untrappable

SIM swap scam: how your number gets stolen

Editorially reviewed · Last updated July 29, 2026

Yes — this is a scam. Your carrier's fraud team will never phone you and ask for your account PIN — that PIN is the one thing protecting your number.

Incoming call
Spam Risk
(866) 555-0138
maybe: Wireless Fraud Dept
Voicemail transcript

Hi, I'm calling from the fraud prevention team about your wireless account. We've flagged a port-out request on your line from another state and we can cancel it, but I need to verify you first. Can you confirm your account PIN and the last four of your Social? If we don't cancel it in the next few minutes the transfer goes through.

The Phone call, as received

Other versions you might get: The same attack arrives without any call at all. Scammers walk into a store or phone the carrier themselves, posing as you with details bought from a data breach — the FBI calls that social engineering, and it also documents criminals paying off carrier employees to make the swap from the inside. A softer version is a text or email asking you to "confirm your account" on a look-alike carrier login page, harvesting the PIN that way. You may never hear from anyone: the first sign is your phone going quiet.

What to do right now

  1. Hang up and call your carrier yourself, on the number printed on your bill or in the carrier's own app. The FCC's rule for this scam is blunt: if someone calls or texts asking for personal information, don't give it — hang up and call the business on a number you trust.
  2. Add a port-out PIN or password to the account. The FCC's first protective step is to contact your phone company and ask about adding one if you don't already have it. Since 2024, FCC rules also require wireless providers to authenticate you securely before moving your number and to notify you immediately whenever a SIM change or port-out is requested — so don't ignore that notification if it arrives.
  3. Get your codes off SMS. The FBI recommends strong multi-factor authentication — biometrics, a physical security token, or a standalone authenticator app — precisely because text-message codes land on whichever device holds the number. Start with your email and bank; email is the account that resets everything else.
  4. Stop feeding the profile. The FBI says not to advertise financial assets or crypto holdings online, and the FCC says to keep the answers scammers need off social media: the last four of your Social, your date of birth, your car, your pet's name, your mother's maiden name.
  5. If your phone has already gone dark: contact your carrier immediately to get the number back, then change the passwords on your email and financial accounts, tell your banks to watch for suspicious logins and transfers, file a police report, and place a fraud alert with one of the three credit bureaus — Equifax, Experian or TransUnion — which will share it with the other two. Report it at [ic3.gov](https://www.ic3.gov) and file a complaint at [consumercomplaints.fcc.gov](https://consumercomplaints.fcc.gov).

How to make sure it never bites you

This attack runs on details about you that are already for sale — address, birth date, the last four of your Social. Thinning out that profile is the durable fix: here's how.

Untrappable · Public service advisory

Stop the next one at the source

You got this because your details are on lists that get bought, sold, and leaked. You can't unspill that, but you can make it useless to a scammer. Start with the free steps — they do most of the work.

Optional — if you'd rather it was handled for you

If you'd rather have it watched for you, an identity-protection service monitors your accounts, SSN, and the dark web, warns you the moment something new appears, and helps you recover if someone gets through.

See identity protection

Affiliate link — we may earn a commission at no extra cost to you. It never changes our verdicts. Why we can still be trusted.

Keep this · forward it to someone who needs it

Frequently asked

My phone suddenly says No Service — have I been SIM swapped?
Maybe, and it's worth ruling out fast. The FCC says loss of service — your phone going dark or only allowing 911 calls — is typically the first sign a port-out has happened, and that starts a race: the attacker has your texts and calls and is resetting the credentials on your financial and social accounts before you notice. Rule out the ordinary causes first (airplane mode, a carrier outage, a loose SIM tray), then use another phone or Wi-Fi to call your carrier and ask whether a SIM change or port-out was requested on your line. If the answer is yes, treat every account tied to that number as compromised.
What is a SIM swap scam, exactly?
It's the theft of your phone number rather than your phone. The FBI describes it as criminals targeting mobile carriers to move your number onto a SIM card they control — by impersonating you with personal details they've gathered, by phishing carrier staff, or by paying an insider. Once the number moves, your calls and texts divert to their device, and they use "forgot password" and account-recovery flows plus SMS two-factor codes to take over your email, bank and crypto accounts. Port-out fraud is the same theft done through a different door: instead of a new SIM at your carrier, they open an account at a different carrier and have your number ported to it.
Does an eSIM protect me from SIM swapping?
Partly, and not in the way that matters most. The FCC notes that eSIM cards are hardwired inside newer phones and can't be physically removed, which eliminates some of the risk of a physical SIM swap — but it adds that port-out scams remain a security concern. The attack that empties bank accounts is a paperwork attack, not a hardware one: someone convinces a carrier that they're you. An eSIM doesn't stop that. A port-out PIN and non-SMS two-factor do.
How do I stop a SIM swap before it happens?
Three things, in order. First, call your carrier and set a port-out PIN or password on the account — the FCC lists this as the proactive step, and it's the credential the whole scam is built to extract. Second, move two-factor authentication off SMS: the FBI recommends biometrics, a physical security token, or a standalone authenticator app, and email plus banking are where to start. Third, turn on both email and text alerts for financial accounts, so a change you didn't make reaches you somewhere other than the phone number under attack. And never give account details to someone who called you, however convincing the fraud-department story is.
I've been SIM swapped — what do I do first?
Call your carrier from any other phone and get the number back; nothing else works until you control the number again. Then, in the FBI's and FCC's order: change the passwords on your online accounts starting with email, contact your banks and card issuers to flag suspicious logins and transactions, file a police report, and place a fraud alert on your credit reports at Equifax, Experian or TransUnion — the one you notify tells the other two. Report it to the FBI at ic3.gov and file a free complaint with the FCC at consumercomplaints.fcc.gov. Keep a written timeline as you go; your bank will ask for it.

Sources

A public service

Help protect someone else

Scams spread because people stay quiet about them. If this could have fooled you, it can fool someone you know — a parent, a friend, the family group chat. Passing it on is the easiest good thing you'll do today. It's safe to forward, and stands on its own as a record for a bank or the police.