One day your phone shows 'No Service' forever: a criminal just convinced your carrier to move your number to THEIR SIM, and every SMS verification code now belongs to them.
Updated August 09, 2026, after a fresh review, with updated visuals and links.
It's the attack behind emptied bank accounts and stolen Instagram handles. The defenses are specific, cheap, and take twenty minutes.

What you'll need
- Your carrier account
- Your account passwords
- Twenty minutes
The steps, start to finish
- Understand the mechanic first. The attacker phones your carrier, pretends to be you with leaked personal data, answers weak security questions, and requests a SIM replacement. Your number moves to their chip, and Voila: every 'text me the code' login protection reports to the enemy.
- Set a carrier PIN or passcode today. Call your carrier or use their app: set a verbal passcode/port out PIN that customer service must require before ANY account change. This single step defeats most attempts, and it costs nothing.
- Move important 2FA off SMS. Banks, email and social accounts should prefer authenticator apps (codes generated on your device travel nowhere) or passkeys. Audit: Settings, Security, 2FA on each critical account, switch from SMS to app wherever offered.
- Fortify the accounts that reset everything. Your email account is the nuclear option: unique password, authenticator 2FA, recovery options current. If your number is the only recovery path, fixing that is the single most valuable action on this page.
- Know the emergency response drill. Sudden 'No Service' indoors with full signal history? Contact the carrier IMMEDIATELY from another line and freeze the account, then change email and banking passwords from a clean device. Hours decide outcomes in SIM swap events.

Good habits to keep
- The less personal data online, the harder the impersonation: old addresses and pet names still answer call center questions.
- Ask your carrier specifically for a 'port freeze' or 'number lock', several offer it on request beyond the standard PIN.
- Watch the early signs: unsolicited 'your port request is processing' texts arrive hours before the outage, act on them instantly.
Pitfalls worth skipping
- Assuming 'it won't happen to me': targets are often ordinary people selected by leaked data, not just crypto millionaires.
- Using SMS 2FA for your email while worrying about SIM swaps is locking the windows and leaving the door wide open.
FAQ
Are eSIMs safer against swapping?
Marginally: eSIM transfers still pass through carrier support, the PIN and port freeze defenses matter the same. The weak point is the account, not the card technology.
How common is this really?
Carrier regulators log thousands of cases yearly and the trend grows with every data breach fueling the answers to security questions. Twenty minutes of prevention is absurdly good math.
Keep reading
- How to Spot a Phishing Email in 10 Seconds (The 5 Checks That Catch Them All)
- How to Install a Video Doorbell (Wired or Battery, Both Explained)
- What Are Passkeys and How to Start Using Them Today
That covers it
Carrier PIN set, port freeze on, 2FA off SMS, email fortress sealed. Let the next attacker find an easier door.