How can I protect myself against a SIM swap?

Your mobile number does a lot of quiet work. It receives the codes that log you in, the links that reset your passwords, and the alerts from your bank - so whoever controls your number can reach the accounts behind it. A SIM swap is the trick that hands them that control: someone persuades your mobile provider to move your number onto a SIM card they are holding. The reassuring part is that the defence is not complicated. A little setup, most of it done just once, turns your number into a far poorer target.

How a SIM swap works

It leans on persuasion far more than technology.

  • Groundwork. The attacker gathers a few facts about you - your name, date of birth, maybe part of an ID or account number. Most of this has been circulating since old data breaches.
  • The request. Posing as you, they contact your provider, say the handset was lost, and ask for the number to be moved to a new SIM.
  • The handover. If the provider is convinced, your service quietly stops working and your number begins arriving on their phone instead.

From there they receive whatever your number receives: login codes sent by text, password-reset links, bank notifications, and the recovery route into your email, cloud storage, and any crypto. Often the earliest sign is your own phone losing service for no obvious reason.

What you can do

These are roughly ordered by how much they help. If you only have fifteen minutes, the first three cover the most common attacks.

Lock your number with your provider

Most mobile providers let you add a lock that stops your number being transferred without extra checks. It goes by different names - port-out lock, number lock, account-takeover protection - and usually sits in the security or privacy area of your provider's app. Turning it on takes a couple of minutes. If you cannot find it, a search for your provider's name alongside "port-out lock" will point you straight to it.

Swap text-message codes for an authenticator app

A code that arrives by text can be read by anyone holding your number. An authenticator app keeps that code on your own device instead, out of a swapper's reach. The mainstream choices are painless to use: Google Authenticator and Microsoft Authenticator are both free and widely supported, and many password managers - 1Password and Bitwarden among them - can generate the same codes, so everything lives in one place. Move your important accounts across, starting with email and banking, and choose something that backs up securely so a new phone never locks you out.

Add a hardware key to the accounts that matter

For the accounts you genuinely cannot afford to lose - your main email, your password manager, and anything holding money - a hardware security key is the sturdiest lock there is. It is a small device you tap or plug in to prove it is really you, and it cannot be phished or SIM-swapped. The two best known are the YubiKey and Google's Titan key. They look expensive for a little slip of plastic and metal, but weighed against what they protect they are worth every cent - and it is a one-time purchase. Buy two and register both: carry one with you and keep the second at home as a backup, so losing one is never a lockout. For the key you carry, choose a model with a keyring loop and clip it to your keys with a small tracker attached (an AirTag or similar) - that way a misplaced key is quickly a found one rather than a quiet panic.

Get your number off the internet

Attackers often find your number on people-search and data-broker sites, in old social-media profiles, or in public records tied to a website you own. Many of those sites offer a way to opt out, even if it is tedious, and removal services can do the rounds for you if you would rather not chase them. What exists varies from country to country, so it is worth a search for the brokers that operate where you live. This one is ongoing rather than one-and-done, but it steadily shrinks how much an attacker can dig up.

Keep your real number private

Think of your real number like a spare house key: the fewer copies in circulation, the better. Keep it to the people who genuinely need it, and hand out a secondary or virtual number for deliveries, mailing lists, and sign-ups on sites you do not fully trust - if one of those ever leaks, you just retire it. This is also a good moment to take your number out of the apps that show it off. WhatsApp is rolling out usernames, so before long people will be able to reach you there without ever seeing your number - a fine reason to tuck it back out of sight once the option lands.

Freeze your credit

A stolen number can lead to accounts emptied and fresh credit taken out in someone else's name within hours. If you live somewhere that offers a credit freeze, it is a strong safeguard: it stops anyone opening new accounts in your name until you lift it, and you can lift it briefly whenever you genuinely need to borrow. In the United States it is free with the three main credit bureaus; elsewhere, it is worth checking what your country's credit agencies offer.

Set up a recovery email you never share

Create an email address that exists for one job: recovering your other accounts. Do not post it anywhere, do not sign up to anything with it, and give it a long, unique password and a hardware key of its own. When every other safeguard has failed, this quiet, unknown address is what you fall back on.

The system is starting to catch up

You are not the only line of defence any more. Some countries have begun tackling SIM swaps at the source - the provider - rather than leaving it all to you.

  • In Australia, the telecoms regulator (the ACMA) has required every provider since mid-2022 to run stronger, multi-factor identity checks before high-risk changes like a SIM swap - much as your bank does before it accepts that it is really you.
  • Telstra went further and began sharing a signal with banks that flags when a number has recently been swapped or ported, so the bank can ask for more proof before acting on a text-message code. Other Australian providers, Optus among them, are adopting the same network-level checks. It is advisory rather than a hard block, but it closes the very window attackers count on.
  • The approach is spreading. These provider-to-bank checks are being standardised internationally, so similar protection is arriving with carriers and banks elsewhere - the UK, US, Singapore and beyond. Wherever you are, expect this kind of check to reach you over time.

Australia is simply furthest along, which is why it makes the clearest example. None of this replaces the steps above - the rules are young and the coverage is patchy - but the ground is slowly shifting in your favour.

If your phone suddenly loses signal

Losing signal is almost always nothing - a tunnel, a rural stretch, a thick-walled building, or your provider simply having a bad afternoon. So there is no need to panic at the first missing bar. The pattern actually worth acting on is more particular: your phone shows no service in a place where you normally have full signal, the people beside you still have theirs, and restarting the phone does not bring it back. That combination can mean your number has been moved. If it does:

  1. Use another phone to contact your provider and ask whether your number was ported or a new SIM issued. Have them reverse it and lock the account.
  2. From a device that is still signed in, change your email and banking passwords first, and switch those accounts to app-based codes or a hardware key.
  3. Ask your bank to watch for fraud, and check that your email's recovery options have not been quietly changed.

If you only do one thing

Lock your number with your provider and put a hardware key on your main email. The lock buys you time; the key shuts the door. Neither is quite enough alone, which is why the pair is the real answer - and email is the place to begin, since nearly every other account is recovered through it.

Related: How can I tell if a message is a scam?

← All guides

General information, correct when last reviewed. Platforms and threats change - always confirm critical steps on the official source. Product names are used only to describe their features; Monkleton Labs is not affiliated with, or endorsed by, them. No ads, no affiliate links.