SIM SWAPPING · 2FA
How to detect SIM swapping and secure your two-factor authentication (2FA)
Unexpected loss of mobile service followed by a SIM-change alert or account resets warrants a prompt response. SIM swapping redirects a number to a SIM or eSIM controlled by a fraudster. Accounts using that number for codes or recovery may then be exposed.
Use this guide to compare warning signs, prepare a report to your operator and strengthen SIM & 2FA protection. A SIM swapping detector supports assessment; only the operator can check changes made to your line. If takeover is suspected, contact them without waiting for an analysis result.
1. How SIM swapping works
Gathering information
An attacker may gather a target’s name, date of birth, address or operator from public sources, phishing or leaked data. This can support impersonation but does not always suffice to obtain a transfer.
Requesting a replacement or transfer
The fraudster impersonates the subscriber and may claim a lost phone to request a SIM or eSIM they control. Takeover can also involve a compromised operator account, porting fraud or insider involvement: it is not limited to a call to customer support.
Redirecting communications
Once the transfer is activated, the victim may lose service while calls and texts to the number reach the attacker. SMS codes may be exploited if accounts accept them for sign-in or recovery. The transfer does not automatically expose every account, old message or the phone’s contents.
2. Warning signs of mobile-line takeover
Unexplained loss of service
“No service” or “Emergency calls only” in a normally covered area deserves checking. An operator outage or device issue can also explain it: this sign alone does not confirm a SIM swap.
An unexpected operator notification
An unrequested SIM change, eSIM activation or porting request is a warning. Verify through the official app or a known contact without following a link in a suspicious notification.
Unusual account resets
Unexpected login alerts, recovery requests or sign-outs from Microsoft 365, Google Workspace or banking services strengthen suspicion, especially alongside loss of mobile service.
Cross-check the evidence before drawing conclusions
Record events and times
Record when service was lost, operator alerts and account notifications. An outage alone is not confirmation. Several unusual events together strengthen suspicion but do not replace the operator’s investigation.
Verify through an independent channel
From another phone, use a known official number. Ask whether a SIM, eSIM or porting request was activated without consent and how to block the operation and recover the line. Do not follow a suspicious alert’s link.
Assess accounts relying on the number
Identify email, cloud and financial accounts using the number for sign-in or recovery. SecurCheck helps organise reported signs and priority actions; never provide passwords, text-message codes or recovery codes.
3. How to protect yourself and strengthen 2FA
Reduce SMS dependency, including recovery
With IT, inventory accounts and recovery methods. Prefer passkeys or FIDO2/WebAuthn keys where supported. An app generating codes avoids SMS delivery, but those codes remain vulnerable to phishing. Enable and test an alternative before removing SMS: do not disable all MFA while awaiting migration.
Use your operator’s available safeguards
Ask about safeguards against unauthorised SIM changes and porting: account PINs, stronger verification or locks, depending on the operator. Secure the customer account too. The SIM card PIN protects local use; it does not by itself prevent fraudulent remote replacement.
Limit public information and prepare recovery
Reduce unnecessary exposure of mobile numbers and personal details on social networks or directories. Store recovery codes securely and prepare a backup method independent of the line. At work, document emergency contacts.
4. What to do if you suspect a SIM swap
Immediately contact the operator from another phone through an official number to investigate and block an unauthorised transfer. Notify IT for a work account. From a trusted device, secure your primary email, review sessions and recovery methods, then sensitive accounts. Contact your bank if banking access or transactions are affected.
Do not wait for a tool result before reporting. SecurCheck does not block the line, change passwords or certify the absence of compromise.
Do not make SMS your only fallback
Consistent SIM & 2FA protection combines robust authentication, secure recovery and a prompt response to alerts. These measures reduce takeover risk without guaranteeing protection against every attack.
Deploy SecurCheck Business to support your teams