July 16, 2026
SIM-swap attacks: what they are and how to stop them
A SIM swap is one of the reasons security experts push people away from text-message 2FA. It's a surprisingly low-tech attack with high-stakes consequences.
How a SIM swap works
Your phone number isn't really tied to your phone — it's tied to a SIM record at your carrier. In a SIM swap, an attacker contacts your carrier, impersonates you (using personal details often gathered from data breaches or social media), and convinces them to move your number to a SIM they control.
The moment that happens:
- Your phone loses service.
- Every SMS 2FA code now arrives on the attacker's device.
- They start resetting passwords and draining accounts.
Why authenticator apps are immune
An authenticator app generates TOTP codes on your device itself. They're not tied to your phone number and never travel over the mobile network. Swap the SIM all you like — the codes stay on your phone. That's the core of why apps beat SMS.
How to protect yourself
- Move critical accounts off SMS 2FA and onto an authenticator app — especially email, banking, and crypto.
- Add a carrier PIN / port-freeze. Most carriers let you set a passcode that must be given before any SIM change.
- Share less online. The personal details attackers use to impersonate you often come from your own public posts.