Skip to main content
Attacks and Threats

SIM Swapping

A fraud attack where an attacker convinces a carrier to transfer a victim's phone number to a SIM they control, intercepting SMS-based two-factor authentication codes.

SIM swapping (also called SIM jacking) occurs when an attacker convinces a mobile carrier to transfer a victim’s phone number to a new SIM card controlled by the attacker. This gives the attacker access to all SMS messages and phone calls intended for the victim.

The primary target is SMS-based two-factor authentication. Once the attacker controls the phone number, they can receive 2FA codes and reset passwords on any account that uses SMS verification.

Defenses include using app-based TOTP or hardware security keys instead of SMS for 2FA, setting a PIN on your mobile carrier account, being cautious about sharing personal information (used for carrier verification), and monitoring for unexpected loss of cell service.

Back to the glossary

Stop sharing passwords in spreadsheets

TeamPassword stores, shares and rotates your team credentials, encrypted end to end.

Trusted by 900+ agencies and small teams worldwide