What is a SIM swap attack?
A SIM swap attack happens when a scammer convinces your mobile carrier to move your phone number onto a SIM card they control. Once that happens, they receive your calls and text messages — including the SMS codes used for two-factor authentication (2FA) on your bank, email, and crypto accounts. From there, they can reset passwords, bypass 2FA prompts, and lock you out of accounts within minutes.
This isn't a rare, exotic attack. It's one of the most effective account-takeover methods precisely because it doesn't require hacking your device at all — it exploits weaknesses in carrier customer support processes and your own account settings.
The six factors that determine your exposure
Not everyone is equally vulnerable. Your actual risk comes down to a handful of concrete, checkable factors:
- SMS-based 2FA on critical accounts. If your bank, primary email, or crypto exchange still uses text-message codes as your only second factor, a successful SIM swap gives an attacker everything they need.
- No carrier account PIN. Most carriers let you set a PIN or passcode that must be provided before any account changes — including SIM swaps. Without it, a rep can sometimes be socially engineered into approving the swap with just your name and address.
- No port-out protection. This is a dedicated, carrier-side PIN specifically for number transfers, separate from your general account PIN. It's the single strongest technical defense against SIM swapping, and it's usually free — but rarely enabled by default.
- No authenticator app or hardware key. App-generated codes (like Google Authenticator or Authy) and hardware keys (like a YubiKey) never travel over the phone network, so they simply cannot be intercepted by a SIM swap.
- A publicly listed phone number. Attackers need some personal information to convincingly impersonate you to a carrier. A number that's easy to find on social media, data-broker sites, or public records makes that first step trivial.
- No SIM-change alerts. Without carrier notifications, a swap can happen silently. Your first sign of trouble might just be losing cell signal entirely — by which point account takeovers may already be underway.
How to actually reduce your risk
Start with the highest-impact, lowest-effort fix: move every critical account off SMS-based 2FA and onto an authenticator app or hardware key. This alone neutralizes the entire point of a SIM swap for those accounts, since the attacker gains control of your number but not your 2FA codes.
Next, call your carrier and ask specifically for a port-out protection PIN or number-transfer PIN — not just a general account PIN, which is often weaker or already known to customer service scripts. Many carriers also let you enable proactive SIM-change alerts sent to a secondary email, so you catch a swap attempt the moment it starts rather than after it succeeds.
Why a checklist beats a mental review
It's easy to assume you're probably fine without actually walking through each factor. A structured, weighted checklist forces you to confront the specific gaps in your setup — and prioritizes them, so you fix the highest-impact issue first instead of getting overwhelmed. Running through all six factors takes about two minutes and can be the difference between a blocked attack attempt and a drained bank account.
Frequently Asked Questions
A SIM swap attack is when someone tricks your mobile carrier into transferring your phone number to a SIM card they control, letting them intercept your calls and SMS 2FA codes. It's a leading method for taking over bank, email, and crypto accounts, and it can happen without any malware ever touching your device.
Yes — the SIM Swap Attack Risk Checklist walks through six weighted risk factors (SMS 2FA use, carrier PIN, port-out protection, authenticator app usage, number visibility, and SIM-change alerts) and gives you a live 0-100 risk score with prioritized fixes. It's a one-time $4.99 purchase — no subscription, no account required.
No. The tool runs entirely inside your browser using local JavaScript. Nothing you check or type is transmitted, logged, or stored — there's no server component at all.
Move your critical accounts (primary email, bank, crypto exchange) off SMS-based two-factor authentication and onto an authenticator app or hardware security key. That one change removes the main incentive for an attacker to SIM-swap you in the first place.
No. Every checklist item includes a plain-language explanation of why it matters, and the results are ranked so you know exactly which gap to close first — no technical background required.