CipherWatch All articles
Account Security

Hijacked in Seconds: The Growing Threat of Phone Number Takeovers and How to Fight Back

CipherWatch
Hijacked in Seconds: The Growing Threat of Phone Number Takeovers and How to Fight Back

Photo by Photo by User_Pascal on Unsplash on Unsplash

For most Americans, a smartphone is the master key to their digital life. It unlocks banking apps, receives login verification codes, and serves as the ultimate proof of identity when a forgotten password needs to be reset. That convenience, however, has created a single, fragile point of failure — and a thriving criminal economy has grown up around exploiting it.

Phone number hijacking, which encompasses tactics such as SIM swapping and the exploitation of aging telecom infrastructure, has become one of the most financially devastating forms of identity theft in the United States. The FBI's Internet Crime Complaint Center reported losses exceeding $68 million from SIM-swapping incidents in 2021 alone, a figure that security researchers widely consider an undercount given how rarely victims connect the attack to its root cause.

What SIM Swapping Actually Is

A SIM swap — sometimes called a SIM hijack or port-out scam — is, at its core, a social engineering attack directed not at the victim but at their wireless carrier. The attacker contacts a carrier's customer service department, either by phone or in person at a retail location, and impersonates the account holder. Armed with a handful of personal details — a name, address, last four digits of a Social Security number, or account PIN — the fraudster convinces a representative to transfer the victim's phone number to a new SIM card under the attacker's control.

Once that transfer is complete, the victim's phone goes dark. Calls and text messages — including every one-time passcode dispatched by a bank, brokerage, or email provider — route instead to the attacker's device. Within minutes, the criminal can trigger password resets on financial accounts and drain them before the legitimate owner realizes anything is wrong.

The attack exploits a fundamental asymmetry: carriers are incentivized to resolve customer service requests quickly, while the consequences of an erroneous transfer fall entirely on the account holder.

The SS7 Flaw Nobody Fixed

SIM swapping receives most of the public attention, but it is not the only route to phone number compromise. The Signaling System No. 7 — known as SS7 — is a protocol suite developed in 1975 that forms the backbone of global telephone routing. It was designed for a closed network of trusted operators. The modern internet is anything but closed.

Researchers first demonstrated publicly in 2014 that malicious actors with access to the SS7 network — a category that includes rogue telecom insiders, nation-state actors, and criminal groups that purchase access through gray-market intermediaries — can silently redirect calls and text messages without ever contacting a carrier's customer service line. The victim's phone continues to show full signal strength. Nothing appears wrong. Yet every SMS authentication code sent to that number is being intercepted in real time.

The Federal Communications Commission launched an inquiry into SS7 security in 2023, acknowledging that carriers had made insufficient progress addressing vulnerabilities that had been publicly documented for nearly a decade. For the average consumer, the practical implication is stark: SMS-based two-factor authentication, while better than nothing, rests on a foundation with known structural cracks.

The Human Cost

The victims of these attacks rarely fit a single profile. In 2019, a California resident lost approximately $1 million in cryptocurrency after attackers SIM-swapped his number and bypassed the two-factor protections on his exchange accounts. In 2022, a Michigan retiree discovered that her mobile number had been transferred without her knowledge; by the time she reached her bank, her checking and savings accounts had been drained of nearly $30,000. A college student in Texas found his email, social media, and student loan portal compromised in a single afternoon after a fraudster walked into a carrier store with a fake ID.

Recovery is rarely swift. Victims frequently describe months of calls with carriers, banks, and credit bureaus. Some report that customer service representatives were skeptical of their claims, in part because the attacker had already called in to "confirm" the account. Reimbursement from financial institutions varies widely and is far from guaranteed.

Why Carriers Have Struggled to Respond

The wireless industry has not been indifferent to the problem. In 2023, major US carriers — AT&T, T-Mobile, and Verizon — launched a collaborative initiative called Mobile Authentication Taskforce, and the industry has incrementally tightened verification standards. Some carriers now offer dedicated SIM-lock features that require an in-person visit with government-issued identification before any number transfer can occur.

The challenge is systemic. Carrier call centers process millions of legitimate requests each month from customers who have genuinely lost their phones, forgotten their PINs, or switched devices. Fraudsters study and exploit the same flexibility that makes those systems convenient. Every additional security layer introduced by carriers also increases friction for legitimate users — a tension that has historically resolved in favor of convenience.

Protecting Yourself: A Practical Framework

The following steps represent the most effective measures currently available to individual consumers.

Set a carrier account PIN and verbal password. Contact your wireless carrier directly — by phone or through its official app — and establish a numeric PIN and, where available, a separate verbal passphrase that must be provided before any account changes are processed. Write this information down and store it securely offline.

Activate a SIM lock or number transfer lock. Most major US carriers now offer a feature that freezes your number against unauthorized transfers. AT&T calls it "Number Lock," T-Mobile offers "SIM Protection," and Verizon has a similar toggle in account settings. Enable it immediately.

Migrate away from SMS-based two-factor authentication. Wherever a service offers an authenticator app — such as Google Authenticator, Authy, or Microsoft Authenticator — use it instead of SMS codes. These apps generate time-sensitive codes locally on your device and are immune to both SIM swapping and SS7 interception. For the highest-value accounts, consider a hardware security key such as a YubiKey.

Monitor your phone's connectivity. If your phone unexpectedly loses signal in an area where coverage is normally reliable, treat it as a potential warning sign. Contact your carrier immediately from a different device.

Place a credit freeze. Because SIM-swap attacks often accompany broader identity theft, freezing your credit with all three major bureaus — Equifax, Experian, and TransUnion — limits the downstream damage an attacker can cause with your personal information.

File reports promptly. If you believe you have been targeted, file a complaint with the FCC, the FBI's Internet Crime Complaint Center (IC3), and the Federal Trade Commission. These reports contribute to the aggregate data that regulators use to compel industry action.

The Larger Picture

Phone number hijacking is, at its root, a consequence of building critical security infrastructure on a foundation — the telephone network — that was never designed to bear that weight. As long as a ten-digit number functions as a universal identity credential, it will remain a target. The responsibility for addressing that structural problem rests with carriers, regulators, and the technology industry broadly.

In the meantime, individual vigilance remains the most reliable line of defense. The steps outlined above will not eliminate risk entirely, but they will make your phone number a significantly harder target — and in a threat landscape where criminals routinely pursue the path of least resistance, that distinction matters considerably.

All Articles

Related Articles

The Shadow Industry Profiting From Your Every Click: Inside America's Data Broker Economy

The Shadow Industry Profiting From Your Every Click: Inside America's Data Broker Economy

Ghost Accounts Are Watching You: A Step-by-Step Guide to Hunting Down and Erasing Your Digital Past

Ghost Accounts Are Watching You: A Step-by-Step Guide to Hunting Down and Erasing Your Digital Past

One Key to Rule Them All: The Hidden Dangers Lurking Inside Your Password Manager