SIM Swap Attack Prevention: The Number Is the Weak Link, Not the Password
A SIM swap does not break your phone and does not break your password. It persuades your carrier to move your number onto a card someone else holds. From that moment every code sent by text arrives on their device, and your phone quietly loses signal.
The attack is unusual in one respect that decides how you defend against it: the weak point is not on your device at all. It is a support agent, at a company you do not control, being talked into a routine action.
Why your password is not the target
Most account recoveries end with a text message. That makes the number a master key that opens accounts without knowing any of their passwords: request a reset, receive the code, take the account.
The attacker does not need to beat your security. They need to beat your carrier’s identity check, which is usually a date of birth, an address and a few recent numbers you called.
That is why a longer password changes nothing here, and why the defence lives in two places: the carrier, and the kind of second factor you use.

One SIM card in its tray on a flat red background. The object is trivial and replaceable, which is exactly the problem: your number is not tied to it, and a carrier can move that number to another card in a few minutes.
The one setting that does most of the work
Ask your carrier for a port-out PIN, a transfer lock, or whatever they call an account protection code. Every major operator has one, it is free, and it is rarely enabled by default.
It changes the attack from “convince an agent you are the customer” to “produce a secret you do not have”. That is a different problem, and a much harder one.
Two details make or break it. Choose a code that is not derivable from your public life: not a birth year, not part of your number. And check that it applies to porting the number out, not only to changing your tariff, because those are sometimes two separate settings.
Move your second factor off SMS
This is the structural fix, and it removes the payoff rather than the method.
An authenticator application generates codes on the device itself. Nothing travels through the network, so a stolen number receives nothing useful.
A hardware key goes further: it also proves which site is asking, which stops the phishing that often precedes a swap.
⚠️ Do the migration in the right order. Add the new method, confirm it works, save the recovery codes offline, and only then remove the phone number. Removing first is how people lock themselves out of their own accounts.
And check the recovery path, not just the login. An account protected by an authenticator can still be reset by SMS if the number is left as a backup. The number has to leave the recovery options too, or the front door is locked while the back one stays open.
The signal to recognise, and the ten minutes that follow
Your phone loses service and does not come back. Not one bar: no service, no calls, no data, while other devices on the same network work normally.
That is worth treating as an attack until proven otherwise, because the window between the swap and the first account takeover is short.
Call your carrier from another line, immediately, and say the number may have been ported without authorisation. Then, from a device that still has its own connection, change the password on your email account first: it is the recovery address for everything else, and whoever controls it controls the rest.
This is also the moment where the difference between the two kinds of second factor becomes concrete, and two-factor authentication is worth reading before you need it rather than during.
What does not help
A PIN on the SIM card itself. It protects the physical card in your phone. The attack does not touch that card, it issues a new one.
A stronger password. The attack routes around it entirely.
Being unimportant. Swaps are run at scale against ordinary accounts, and a phone number is worth taking whether or not anyone has heard of you. The same reasoning applies to every threat worth ranking honestly, which is what a threat model is for.
The short version
- The attacker targets your carrier, not your phone or your password.
- Set a port-out PIN or transfer lock. It is free, rarely on by default, and does most of the work.
- Move two-factor off SMS, to an authenticator application or a hardware key.
- Remove the number from RECOVERY too, not only from login.
- Sudden total loss of service is the signal. Call the carrier from another line, then secure your email first.