What Is SIM Swapping?
SIM swapping is the hijacking of a victim's mobile phone number by convincing — or corrupting — the carrier into transferring that number to a SIM card the attacker controls. From the moment the port completes, every call and text message meant for the victim rings on the attacker's device, including the SMS one-time codes that banks, exchanges, and email providers send to "verify it's really you." The attack subverts nothing technical in the phone network; it exploits the fact that a phone number, widely used as an identity anchor, is administratively reassignable by a support agent having a bad day.
Anatomy of a swap
The attack starts with research, because the carrier conversation requires answers: name, address, date of birth, last payment amounts — harvested from breach dumps, phishing, and social media. Armed with a convincing story ("lost my phone, need my number on this new SIM"), the attacker social-engineers a support channel; higher-end crews skip persuasion and pay carrier insiders to process the port directly. The victim's handset goes dead, and a race begins that the victim usually loses while wondering why they have no signal: password resets on email, then bank and cryptocurrency accounts, each secured by SMS codes now arriving at the attacker. Documented single-victim losses run into the millions, and prosecutions of SIM-swap rings have become a fixture of cybercrime enforcement in the US and Europe.
What it says about SMS authentication
SIM swapping is the clearest argument in the case against SMS as a security factor: the code proves possession of a phone number, and a phone number is not a possession — it is an entry in a carrier database with human-mediated write access. Security guidance has drawn the consequence; NIST's digital identity guidelines have discouraged SMS-based verification for years in favor of app-based codes and phishing-resistant authenticators. The two-factor authentication hierarchy matters here: authenticator apps and passkeys are immune to number porting, while SMS remains the fallback that MFA bypass techniques of every kind gravitate toward — with OTP bots covering the cases where the code must be phished rather than received.
Reducing exposure on both sides
Individuals can set a carrier port-out PIN, remove their phone number as a recovery method wherever a stronger option exists, and prefer app-based or hardware-backed factors for anything touching money. Services should treat SMS as a convenience tier, offer stronger factors prominently, and — because a swapped SIM is usually the second act of a compromise that began with leaked credentials — harden the login surface itself: monitoring for credential-stuffing patterns, with human verification such as CaptchaFox filtering the automated login and password-reset traffic that identifies which accounts are worth swapping a SIM for. Our article on account takeover attacks covers that broader kill chain. A number that can be ported will eventually be ported; the design goal is an account where that event no longer matters.
About CaptchaFox
CaptchaFox is a GDPR-compliant solution based in Germany that protects websites and applications from automated abuse, such as bots and spam. Its distinctive, multi-layered approach utilises risk signals and cryptographic challenges to facilitate a robust verification process. CaptchaFox enables customers to be onboarded in a matter of minutes, requires no ongoing management and provides enterprises with long-lasting protection.
To learn more about CaptchaFox, talk to us or start integrating our solution with a free trial.