How SIM swap fraud works

  1. Criminal targets you. Through data breach (your phone number + identity info on a leaked database), social media research (your full name, DOB, address), or phishing.
  2. Criminal contacts your carrier. Posing as you. Says "I've lost my phone and my SIM is damaged. I need to activate a new SIM on the same number."
  3. Carrier asks security questions. Criminal provides answers from their dossier (often correct given prior data harvesting).
  4. Carrier approves swap. Activates your number on the criminal's SIM card. Your SIM becomes inactive within minutes.
  5. Your phone stops receiving signal. "No service" indicator. You can't make calls or send SMS.
  6. Criminal receives your SMS 2FA codes. Now they can authenticate as you on banking apps, email, crypto exchanges, social media — bypassing 2FA via SMS.
  7. Account takeover and asset draining. Money out of bank accounts, crypto exchange withdrawals, social media takeover, password resets across services using your email.

The 5 warning signs

  1. Your phone loses signal suddenly with no obvious reason (no network outage, no carrier issue, full battery, same location as before).
  2. You can't make calls or send SMS even though signal display looks normal.
  3. You receive an unexpected SMS or email confirming SIM activation or account change. This may come to your email even after the SMS-to-phone breaks.
  4. Banking app suddenly logs out and asks for re-verification (criminal triggered password reset).
  5. Friends report receiving strange messages from your number that you didn't send.

Any one of these warrants immediate carrier contact from another phone. Multiple together is near-certain SIM swap.

Immediate response — what to do if you suspect SIM swap right now

Act in the next 30 minutes if possible. Each hour reduces recovery odds.

Step 1 — Call your carrier from another phone

  • EE: 0800 956 6000
  • O2: 0800 977 7337
  • Three: 0333 338 1001
  • Vodafone: 03333 040191
  • Tesco / Sky / GiffGaff: number on bill or carrier's website

Tell them: "I suspect SIM-swap fraud on my account. My phone has lost signal. Please immediately suspend any new SIM activated on my number and arrange reissue to me at a physical store with ID verification."

Step 2 — From another device, change critical passwords

While carrier deals with the SIM, log in from a computer or tablet you trust + change passwords on, in order of priority:

  1. Email (Gmail / Outlook / Yahoo) — this is the recovery channel for everything else
  2. Banking apps + change to authenticator-app 2FA where supported
  3. Crypto exchanges if applicable
  4. Social media (Twitter / Facebook / Instagram / LinkedIn) — change passwords + revoke active sessions
  5. Password manager (1Password / Bitwarden / Dashlane) — top priority if criminal got into it

Step 3 — Call your bank fraud line

Even if no unauthorised transactions yet visible, alert the bank. They can flag the account for closer monitoring + assist with PSR claim if money has been taken. UK bank fraud lines: see bank fraud directory.

Step 4 — Document + report

  1. Note the exact time your phone lost signal.
  2. Screenshot any unauthorised emails / SMS / app notifications you received.
  3. File Report Fraud report at reportfraud.police.uk.
  4. Start PSR claim if money taken via UK bank transfer.
  5. Add CIFAS Protective Registration — SIM-swap victims are frequently re-targeted.

6-layer prevention setup

Layer 1 — Carrier port-out PIN

Call your carrier and ask for a port-out PIN or account-security PIN. This must be quoted before any SIM swap or port-out can proceed. Free. Stops the most common social-engineering path.

Layer 2 — Authenticator-app 2FA

Move SMS-based 2FA to authenticator app for: email, banking, crypto, social media. Apps: Google Authenticator, Microsoft Authenticator, Authy, Aegis (Android), Raivo (iOS). Authenticator codes are generated locally on your device — can't be intercepted by SIM swap.

Layer 3 — Hardware-key 2FA for high-value accounts

YubiKey (£35-£50) or Google Titan key. For your main bank, pension, crypto exchanges where supported. Hardware key must be physically inserted; defeats SIM swap entirely.

Layer 4 — Phone number hygiene

Remove your mobile number from public social-media bios. Don't post it on contact pages of websites unless necessary. Reduces criminal targeting data.

Layer 5 — Vigilant about carrier-account phishing

Never enter carrier-account credentials via a link in a message — go to ee.co.uk / o2.co.uk / three.co.uk / vodafone.co.uk directly.

Layer 6 — Periodic audit

Once per quarter: call your carrier and ask "have any SIM-swap or account-change requests been logged on my account in the last 3 months?". Early detection of attempts that didn't yet succeed.

Recovery routes if money was lost

  • UK bank transfers: PSR Mandatory Reimbursement Scheme. PSR claim wizard.
  • Carrier liability: if the carrier approved the SIM swap without proper identity checks, they may be liable. Complaints process via Communications Ombudsman at commsombudsman.org.
  • Crypto exchanges: harder. They may dispute claiming you authorised the transactions. Specialist solicitor advice (TLW, CEL, Hugh James) on no-win-no-fee.
  • FSCS: covers FCA-authorised banks if bank fails to operate within their security duty; bank-specific claim path.

Frequently asked questions

What is SIM swap fraud?

SIM swap fraud is when criminals convince your mobile carrier to transfer your phone number to a SIM card they control. Once swapped, your number is theirs — your phone stops working, all SMS 2FA codes get sent to the criminal's device, and they can intercept calls. They use this to defeat 2FA on banking apps, email, crypto exchanges, and social media — taking over accounts and draining funds. UK Finance reports a 250% increase in SIM-swap-related fraud 2022-2024.

How do criminals execute the swap?

Three common methods. (1) Social engineering — criminal calls your carrier pretending to be you, claims phone lost/damaged, requests SIM activation on a new device. Provides plausible answers to security questions (often gathered from data breaches or social media). (2) Insider corruption — bribed carrier employee with access to SIM-swap tools executes the swap. Rare but documented. (3) Phishing — criminal phishes your carrier account credentials, logs in to your account online, and triggers a self-service SIM swap. UK carriers have tightened these processes since 2022 but social engineering remains the dominant method.

What are the warning signs?

Five immediate signs. (1) Your phone loses signal suddenly with no obvious reason (no network coverage issue, no carrier outage). (2) You can't make calls or send SMS even though you have full signal display. (3) You receive an unexpected SMS or email confirming SIM activation or account change. (4) Your banking app suddenly logs out and asks for re-verification. (5) Friends/colleagues say they've received strange messages from your number that you didn't send. Any one of these warrants immediate carrier contact — call from another phone.

What do I do if I suspect a SIM swap right now?

Act in the next 30 minutes if possible. (1) Call your carrier from another phone — EE: 150 from EE mobile or 0800 956 6000, O2: 202 or 0800 977 7337, Three: 333 or 0333 338 1001, Vodafone: 191 or 03333 040191. Tell them you suspect SIM-swap fraud. (2) Request immediate suspension of the suspicious SIM + reissue of your number to a new SIM you'll collect from a physical store. (3) From another device, log into your email (Gmail/Outlook/etc.) and change the password. (4) Log into your banking app and change passwords + alert the bank fraud line. (5) Log into crypto exchanges if you have any — same protocol. (6) Check what was accessed and what's been changed. (7) File Report Fraud report.

How can I prevent SIM swap fraud?

Six-layer defence. (1) Set a port-out PIN with your carrier — most UK carriers offer this; quote it before any account change. Call your carrier and ask for 'account port-out PIN'. (2) Use authenticator-app 2FA (Google Authenticator, Microsoft Authenticator, Authy) instead of SMS for banking, email, crypto, social media. Authenticator codes can't be intercepted by SIM swap. (3) For high-value accounts (main bank, pension, crypto): use hardware-key 2FA (YubiKey, Titan key) where supported. Defeats SIM swap completely. (4) Remove your phone number from social media bios and public posts — reduces criminal targeting data. (5) Be wary of phishing aimed at your carrier account — never enter carrier-account credentials via a link in a message. (6) Periodic check: ask your carrier whether any SIM-swap requests have been logged on your account.

Can I recover money lost to SIM-swap fraud?

Yes, multiple routes. (1) UK bank transfers covered by PSR Mandatory Reimbursement Scheme — qualifying claims refunded within 5 working days. (2) Carrier liability — if the carrier failed in their security duty (e.g., approved the SIM swap without proper identity checks), they may be liable for resulting losses. Communications Ombudsman handles these complaints. (3) Crypto exchange losses are harder — they may dispute liability claiming you 'authorised' the transactions via your number; specialist solicitor advice may help. (4) Account takeover at the email layer: notify all linked accounts; password resets where needed; consider CIFAS Protective Registration. (5) Report Fraud report at reportfraud.police.uk for criminal investigation reference. Time-critical: each hour after the swap reduces recovery odds.

Related scam guides