SIM SWAPPING · 2FA
What is SIM swapping and how can you protect yourself? The 2FA guide
Access security extends beyond servers. An employee’s or executive’s mobile line can serve as an account recovery route. SIM swapping transfers that line to another SIM or eSIM, potentially exposing codes received by text.
Learn how the attack works, recognise warning signs with a SIM swapping detector and strengthen SIM & 2FA protection. An assessment guides checks; it does not replace confirmation from the operator.
1. How SIM swapping works
Gathering information
An attacker may gather a target’s name, date of birth, address or operator from public sources, phishing or leaked data. This can support impersonation but does not always suffice to obtain a transfer.
Requesting a replacement or transfer
The fraudster impersonates the subscriber and may claim a lost phone to request a SIM or eSIM they control. Takeover can also involve a compromised operator account, porting fraud or insider involvement: it is not limited to a call to customer support.
Redirecting communications
Once the transfer is activated, the victim may lose service while calls and texts to the number reach the attacker. SMS codes may be exploited if accounts accept them for sign-in or recovery. The transfer does not automatically expose every account, old message or the phone’s contents.
2. Warning signs of mobile-line takeover
Unexplained loss of service
“No service” or “Emergency calls only” in a normally covered area deserves checking. An operator outage or device issue can also explain it: this sign alone does not confirm a SIM swap.
An unexpected operator notification
An unrequested SIM change, eSIM activation or porting request is a warning. Verify through the official app or a known contact without following a link in a suspicious notification.
Unusual account resets
Unexpected login alerts, recovery requests or sign-outs from Microsoft 365, Google Workspace or banking services strengthen suspicion, especially alongside loss of mobile service.
3. How to protect yourself and strengthen 2FA
Reduce SMS dependency, including recovery
With IT, inventory accounts and recovery methods. Prefer passkeys or FIDO2/WebAuthn keys where supported. An app generating codes avoids SMS delivery, but those codes remain vulnerable to phishing. Enable and test an alternative before removing SMS: do not disable all MFA while awaiting migration.
Use your operator’s available safeguards
Ask about safeguards against unauthorised SIM changes and porting: account PINs, stronger verification or locks, depending on the operator. Secure the customer account too. The SIM card PIN protects local use; it does not by itself prevent fraudulent remote replacement.
Limit public information and prepare recovery
Reduce unnecessary exposure of mobile numbers and personal details on social networks or directories. Store recovery codes securely and prepare a backup method independent of the line. At work, document emergency contacts.
4. What to do if you suspect a SIM swap
Immediately contact the operator from another phone through an official number to investigate and block an unauthorised transfer. Notify IT for a work account. From a trusted device, secure your primary email, review sessions and recovery methods, then sensitive accounts. Contact your bank if banking access or transactions are affected.
Do not wait for a tool result before reporting. SecurCheck does not block the line, change passwords or certify the absence of compromise.
Do not make SMS your only fallback
Consistent SIM & 2FA protection combines robust authentication, secure recovery and a prompt response to alerts. These measures reduce takeover risk without guaranteeing protection against every attack.
Deploy SecurCheck Business to support your teams