Vai al contenuto principale
Torna al wiki
Account Security

What Is SIM Swapping?

Ultimo aggiornamento il 21 luglio 2026

SIM swapping is the hijacking of a victim's mobile phone number by convincing, or corrupting, the carrier into transferring that number to a SIM card the attacker controls. From the moment the port completes, every call and text message meant for the victim rings on the attacker's device, including the SMS one-time codes that banks, exchanges, and email providers send to "verify it's really you." The attack subverts nothing technical in the phone network; it exploits the fact that a phone number, widely used as an identity anchor, is administratively reassignable by a support agent having a bad day.

Anatomy of a Swap

The attack starts with research, because the carrier conversation requires answers: name, address, date of birth, and last payment amounts, all harvested from breach dumps, phishing, and social media. Armed with a convincing story ("lost my phone, need my number on this new SIM"), the attacker social-engineers a support channel; higher-end crews skip persuasion and pay carrier insiders to process the port directly. The victim's handset goes dead, and a race begins that the victim usually loses while wondering why they have no signal: password resets on email, then bank and cryptocurrency accounts, each secured by SMS codes now arriving at the attacker. Documented single-victim losses run into the millions, and prosecutions of SIM-swap rings have become a fixture of cybercrime enforcement in the US and Europe.

What It Says About SMS Authentication

SIM swapping is the clearest argument against SMS as a security factor: the code proves possession of a phone number, and a phone number isn't a possession, it's an entry in a carrier database with human-mediated write access. Security guidance has drawn the consequence; NIST's digital identity guidelines have discouraged SMS-based verification for years in favor of app-based codes and phishing-resistant authenticators. The two-factor authentication hierarchy matters here: authenticator apps and passkeys are immune to number porting, while SMS remains the fallback that MFA bypass techniques of every kind gravitate toward, with OTP bots covering the cases where the code has to be phished rather than received.

Reducing Exposure on Both Sides

Individuals can set a carrier port-out PIN, remove their phone number as a recovery method wherever a stronger option exists, and prefer app-based or hardware-backed factors for anything touching money. Services should treat SMS as a convenience tier, offer stronger factors prominently, and, because a swapped SIM is usually the second act of a compromise that began with leaked credentials, harden the login surface itself: monitoring for credential-stuffing patterns, with human verification such as CaptchaFox filtering the automated login and password-reset traffic that identifies which accounts are worth swapping a SIM for. Our article on account takeover attacks covers that broader kill chain. A number that can be ported will eventually be ported; the design goal is an account where that event no longer matters.

Informazioni su CaptchaFox

CaptchaFox è una soluzione conforme al GDPR con sede in Germania che protegge siti web e applicazioni da abusi automatizzati, come bot e spam. Il suo approccio distintivo e multilivello utilizza segnali di rischio e sfide crittografiche per facilitare un processo di verifica robusto. CaptchaFox consente ai clienti di essere operativi in pochi minuti, non richiede gestione continua e offre alle aziende una protezione duratura.

Per saperne di più su CaptchaFox, contattaci o inizia a integrare la nostra soluzione con una prova gratuita.

Termini correlati

What Is Strong Customer Authentication (SCA)?

Strong Customer Authentication is the PSD2 requirement that electronic payments in the EEA be confirmed with two independent factors, reshaping checkout flows.

Continua a leggere
What Is Two-Factor Authentication (2FA)?

Two-factor authentication secures logins by requiring a second, independent proof of identity beyond the password, whether knowledge, possession, or biometrics.

Continua a leggere
What Is a Datacenter Proxy?

A datacenter proxy routes traffic through servers in commercial hosting facilities: fast and cheap, but recognizable by its network of origin.

Continua a leggere
What Is a DDoS Attack?

A DDoS attack floods a service with traffic from many sources at once to make it unavailable, from raw bandwidth floods to stealthy application-layer attacks.

Continua a leggere

Combatti i bot e proteggi i dati dei tuoi utenti.

Non dare ai truffatori e agli spammer alcuna possibilità e proteggi il tuo sito web con CaptchaFox oggi.

CaptchaFox protegge i siti web su desktop e dispositivi mobili