Avatier

MFA bypass

SIM swapping

Also called: SIM swap

SIM swapping is tricking or bribing a mobile carrier into moving a victim's phone number onto a SIM card the attacker controls. The attacker then receives the victim's calls and texts, including one-time codes and password reset messages, which lets them take over accounts that rely on the phone number for verification.

How it works

The attacker gathers the victim's personal details, then contacts the carrier or visits a store posing as the victim, sometimes with a fake ID or help from an insider. Once the number moves, the victim's phone loses service and the attacker requests password resets for email, financial and social media accounts tied to that number.

A real example

In February 2025 the Justice Department said a man pleaded guilty in connection with the January 2024 takeover of the US Securities and Exchange Commission's X account, which conspirators gained through an unauthorized SIM swap.

Source: Alabama Man Pleads Guilty in Connection with Securities and Exchange Commission X Account Hack — US Department of Justice, Office of Public Affairs, 2025-02-10

The Identity Attack Ledger holds 1 cited incident for mfa bypass in California breach filings (January 1, 2023 – August 14, 2026), each quoted from its filed letter.

How to stop it

Move accounts off SMS codes and phone-number recovery to passkeys or FIDO2 keys, which a SIM swap cannot intercept, and ask carriers for a port-out lock on important numbers.

Related terms

Threat actors that use it

Sources

  1. Alabama Man Pleads Guilty in Connection with Securities and Exchange Commission X Account Hack — US Department of Justice, Office of Public Affairs, 2025-02-10

Last reviewed Oct 2, 2026