Vai al contenuto principale
Torna al wiki
Account Security

What Is SIM Swapping?

Ultimo aggiornamento il 21 luglio 2026

SIM swapping is the hijacking of a victim's mobile phone number by convincing — or corrupting — the carrier into transferring that number to a SIM card the attacker controls. From the moment the port completes, every call and text message meant for the victim rings on the attacker's device, including the SMS one-time codes that banks, exchanges, and email providers send to "verify it's really you." The attack subverts nothing technical in the phone network; it exploits the fact that a phone number, widely used as an identity anchor, is administratively reassignable by a support agent having a bad day.

Anatomy of a swap

The attack starts with research, because the carrier conversation requires answers: name, address, date of birth, last payment amounts — harvested from breach dumps, phishing, and social media. Armed with a convincing story ("lost my phone, need my number on this new SIM"), the attacker social-engineers a support channel; higher-end crews skip persuasion and pay carrier insiders to process the port directly. The victim's handset goes dead, and a race begins that the victim usually loses while wondering why they have no signal: password resets on email, then bank and cryptocurrency accounts, each secured by SMS codes now arriving at the attacker. Documented single-victim losses run into the millions, and prosecutions of SIM-swap rings have become a fixture of cybercrime enforcement in the US and Europe.

What it says about SMS authentication

SIM swapping is the clearest argument in the case against SMS as a security factor: the code proves possession of a phone number, and a phone number is not a possession — it is an entry in a carrier database with human-mediated write access. Security guidance has drawn the consequence; NIST's digital identity guidelines have discouraged SMS-based verification for years in favor of app-based codes and phishing-resistant authenticators. The two-factor authentication hierarchy matters here: authenticator apps and passkeys are immune to number porting, while SMS remains the fallback that MFA bypass techniques of every kind gravitate toward — with OTP bots covering the cases where the code must be phished rather than received.

Reducing exposure on both sides

Individuals can set a carrier port-out PIN, remove their phone number as a recovery method wherever a stronger option exists, and prefer app-based or hardware-backed factors for anything touching money. Services should treat SMS as a convenience tier, offer stronger factors prominently, and — because a swapped SIM is usually the second act of a compromise that began with leaked credentials — harden the login surface itself: monitoring for credential-stuffing patterns, with human verification such as CaptchaFox filtering the automated login and password-reset traffic that identifies which accounts are worth swapping a SIM for. Our article on account takeover attacks covers that broader kill chain. A number that can be ported will eventually be ported; the design goal is an account where that event no longer matters.

Informazioni su CaptchaFox

CaptchaFox è una soluzione conforme al GDPR con sede in Germania che protegge siti web e applicazioni da abusi automatizzati, come bot e spam. Il suo approccio distintivo e multilivello utilizza segnali di rischio e sfide crittografiche per facilitare un processo di verifica robusto. CaptchaFox consente ai clienti di essere operativi in pochi minuti, non richiede gestione continua e offre alle aziende una protezione duratura.

Per saperne di più su CaptchaFox, contattaci o inizia a integrare la nostra soluzione con una prova gratuita.

Termini correlati

What Is Two-Factor Authentication (2FA)?

Two-factor authentication secures logins by requiring a second, independent proof of identity beyond the password — knowledge, possession, or biometrics.

Continua a leggere
What Is a Datacenter Proxy?

A datacenter proxy routes traffic through servers in commercial hosting facilities — fast and cheap, but recognizable by its network of origin.

Continua a leggere
What Is a DDoS Attack?

A DDoS attack floods a service with traffic from many sources at once to make it unavailable — from raw bandwidth floods to stealthy application-layer attacks.

Continua a leggere
What Is a False Positive Rate?

The false positive rate is the share of legitimate users a security system wrongly flags as threats — the metric that decides what protection really costs.

Continua a leggere

Combatti i bot e proteggi i dati dei tuoi utenti.

Non dare ai truffatori e agli spammer alcuna possibilità e proteggi il tuo sito web con CaptchaFox oggi.

CaptchaFox protegge i siti web su desktop e dispositivi mobili