker never needs to touch your phone. They only need to convince the carrier, or someone at a store counter, that they are the owner of a number whose card was lost or damaged, and ask for a replacement.

How it works

A number is active on only one SIM at a time. When a replacement card is issued, the old one stops working. The usual sequence:

  1. The attacker gathers the victim's details: full name, national ID number, date of birth, mother's maiden name. These often come from data breaches, circulating ID card photos, or are fished out through fake calls and messages.
  2. The attacker goes to a store or calls customer service, claims the card is lost, and asks for a replacement. Sometimes an insider helps.
  3. The victim's card dies. The attacker puts the new card in their own phone and starts receiving SMS and calls for the victim's number.
  4. The attacker taps "forgot password" on email, social media, and finance apps, then uses the OTP codes now arriving on their phone.

Other variants need no physical card at all: the attacker requests a move to eSIM, or tricks the victim into reading out a code the carrier sent. The pretext often resembles scams posing as technicians.

Warning signs

  • Cellular signal disappears entirely with "no service" or "SIM not registered", while people near you on the same carrier are fine.
  • An SMS from the carrier about a card replacement or eSIM activation you never requested.
  • Emails about a new login or password change from services you use.
  • Friends tell you they received strange messages from your account.

Watch for one trap: if your phone is on Wi-Fi, WhatsApp and the internet carry on as usual even after the SIM has died. Many victims only notice hours later, after leaving home and finding they can't make a call. Get into the habit of glancing at the cellular signal indicator, not just the Wi-Fi icon.

If you suspect it is happening

Time matters. Do this from another phone or computer:

  1. Call your carrier's customer service, ask them to suspend the number and whether a card or eSIM replacement was made.
  2. Call your bank on the official number on the back of your card and ask them to block mobile banking and the card.
  3. Change your main email password from a device you still control, then sign out all other sessions.
  4. Go to an official carrier store with your ID to reclaim your number.
  5. Keep evidence: screenshots, SMS, and notification emails, for reports to the bank and police.

Follow-up steps after an account has been taken over are similar to what to do after a network is hacked: treat every account linked to that number as needing a fresh check.

Reducing the risk

You can't control procedures at the carrier's counter, but you can stop your phone number from being the only key.

StepWhy it helps
Replace SMS OTP with an authenticator app or passkeyCodes are tied to a device and don't move with the number
Turn on WhatsApp two-step PINAn attacker receiving the SMS code still can't register your account
Use a recovery email that isn't itself recovered by SMSEmail is the door to other accounts; don't let it depend on the number
Enable device binding in mobile bankingThe account can't be opened on a new phone with an OTP alone
Don't share ID card photos and personal detailsThat data is exactly what attackers use to convince staff

A broader look at verification methods is in two-step verification and account security. If your data has appeared in a breach, the risk is higher; see also how to report a personal data breach.

Numbers you no longer use

A prepaid number that isn't topped up eventually expires and is later reissued to someone else. If that old number is still listed for recovery on your email, bank, or marketplace accounts, its new owner can receive your OTP codes without any SIM swap. Before letting a number go, move every account to your new one.

Frequently asked questions

What are the signs my number is being hijacked through a SIM swap?

The most common sign is your SIM suddenly getting no service at all, unable to call or receive SMS, while other phones in the same place work normally. It is often followed by login or password-reset notifications in your email and apps. If that happens, contact your carrier straight away from another phone.

Does using Wi-Fi protect me from a SIM swap?

No. A SIM swap happens at the carrier, not on the network you use. Wi-Fi can actually hide the signs, because WhatsApp and the internet keep working over Wi-Fi even after the SIM has been deactivated. Watch the cellular signal indicator, not just the Wi-Fi icon.

What is a safer alternative to SMS OTP?

An authenticator app, a physical security key, or a passkey. All three are tied to a device rather than a phone number, so they don't move when the number is hijacked. For mobile banking, also enable the transaction PIN and device binding your bank provides.