SecurCheckCyber Centre

SIM SWAPPING · 2FA

How to detect SIM swapping and secure your two-factor authentication (2FA)

Secur Cloud ·

Unexpected loss of mobile service followed by a SIM-change alert or account resets warrants a prompt response. SIM swapping redirects a number to a SIM or eSIM controlled by a fraudster. Accounts using that number for codes or recovery may then be exposed.

Use this guide to compare warning signs, prepare a report to your operator and strengthen SIM & 2FA protection. A SIM swapping detector supports assessment; only the operator can check changes made to your line. If takeover is suspected, contact them without waiting for an analysis result.

1. How SIM swapping works

  1. Gathering information

    An attacker may gather a target’s name, date of birth, address or operator from public sources, phishing or leaked data. This can support impersonation but does not always suffice to obtain a transfer.

  2. Requesting a replacement or transfer

    The fraudster impersonates the subscriber and may claim a lost phone to request a SIM or eSIM they control. Takeover can also involve a compromised operator account, porting fraud or insider involvement: it is not limited to a call to customer support.

  3. Redirecting communications

    Once the transfer is activated, the victim may lose service while calls and texts to the number reach the attacker. SMS codes may be exploited if accounts accept them for sign-in or recovery. The transfer does not automatically expose every account, old message or the phone’s contents.

2. Warning signs of mobile-line takeover

  1. Unexplained loss of service

    “No service” or “Emergency calls only” in a normally covered area deserves checking. An operator outage or device issue can also explain it: this sign alone does not confirm a SIM swap.

  2. An unexpected operator notification

    An unrequested SIM change, eSIM activation or porting request is a warning. Verify through the official app or a known contact without following a link in a suspicious notification.

  3. Unusual account resets

    Unexpected login alerts, recovery requests or sign-outs from Microsoft 365, Google Workspace or banking services strengthen suspicion, especially alongside loss of mobile service.

Cross-check the evidence before drawing conclusions

  1. Record events and times

    Record when service was lost, operator alerts and account notifications. An outage alone is not confirmation. Several unusual events together strengthen suspicion but do not replace the operator’s investigation.

  2. Verify through an independent channel

    From another phone, use a known official number. Ask whether a SIM, eSIM or porting request was activated without consent and how to block the operation and recover the line. Do not follow a suspicious alert’s link.

  3. Assess accounts relying on the number

    Identify email, cloud and financial accounts using the number for sign-in or recovery. SecurCheck helps organise reported signs and priority actions; never provide passwords, text-message codes or recovery codes.

3. How to protect yourself and strengthen 2FA

  1. Reduce SMS dependency, including recovery

    With IT, inventory accounts and recovery methods. Prefer passkeys or FIDO2/WebAuthn keys where supported. An app generating codes avoids SMS delivery, but those codes remain vulnerable to phishing. Enable and test an alternative before removing SMS: do not disable all MFA while awaiting migration.

  2. Use your operator’s available safeguards

    Ask about safeguards against unauthorised SIM changes and porting: account PINs, stronger verification or locks, depending on the operator. Secure the customer account too. The SIM card PIN protects local use; it does not by itself prevent fraudulent remote replacement.

  3. Limit public information and prepare recovery

    Reduce unnecessary exposure of mobile numbers and personal details on social networks or directories. Store recovery codes securely and prepare a backup method independent of the line. At work, document emergency contacts.

4. What to do if you suspect a SIM swap

Immediately contact the operator from another phone through an official number to investigate and block an unauthorised transfer. Notify IT for a work account. From a trusted device, secure your primary email, review sessions and recovery methods, then sensitive accounts. Contact your bank if banking access or transactions are affected.

Do not wait for a tool result before reporting. SecurCheck does not block the line, change passwords or certify the absence of compromise.

Do not make SMS your only fallback

Consistent SIM & 2FA protection combines robust authentication, secure recovery and a prompt response to alerts. These measures reduce takeover risk without guaranteeing protection against every attack.

Deploy SecurCheck Business to support your teams

Further reading