The Quick Read
A SIM swap is when someone walks into a mobile carrier, sweet-talks a clerk, and walks out with your phone number on their SIM. Once your number is on their SIM, every SMS-based two-factor code, password reset, and one-time login link meant for you lands in their phone instead.
It is not a theoretical risk. The FBI logged 1,611 SIM swap complaints totaling more than $68 million in adjusted losses in 2021. [1]
Since July 8, 2024, every U.S. wireless carrier is required by FCC rules to use secure authentication, offer free lock features, and send immediate notifications before any SIM change or number port. [2] [3] The trick is turning the protections on, because most carriers do not enable them by default.
What a SIM Swap Actually Is
A SIM swap is the moment a mobile carrier moves your phone number from the SIM card in your phone to a different SIM card. A working SIM swap is invisible to you: your phone loses signal, the attacker’s phone lights up with your number, and every service that texts you a code now texts them.
The FBI describes the three ways attackers do it: "Criminal actors primarily conduct SIM swap schemes using social engineering, insider threat, or phishing techniques." [1] The FCC rules now require carriers to train their employees to spot the social-engineering and insider-threat versions, with section 47 CFR 64.2010(h)(7) mandating training "on how to identify potentially fraudulent SIM change requests, how to identify when a customer may be the victim of SIM swap fraud, and how to direct potential victims and individuals making potentially fraudulent requests to employees specifically trained to handle such incidents." [4]
What the attacker gets once the swap lands:
- Every SMS code sent to your number, including bank, email, and crypto account 2FA codes.
- Calls and texts intended for you, used for further social engineering.
- Password reset links for any account that uses your phone number as a recovery method.
The FBI is blunt about what comes next: "Once the SIM is swapped, the victim’s calls, texts, and other data are diverted to the criminal’s device." [1] The attack usually ends in minutes. The fallout (drained bank accounts, hijacked email, lost crypto) takes weeks to unwind.
What the FCC Now Requires Carriers to Do
On November 15, 2023, the FCC adopted rules to combat SIM swap and port-out fraud. The order took effect January 8, 2024, and the compliance date for the carrier obligations is July 8, 2024. [2] [3]
The rules added a new section 47 CFR 64.2010(h) covering SIM change requests. The regulation requires carriers to "only effectuate SIM change requests" after using "secure authentication methods reasonably designed to confirm the customer’s identity before executing a SIM change request." [4]
The same section says those methods "shall not rely on readily available biographical information, account information, recent payment information, or call detail information." [4] In plain English: your last bill amount, your address, and your date of birth are not enough to authenticate a SIM swap anymore.
The Federal Register summary of the order lists what carriers must now do for every SIM change and every number port:
- "Use secure methods to authenticate a customer" before completing the request, and review those methods at least once a year. [3]
- Send "immediate notification" to the customer before effectuating the swap or port. [3]
- Offer a SIM change and port-out "lock" feature "at no cost" to every customer, including prepaid. [3]
- Retain SIM change records for three years, including request totals, success and failure rates, fraud incidents, and remediation time. [3]
- Provide a "clearly disclosed, transparent, and easy-to-use process" to report fraud, with prompt investigation and free documentation for victims. [3]
The order summary also quotes the FCC’s framing of why: "the cornerstone of our action is a requirement that wireless providers use secure methods of authenticating customers prior to performing SIM changes and number ports." [3] And the damage the rules are designed to limit: "SIM swap and port-out fraud can result in substantial harm to the customer." [3]
These rules apply to every U.S. mobile carrier, including AT&T, Verizon, T-Mobile, MVNOs, and prepaid providers. The protection only works if you turn it on. Most carriers do not enable locks by default.
What to Lock Down: Number Lock, SIM Protection, and Port-Out PINs
The three protections you want on are:
- A port-out lock that prevents anyone from transferring your number to another carrier without you flipping the switch first.
- A SIM change lock that prevents anyone from moving your number to a new SIM on the same carrier.
- Immediate notifications so you know within seconds if a swap is attempted.
The next sections cover what Verizon, T-Mobile, and AT&T actually offer and how to turn each on. UI paths change. The features described below are what the carriers publicly document today.
Verizon: Turn On Number Lock
Verizon sells the protection as "Number Lock" and documents it on its port-out FAQ page. [5] Verizon describes the feature as protecting against "unauthorized port out," where "a scammer who gets your personal information could move your mobile number to another carrier." [5]
How to turn it on, per Verizon’s own support page:
- From your Verizon phone, dial *611 and follow the prompts. [5]
- Or open My Verizon, go to the Security page, find the Number Lock section, set the toggle to On for the numbers you want protected, and tap Save Changes. [5]
Verizon also documents a related SIM protection toggle in the same Account Settings area, sitting just below the Number Lock section. [5]
Two important limitations from Verizon’s own page: you must turn Number Lock off before porting your number out yourself, and the company flags that "Number Lock on your number doesn’t help prevent SIM card changes or equipment changes to your device." [5] That is why enabling the SIM protection toggle below it matters too. When a port-out is requested, Verizon sends a confirmation text; if you did not initiate it, the page tells you to call the number in the message. [5]
T-Mobile: SIM Protection and Port Out Protection
T-Mobile documents two separate features, both free, both designed to be turned on per line.
SIM Protection is a free feature "offered to all T-Mobile Postpaid customers" that "prevents bad actors from moving your number to another device and using it for fraud." [6] The catch is in the same paragraph: "If you don’t disable SIM Protection before changing to a new SIM card or moving your eSIM to a new device, you’ll receive an error." [6] Remember your own setting.
To turn SIM Protection on in the T-Life app: open T-Life, go to the Manage tab, tap the gear icon, choose Security, then SIM Protection, toggle it on, and select Save Changes then Continue. [6] On T-Mobile.com: log in, open the profile menu, choose Profile, then Security, then SIM Protection, flip the toggle, and save. [6] Only the Primary Account Holder can remove the feature. [6]
Port Out Protection is a separate free feature "offered to all T-Mobile Postpaid, T-Mobile for Business, T-Mobile Prepaid, and Metro by T-Mobile customers" that "adds additional security to your account by blocking unauthorized users from transferring your lines to another wireless carrier." [6]
To turn Port Out Protection on in the T-Life app: open T-Life, go to the Manage tab, choose See Plans in the My Account section, tap Manage add-ons, pick the line, check Port Out Protection, tap Continue, review, and select Agree & Submit. [6] It has to be added to each line individually. [6]
For prepaid lines, log in at prepaid.t-mobile.com, go to My T-Mobile, choose My Profile, then SIM Protection or Port Out Protection, toggle, and save. [6]
AT&T: The Same Rules Apply, the Setup Is Less Documented
AT&T is covered by the same FCC rules that took effect July 8, 2024, so AT&T customers can demand the same three protections: a port-out lock, a SIM change lock, and immediate notification of any change attempt. [3]
AT&T is covered by the same FCC rules that took effect July 8, 2024, so AT&T customers can demand the same three protections: a port-out lock, a SIM change lock, and immediate notification of any change attempt. [3]
The safest path is to call AT&T directly, ask the representative to enable port-out protection and SIM change protection on your line, ask them to confirm a notification method (text or email) is on file, and ask for a case number. This is the universal workaround for any carrier whose UI you cannot find the toggle in.
Beyond the Carrier: Backup Authentication and Account Hygiene
The carrier-side lock stops the SIM swap. It does not stop the attacker from getting into your accounts if they already have your password. The FBI’s PSA recommends a layered defense. [1]
Stop using SMS for two-factor authentication. The FBI says outright: "Use strong multi-factor authentication methods such as biometrics, physical security tokens, or standalone authentication applications." [1] SMS is the most phishable 2FA method because it is the very channel a SIM swap hijacks. Move your important accounts (email, bank, crypto, password manager) to an authenticator app or a hardware security key.
Lock down the phone number itself. The three carrier controls above (port-out lock, SIM change lock, immediate notification) make a successful swap much harder. Turn them all on.
Reduce the biographical data attackers use to social-engineer a carrier rep. The FBI recommends avoiding "publicly discussing financial assets or cryptocurrency ownership" and not "posting phone numbers, addresses, and other identifying information online." [1] Every field on your public profiles is one less hoop for a smooth-talking scammer at a carrier store.
Set a unique account passcode, not the default. If your carrier account uses a default PIN like the last four of your social, change it. SIM swaps succeed by guessing, looking up, or phoning the carrier and verifying a small number of facts. A strong carrier account passcode is the layer that stops the call.
Watch for the telltale sign. The FBI lists the warning sign: "Monitor for unexpected changes in SMS service." [1] If your phone suddenly drops to no service in the middle of a city, or in a place where you normally have signal, do not assume it is the network. Try to call someone. If the call fails and you do not know why, contact your carrier immediately from another phone or in person.
What to Do If You Suspect You Are Already SIM Swapped
The FBI’s PSA lays out the recovery steps, in order. [1]
- Contact the mobile carrier immediately to recover control of the phone number. [1]
- Change online-account passwords, starting with email and bank accounts. Do this from a device the attacker does not control, ideally over a network they are not on. [1]
- Notify financial institutions and request alerts for suspicious logins or transactions. [1]
- Report suspicious activity to local law enforcement or an FBI field office. [1]
- Submit a report to the FBI’s Internet Crime Complaint Center at ic3.gov. [1]
The FBI’s underlying warning: the longer the attacker holds your number, the more downstream accounts they can drain. A SIM swap is not something to wait out overnight.
What a SIM Swap Can and Cannot Do
A successful SIM swap gives the attacker your phone number on their device. It does not give them the data on your phone (unless they also have your phone), the password to your accounts, or the keys to your crypto wallet. The danger is everything that uses your number as a recovery or verification method.
That is a long list. The FBI PSA says the goal is to "steal money from fiat and virtual-currency accounts," and the 2021 reported loss total was more than $68 million across 1,611 complaints. [1]
The new FCC rules shift the attacker’s economics. Before July 8, 2024, a successful swap could happen over the phone with a name, address, and last four of a Social Security number. After that date, the carrier is required to use "secure methods" that do not rely on those facts, and to notify you the moment a swap is requested. [3] [4]
The rules are not a guarantee. They are a wall. The attacker now has to defeat your carrier’s authentication plus your notification plus, ideally, a port-out lock you turned on. The right setup makes a SIM swap a noisy, slow, and obvious operation. The wrong setup lets it happen in five minutes and you find out from your bank.
The Bottom Line
Every U.S. wireless carrier is now required to offer free port-out locks, SIM change locks, and immediate notifications on every line, including prepaid. The rules took effect on January 8, 2024 and carriers had to comply by July 8, 2024. [2] [3]
If you only do three things after reading this, do these.
- Turn on your carrier’s port-out lock and SIM change lock today. Verizon: *611 or My Verizon Security page. [5] T-Mobile: T-Life or T-Mobile.com under Security and Manage add-ons. [6] AT&T: call the carrier and ask.
- Move every important account off SMS 2FA. Use an authenticator app or a hardware security key. The FBI recommends this directly. [1]
- If your phone suddenly loses service in a place where it should work, treat it as a SIM swap attempt, not a dead cell tower. Call your carrier from another phone.
References
- FBI Internet Crime Complaint Center: Criminals Increasing SIM Swap Schemes to Steal Millions of Dollars From US Cryptocurrency Investors (Feb 8, 2022)
- Federal Register: Protecting Consumers from SIM-Swap and Port-Out Fraud (Dec 8, 2023)
- GovInfo: Federal Register, Vol. 88 No. 233, In the Matter of Protecting Consumers from SIM-Swap and Port-Out Fraud (Dec 8, 2023)
- Cornell Law: 47 CFR 64.2010 - Safeguards on the disclosure of customer proprietary network information
- Verizon Support: Port-out protection and Number Lock
- T-Mobile Support: SIM Protection and Port Out Protection