Skip to main content
Back to the wiki
Account Security

What Is SIM Swapping?

Last updated on July 21, 2026

SIM swapping is the hijacking of a victim's mobile phone number by convincing — or corrupting — the carrier into transferring that number to a SIM card the attacker controls. From the moment the port completes, every call and text message meant for the victim rings on the attacker's device, including the SMS one-time codes that banks, exchanges, and email providers send to "verify it's really you." The attack subverts nothing technical in the phone network; it exploits the fact that a phone number, widely used as an identity anchor, is administratively reassignable by a support agent having a bad day.

Anatomy of a swap

The attack starts with research, because the carrier conversation requires answers: name, address, date of birth, last payment amounts — harvested from breach dumps, phishing, and social media. Armed with a convincing story ("lost my phone, need my number on this new SIM"), the attacker social-engineers a support channel; higher-end crews skip persuasion and pay carrier insiders to process the port directly. The victim's handset goes dead, and a race begins that the victim usually loses while wondering why they have no signal: password resets on email, then bank and cryptocurrency accounts, each secured by SMS codes now arriving at the attacker. Documented single-victim losses run into the millions, and prosecutions of SIM-swap rings have become a fixture of cybercrime enforcement in the US and Europe.

What it says about SMS authentication

SIM swapping is the clearest argument in the case against SMS as a security factor: the code proves possession of a phone number, and a phone number is not a possession — it is an entry in a carrier database with human-mediated write access. Security guidance has drawn the consequence; NIST's digital identity guidelines have discouraged SMS-based verification for years in favor of app-based codes and phishing-resistant authenticators. The two-factor authentication hierarchy matters here: authenticator apps and passkeys are immune to number porting, while SMS remains the fallback that MFA bypass techniques of every kind gravitate toward — with OTP bots covering the cases where the code must be phished rather than received.

Reducing exposure on both sides

Individuals can set a carrier port-out PIN, remove their phone number as a recovery method wherever a stronger option exists, and prefer app-based or hardware-backed factors for anything touching money. Services should treat SMS as a convenience tier, offer stronger factors prominently, and — because a swapped SIM is usually the second act of a compromise that began with leaked credentials — harden the login surface itself: monitoring for credential-stuffing patterns, with human verification such as CaptchaFox filtering the automated login and password-reset traffic that identifies which accounts are worth swapping a SIM for. Our article on account takeover attacks covers that broader kill chain. A number that can be ported will eventually be ported; the design goal is an account where that event no longer matters.

About CaptchaFox

CaptchaFox is a GDPR-compliant solution based in Germany that protects websites and applications from automated abuse, such as bots and spam. Its distinctive, multi-layered approach utilises risk signals and cryptographic challenges to facilitate a robust verification process. CaptchaFox enables customers to be onboarded in a matter of minutes, requires no ongoing management and provides enterprises with long-lasting protection.

To learn more about CaptchaFox, talk to us or start integrating our solution with a free trial.

Related terms

What Is Two-Factor Authentication (2FA)?

Two-factor authentication secures logins by requiring a second, independent proof of identity beyond the password — knowledge, possession, or biometrics.

Read more
What Is a Datacenter Proxy?

A datacenter proxy routes traffic through servers in commercial hosting facilities — fast and cheap, but recognizable by its network of origin.

Read more
What Is a DDoS Attack?

A DDoS attack floods a service with traffic from many sources at once to make it unavailable — from raw bandwidth floods to stealthy application-layer attacks.

Read more
What Is a False Positive Rate?

The false positive rate is the share of legitimate users a security system wrongly flags as threats — the metric that decides what protection really costs.

Read more

Fight bots and protect your users' data.

Don't give fraudsters and spammers a chance and protect your website with CaptchaFox today.

CaptchaFox protecting websites on desktop and mobile devices