What Is SIM Swapping?
SIM swapping is the hijacking of a victim's mobile phone number by convincing, or corrupting, the carrier into transferring that number to a SIM card the attacker controls. From the moment the port completes, every call and text message meant for the victim rings on the attacker's device, including the SMS one-time codes that banks, exchanges, and email providers send to "verify it's really you." The attack subverts nothing technical in the phone network; it exploits the fact that a phone number, widely used as an identity anchor, is administratively reassignable by a support agent having a bad day.
Anatomy of a Swap
The attack starts with research, because the carrier conversation requires answers: name, address, date of birth, and last payment amounts, all harvested from breach dumps, phishing, and social media. Armed with a convincing story ("lost my phone, need my number on this new SIM"), the attacker social-engineers a support channel; higher-end crews skip persuasion and pay carrier insiders to process the port directly. The victim's handset goes dead, and a race begins that the victim usually loses while wondering why they have no signal: password resets on email, then bank and cryptocurrency accounts, each secured by SMS codes now arriving at the attacker. Documented single-victim losses run into the millions, and prosecutions of SIM-swap rings have become a fixture of cybercrime enforcement in the US and Europe.
What It Says About SMS Authentication
SIM swapping is the clearest argument against SMS as a security factor: the code proves possession of a phone number, and a phone number isn't a possession, it's an entry in a carrier database with human-mediated write access. Security guidance has drawn the consequence; NIST's digital identity guidelines have discouraged SMS-based verification for years in favor of app-based codes and phishing-resistant authenticators. The two-factor authentication hierarchy matters here: authenticator apps and passkeys are immune to number porting, while SMS remains the fallback that MFA bypass techniques of every kind gravitate toward, with OTP bots covering the cases where the code has to be phished rather than received.
Reducing Exposure on Both Sides
Individuals can set a carrier port-out PIN, remove their phone number as a recovery method wherever a stronger option exists, and prefer app-based or hardware-backed factors for anything touching money. Services should treat SMS as a convenience tier, offer stronger factors prominently, and, because a swapped SIM is usually the second act of a compromise that began with leaked credentials, harden the login surface itself: monitoring for credential-stuffing patterns, with human verification such as CaptchaFox filtering the automated login and password-reset traffic that identifies which accounts are worth swapping a SIM for. Our article on account takeover attacks covers that broader kill chain. A number that can be ported will eventually be ported; the design goal is an account where that event no longer matters.
About CaptchaFox
CaptchaFox is a GDPR-compliant solution based in Germany that protects websites and applications from automated abuse, such as bots and spam. Its distinctive, multi-layered approach utilises risk signals and cryptographic challenges to facilitate a robust verification process. CaptchaFox enables customers to be onboarded in a matter of minutes, requires no ongoing management and provides enterprises with long-lasting protection.
To learn more about CaptchaFox, talk to us or start integrating our solution with a free trial.