SIM swapping is the hack where a criminal convinces your carrier to move your number to their phone, then resets every account that texts you codes. Bank, email, crypto: the whole identity collapses through one phone call you never made.
Updated August 15, 2026, after a fresh review, with updated visuals and links.
The defense takes thirty minutes across your carrier and email settings. Here's the complete lockdown, in the order that matters.
Get this ready first
- Your carrier account access
- Your main email account access

The how to part
1. Set the carrier PIN or port-out lock
Call your carrier or use their app: set a numeric account PIN that support must request before any SIM change, and enable any 'number lock' or port-out protection offered (major carriers all added one after the fraud wave). Record the PIN in your password manager, not a sticky note.
2. Move two-factor off SMS where possible
Email, banking and password managers all offer authenticator-app or passkey options: switch them. SMS codes are exactly what SIM swaps steal; every account moved to app-based codes removes one hostage your number holds.
3. Harden the email that resets everything
Your primary email is the master key: strong unique password, app-based 2FA or passkeys, and check recovery options so a phone number isn't the only way back in. If email falls, everything follows; defend it accordingly.
4. Teach the household the tell
The attack's signature: your phone suddenly shows 'no service' for no reason. The correct response is immediate, not tomorrow: call the carrier from another line, freeze financial accounts, change the email password. Minutes decide outcomes.
5. Shave your public-data trail
SIM swaps start with persuading support you're you: your birthday, carrier, and 'mother's maiden name'-style answers scraped from social media arm the attacker. Privacy settings and data-broker opt-outs (or services that automate them) lower the ammunition supply.
6. Consider the quiet upgrade: a separate number
High-value targets' classic move: banks and email recovery tied to a number your public life never sees (an eSIM line costs little). Public-facing number handles life; the private one guards the vault.

Tips that actually help
- Authenticator backups matter too: export or cloud-sync your authenticator so losing the phone doesn't lock you out during recovery.
- Carrier store visits: photo ID on your account profile helps in-person fraud checks at the counter.
- After any unexplained 'no service': also check email filters for hidden forwarding rules the attacker may have planted in the window.
Keep reading
- Browser Extensions: Which Are Safe, Which Spy on You, and the 5-Minute Security Audit
- Random Password Generator: Strong Passwords in One Click (Free Tool)
- Password Strength Checker: How Long Would Yours Survive? (Free Tool)
Carrier PIN, authenticator apps, hardened email, and a family that knows the tell: thirty minutes, and your number stops being your weakest link.