PriChat
DE Open app

20 July 2026Security6 min read

SIM swapping: how attackers take over accounts via your number

Whoever takes over your phone number receives the SMS codes for your most important accounts. How SIM swapping works, how to spot it, and what helps against it.

Imagine your phone showing "no service" in the middle of the day. No call goes out, no text comes in. That can be a simple outage. It can also mean that someone else is using your phone number right now, receiving the SMS codes that reset your email account and your online banking. This scam is called SIM swapping, and it works without your phone ever being hacked.

What happens in a SIM swap

Your number is not glued to your SIM card. Your mobile carrier can move it to a new card or an eSIM at any time, for example when you lose your phone. That perfectly normal service is exactly what attackers abuse. The FBI describes three routes: criminals impersonate you and get the carrier to move your number to their SIM card. They pay carrier employees to make the switch. Or they use phishing to plant malware inside the carrier's systems.

A fourth route often needs no phone call at all: attackers phish your login for your carrier's customer portal and order a new SIM or eSIM themselves. Switzerland's national cyber security centre NCSC describes exactly this in a real case. From that moment on, all calls and texts go to the criminals, and your device falls silent.

Why a phone number is so valuable

The real damage does not happen at the carrier, but everywhere your number serves as a security anchor. Many services send password reset codes by SMS, and banks use SMS-based transaction codes. Germany's federal data protection commissioner, the privacy regulator for telecom providers, considers SIM swapping particularly dangerous when the mobile number acts as an access factor for online services through such schemes. The NCSC puts it plainly: once the number is taken over, the attackers have access to all accounts tied to it.

FBI figures show how big the business is. From January 2018 to December 2020, the FBI received 320 complaints about SIM swapping, with losses of roughly 12 million US dollars. In 2021 alone, there were 1,611 complaints with losses of more than 68 million US dollars. And those are only the cases that were reported to the FBI.

A 2020 Princeton University study showed how low the bar was for a long time: the researchers tested the authentication challenges of five US prepaid carriers, and at all five those challenges could easily be subverted. Of more than 140 websites with phone-based sign-in that they examined, 17 could be taken over through a SIM swap alone. The study later fed into stricter rules by the US regulator FCC.

And Germany? In early 2022 the big German carriers told heise they were seeing hardly any SIM swapping cases any more, or none for years, thanks to tightened security procedures, and the Federal Criminal Police Office saw no major relevance at the time either, partly because banks had moved from SMS codes to app-based methods. That is good news, but not a free pass: the portal variant built on phished credentials does not depend on your carrier's hotline, it depends on you.

How to recognise an attack

  • Your phone loses service in a place where you normally have coverage, and a restart changes nothing.
  • You can no longer send or receive texts, and calls and mobile data stop working.
  • You are suddenly locked out of your email or other accounts.
  • Your carrier notifies you about a SIM change or an eSIM order you never requested.

Speed matters here, but stay calm: call your carrier from another device and have the new SIM blocked. Then change the passwords of your most important accounts, starting with email, and check your bank statements. If anything looks off, contact your bank immediately.

How to protect yourself

  • Add extra protection to your carrier account. The Association of German Banks recommends setting up a PIN or a security question with your carrier. That way, knowing your personal details alone is not enough.
  • Replace SMS codes wherever you can. The FBI recommends strong methods such as authenticator apps, hardware security keys or biometrics. Every account that no longer receives its codes by SMS is worthless to a SIM swapper.
  • Enable notifications for SIM changes if your carrier offers them. That way you learn about the attack before the criminals are done.
  • Do not show off what you own. The FBI explicitly advises against advertising cryptocurrency holdings or other assets on social media. Anyone who looks like a worthwhile target is more likely to be attacked.
  • Distrust messages in your carrier's name. The portal variant of the attack almost always starts with a phishing message.
The one thing to remember

Your phone number is a master key as long as services send security codes to it by SMS. Treat it accordingly: hand it out as little as possible, and replace it with an authenticator app or a passkey for accounts that matter.

What this has to do with PriChat

Honestly: a SIM swap usually targets your bank account, your email or your crypto wallet, not your messenger. But many messengers are tied to a phone number, which means your account there also depends on your carrier and its processes.

At PriChat this attack surface does not exist, because there simply is no number. You register with a username and a password, and we never send codes by SMS. Someone who hijacks your phone number has no leverage over your PriChat account at all. Just as honestly: this does not help against a phished password. For that we offer optional two-factor sign-in with an authenticator app, and passkeys. But a SIM swap on its own opens no door here.

← Back to the guide

Ready?

Chat privately, no explanations needed.

Get started for free