SIM Swap Attack

A SIM swap attack is the fraudulent transfer of a victim's MSISDN — their phone number — onto a SIM (or eSIM profile) controlled by the attacker. Once the swap is processed, the victim's handset loses service, and every SMS or voice call directed at that number is delivered to the attacker. The objective is almost always to intercept SMS-based one-time passwords (OTPs) for banking, email, exchange or social accounts, complete a password reset using the same channel, and take the account over. The technique does not exploit a protocol vulnerability; it exploits the operator's identity-verification and porting workflow.

The two common variants are customer-care SIM swap (the attacker contacts the home operator's call centre, impersonates the subscriber with social-engineering data harvested elsewhere, and requests a replacement SIM) and port-out fraud (the attacker triggers a number portability transfer to a different operator under their control, abusing MNP procedures). Both end at the same place: the HLR/UDM is updated to point the MSISDN at the attacker's SIM, and the SS7/Diameter machinery routes traffic to it normally.

Operator-side containment is workflow-heavy rather than protocol-heavy. The controls that actually work are mandatory port-out PINs that cannot be reset by SMS, strong identity verification before any SIM replacement, anomaly detection on swap velocity and on first-use of a freshly issued SIM, customer-facing notification with a cooling-off window, and tightened authority for high-risk number ranges. SMS-based 2FA is itself the underlying weakness on the consumer side: where it can be replaced with app-based or hardware authenticators, it should be. For the broader SMS attack surface see the SMS Firewall guide; for the SS7/Diameter paths that complement SIM swap (location disclosure and SMS interception without a swap), see SS7 Security.

Frequently asked questions about sim swap attack

What is SIM swapping and how is it used in attacks?

SIM swapping is a social engineering attack where an attacker convinces a mobile operator to transfer a victim's phone number to a SIM card they control. This allows the attacker to receive the victim's calls and SMS messages, including two-factor authentication codes, enabling account takeover of banking, email, and cryptocurrency accounts. Defenses include port-out PINs and multi-factor authentication that does not rely on SMS.

See all telecom security FAQs

Related glossary terms

Browse the full telecom security glossary

Related comparisons

Regulation by jurisdiction

More on Sim Swap Attack

Browse all topic hubs, the Ultimate Guide to Mobile Network Security and the TelcoSec Glossary.