Most people don’t think of their mobile number as something that can be stolen — but SIM swap fraud does exactly that, and once a criminal controls your number, they can use it to work through the security checks protecting your bank accounts, email and social media, one by one.
How SIM swap fraud actually works
According to Which?, the UK consumer rights organisation, criminals gather enough personal information about a target — often through phishing, data breaches, or details posted publicly on social media — to convincingly impersonate them to a mobile network provider, then use that information to request that the victim’s number be transferred to a new SIM card the criminal controls. Once that transfer, or “swap,” is complete, “your phone loses network connectivity, and the fraudster receives all your calls and texts” instead of you.
The real danger isn’t the lost signal itself — it’s what that access unlocks. As Which? explains, “by stealing it, they could intercept OTPs [one-time passcodes] to access your bank accounts, social media profiles, emails and any other online accounts that use SMS-based identity checks.” A phone number is still treated as a strong identity signal by many services, which is precisely why controlling it is so valuable to a fraudster.
A pattern worth knowing about
Which?’s reporting highlights that email compromise often happens first, as a stepping stone to a SIM swap — in one case, fraudsters targeted a victim’s email first, “meaning they could receive the OTP to reset his Vodafone password and complete the SIM swap.” This shows how these attacks often chain together multiple weaker points rather than relying on a single failure, which is part of why securing your email account specifically is so important.
Warning signs to watch for
- Sudden, total loss of signal. If calls, texts and mobile data stop working unexpectedly, and it isn’t a known network outage, treat it as a genuine warning sign rather than an annoyance to deal with later.
- Unexpected SIM-related texts or emails. A message confirming a SIM swap, PAC (number transfer) request, or account change you didn’t initiate needs immediate attention.
- Repeated failed security check attempts. Which?’s reporting notes that in real cases, fraudsters were allowed to proceed “despite repeatedly failing to answer security questions correctly” — a reminder that “failed or persistent attempts to change sensitive account information should be another warning sign” worth acting on if you notice it on your own accounts.
How to protect yourself
Which? recommends a layered set of protections rather than relying on any single measure:
- Stay alert to the sources that feed these attacks — “fake calls, emails, texts and adverts” are often how criminals gather the personal details needed to impersonate you in the first place.
- Use strong, unique passwords on your email and mobile network account specifically, since these are the accounts most directly involved in enabling a SIM swap.
- Move beyond SMS-based two-factor authentication where you can. Which? specifically recommends preferring “passkeys” — which are tied to a physical device rather than your phone number — over SMS codes, since SMS-based verification is exactly what a SIM swap is designed to intercept.
- Review your social media privacy settings, since publicly visible personal details (date of birth, address, mother’s maiden name, pet names) are often exactly what’s used to pass a mobile provider’s identity checks.
- Ask your provider about extra account security, such as an additional PIN or password required before any sensitive change — including a SIM swap — can be made on your account.
What to do if you suspect a SIM swap is happening
If you unexpectedly lose all phone service, or receive a message about a SIM or number change you didn’t request, act immediately: contact your network provider via webchat or by using another device to call them, rather than waiting to see if service returns on its own. The faster a fraudulent swap is identified and reversed, the smaller the window a criminal has to use your number to compromise other accounts.
Securing the accounts most worth prioritising
If you’re working through your own accounts to reduce SIM swap risk, it’s worth prioritising rather than trying to change everything at once. Email is the natural starting point, since it’s frequently the gateway used to reset other accounts, followed by online banking and any account holding stored payment details. For each of these, check what authentication method is currently in use, and where an app-based authenticator or passkey option exists as an alternative to SMS codes, switching to it removes one of the specific weaknesses that makes SIM swap fraud effective in the first place.
What information to avoid sharing publicly
Because SIM swap fraud typically begins with gathering enough personal detail to pass a mobile provider’s identity checks, it’s worth reviewing what’s publicly visible on your own social media profiles. Full date of birth, home address, children’s or pets’ names, and answers to common security questions (first school, mother’s maiden name) are all worth keeping off public profiles specifically because they’re the building blocks fraudsters use to impersonate you convincingly to a call centre agent who has no way of independently verifying who they’re actually speaking to.
