The attacker wants control of the number
A SIM swap redirects your phone number to another SIM or device. A fraudulent port-out can move it to another carrier. The attacker may then receive verification messages and exploit account-recovery methods tied to that number.
The attack can involve stolen personal information, social engineering, or a compromised carrier account. An eSIM does not eliminate this problem: an unauthorized change can target the carrier’s account process rather than a physical card.
Remove the number from the most important recovery paths
Prefer supported security keys, passkeys, or authenticator apps for email and exchange access. Check password resets and fallback authentication too; switching the normal login method is not enough if the service still lets someone reset access using SMS.
Keep recovery codes independently available. A separate, less public number can reduce exposure but should not be treated as impossible to hijack. Your defenses should not depend on the number remaining secret forever.
Ask the carrier which controls it actually offers
Set a unique account password and a separate carrier security PIN if available. Ask about a number lock, SIM-change protection, port-out lock, and notifications for account changes. These features and their exceptions differ by provider.
- Find the carrier’s support route in advance and save it somewhere accessible without mobile service.
- Review who is authorized to make changes to the account.
- Use account-change alerts on an independently secured email address where supported.
- Remove unnecessary public personal details that could help someone impersonate you.
- Confirm how you would regain access if both the phone and the number were unavailable.
Unexpected loss of service needs a quick check
A sudden loss of calls, texts, or data can have an ordinary network cause, but an unexpected SIM activation or porting notice is more specific. Do not wait for an SMS confirmation if the number itself may be compromised.
Use Wi-Fi, another phone, or the carrier’s verified website to check. Examine email alerts for password resets, unfamiliar sessions, new withdrawal addresses, or other account changes.
Contain the damage while reclaiming the number
Contact the carrier through a known channel and report an unauthorized SIM change or transfer. In parallel, use a trusted device to secure your email and ask financial providers or exchanges to restrict compromised accounts.
After access is restored, replace exposed credentials, revoke unknown sessions, and inspect recovery settings. Preserve the carrier notices and suspicious activity. US identity-theft victims can use IdentityTheft.gov to build a recovery plan and report internet crime to IC3.
Sources & limits
Source review: Oct 1, 2026. Availability and provider terms can change.
Keep exploring
Set up two-factor authentication for your crypto accounts
Choose a security key or authenticator app, save recovery codes, and secure the email account that controls your exchange logins.
Read page →Secure an exchange account and understand custody risk
Review authentication, withdrawals, API permissions, the legal entity holding your crypto, and what protection applies to each balance.
Read page →Recognize crypto phishing before you sign or send
Spot fake support, login pages, wallet updates, investment pitches and recovery scams. Know what to do after a suspicious request.
Read page →