SIM swapping
Also called: SIM swap
SIM swapping is tricking or bribing a mobile carrier into moving a victim's phone number onto a SIM card the attacker controls. The attacker then receives the victim's calls and texts, including one-time codes and password reset messages, which lets them take over accounts that rely on the phone number for verification.
How it works
The attacker gathers the victim's personal details, then contacts the carrier or visits a store posing as the victim, sometimes with a fake ID or help from an insider. Once the number moves, the victim's phone loses service and the attacker requests password resets for email, financial and social media accounts tied to that number.
A real example
In February 2025 the Justice Department said a man pleaded guilty in connection with the January 2024 takeover of the US Securities and Exchange Commission's X account, which conspirators gained through an unauthorized SIM swap.
Source: Alabama Man Pleads Guilty in Connection with Securities and Exchange Commission X Account Hack — US Department of Justice, Office of Public Affairs, 2025-02-10
The Identity Attack Ledger holds 1 cited incident for mfa bypass in California breach filings (January 1, 2023 – August 14, 2026), each quoted from its filed letter.
How to stop it
Move accounts off SMS codes and phone-number recovery to passkeys or FIDO2 keys, which a SIM swap cannot intercept, and ask carriers for a port-out lock on important numbers.
Related terms
Threat actors that use it
- Scattered Spider
Profile with government sources
Sources
- Alabama Man Pleads Guilty in Connection with Securities and Exchange Commission X Account Hack — US Department of Justice, Office of Public Affairs, 2025-02-10
Last reviewed Oct 2, 2026