The attacker wants control of the number

A SIM swap redirects your phone number to another SIM or device. A fraudulent port-out can move it to another carrier. The attacker may then receive verification messages and exploit account-recovery methods tied to that number.

The attack can involve stolen personal information, social engineering, or a compromised carrier account. An eSIM does not eliminate this problem: an unauthorized change can target the carrier’s account process rather than a physical card.

Remove the number from the most important recovery paths

Prefer supported security keys, passkeys, or authenticator apps for email and exchange access. Check password resets and fallback authentication too; switching the normal login method is not enough if the service still lets someone reset access using SMS.

Keep recovery codes independently available. A separate, less public number can reduce exposure but should not be treated as impossible to hijack. Your defenses should not depend on the number remaining secret forever.

Ask the carrier which controls it actually offers

Set a unique account password and a separate carrier security PIN if available. Ask about a number lock, SIM-change protection, port-out lock, and notifications for account changes. These features and their exceptions differ by provider.

  • Find the carrier’s support route in advance and save it somewhere accessible without mobile service.
  • Review who is authorized to make changes to the account.
  • Use account-change alerts on an independently secured email address where supported.
  • Remove unnecessary public personal details that could help someone impersonate you.
  • Confirm how you would regain access if both the phone and the number were unavailable.

Unexpected loss of service needs a quick check

A sudden loss of calls, texts, or data can have an ordinary network cause, but an unexpected SIM activation or porting notice is more specific. Do not wait for an SMS confirmation if the number itself may be compromised.

Use Wi-Fi, another phone, or the carrier’s verified website to check. Examine email alerts for password resets, unfamiliar sessions, new withdrawal addresses, or other account changes.

Contain the damage while reclaiming the number

Contact the carrier through a known channel and report an unauthorized SIM change or transfer. In parallel, use a trusted device to secure your email and ask financial providers or exchanges to restrict compromised accounts.

After access is restored, replace exposed credentials, revoke unknown sessions, and inspect recovery settings. Preserve the carrier notices and suspicious activity. US identity-theft victims can use IdentityTheft.gov to build a recovery plan and report internet crime to IC3.

Sources & limits

Source review: Oct 1, 2026. Availability and provider terms can change.

Keep exploring