SIM Swapping in 2026: How It Works, Warning Signs and How to Protect Yourself
Your phone suddenly loses signal.
You cannot receive calls or text messages.
A few minutes later, password-reset notifications start appearing in your email.
Then your bank contacts you about activity you do not recognise.
You may be experiencing a SIM-swap attack.
SIM swapping is a form of account takeover where a criminal convinces a mobile provider to transfer your telephone number to a SIM or eSIM under their control. Once successful, calls and SMS messages intended for you can instead reach the attacker. Ofcom specifically identifies SIM-swap fraud as a technique criminals can use to intercept one-time security codes.
That can become particularly serious when businesses and online services still rely on SMS for password resets or multi-factor authentication.
The good news is that modern authentication gives us considerably better ways to protect important accounts than relying on text messages alone.
What Is SIM Swapping?
A SIM card identifies your mobile subscription to your network.
When you genuinely change phone, lose a device or move from a physical SIM to an eSIM, your mobile provider may legitimately transfer your telephone number to another SIM.
A fraudulent SIM swap abuses that legitimate process.
The criminal attempts to convince your mobile provider that they are you.
If successful, your existing SIM can stop working and your telephone number becomes active on the attacker's device.
The attacker may then receive:
SMS security codes.
Password-reset messages.
Banking verification messages.
Telephone calls intended for you.
That does not automatically give them access to every account.
But if they have already obtained your password, personal information or email credentials, control of your telephone number can provide another part of the puzzle.
The NCSC's updated 2026 research into authentication specifically identifies SIM swapping as a way financially motivated attackers can obtain security codes delivered through SMS.
How Does a SIM-Swap Attack Happen?
The attack frequently begins before the mobile provider is contacted.
A criminal may gather information about you through:
Phishing.
Data breaches.
Social media.
Previous scams.
Public company information.
Compromised email accounts.
They may know your name, mobile number, date of birth, address or information relating to your mobile account.
The attacker then impersonates you.
They might claim:
“I've lost my phone.”
“My SIM has stopped working.”
“I've bought a new handset.”
“I need to activate an eSIM.”
The objective is to persuade the provider's account-recovery process that they are the legitimate customer.
If successful, your telephone number moves to their device.
Why SIM Swapping Can Be So Dangerous
The problem is not simply somebody being able to receive your text messages.
Your mobile number may be connected to several important accounts.
For example:
Banking.
Email.
Microsoft accounts.
Social media.
Payment services.
Cloud applications.
Password-reset processes.
If a service sends an SMS code to verify your identity, the attacker may now receive it.
This is one reason the NCSC advises organisations using SMS in critical business processes to consider the security weaknesses associated with mobile-number ownership and even recommends that services capable of doing so check whether a recent SIM swap has occurred before sending sensitive OTPs.
SMS MFA Is Better Than No MFA — but There Are Stronger Options
This point needs some nuance.
You should not switch MFA off simply because SMS isn't the strongest method.
Two-step verification is still considerably better than protecting important accounts with a password alone. The NCSC continues to recommend enabling 2SV on important accounts, particularly email accounts.
But where stronger authentication is available, use it.
For important business systems, the preference in 2026 should increasingly move towards phishing-resistant authentication.
That means options such as:
Passkeys.
FIDO2 security keys.
Windows Hello for Business.
These do not depend on receiving a reusable security code through your telephone number.
The NCSC's April 2026 comparison of authentication methods specifically highlights SIM swapping as a weakness affecting SMS authentication while FIDO2-based authentication avoids that particular attack route.
Passkeys Are Particularly Useful
Passkeys represent one of the biggest improvements in account security in recent years.
Instead of entering a password and then receiving an SMS code, a passkey uses cryptographic authentication tied to the legitimate service.
That has two major benefits.
First, there is no SMS code for a SIM-swap attacker to intercept.
Second, passkeys provide strong resistance against conventional phishing sites.
For businesses using Microsoft 365, this is one reason organisations should increasingly look at passkeys/FIDO2 and other phishing-resistant authentication methods, especially for administrators and other high-value accounts.
Authenticator Apps Can Still Be Better Than SMS
An authenticator application can also reduce dependence on your mobile number.
Time-based codes generated by an authenticator application are generated on the device rather than being delivered through the mobile network.
The NCSC describes authentication applications as more secure than SMS for 2-step verification.
But don't assume every form of app-based authentication is equally strong.
Push-notification MFA can face its own risks, including MFA fatigue attacks, where attackers repeatedly trigger login prompts hoping the victim eventually presses Approve just to make them stop. The NCSC's 2026 authentication research explicitly discusses this attack technique.
Phishing-resistant authentication remains the stronger destination where supported.
6 Ways to Reduce the Risk of SIM-Swap Fraud
You cannot completely control the security processes used by your mobile provider.
But you can make an attack considerably harder and reduce the damage it can cause.
1. Secure Your Mobile Provider Account
Protect your mobile-provider account itself.
Use a strong unique password.
If your provider supports an additional account PIN, security phrase, porting protection or other takeover protection, enable it.
The exact controls vary between UK mobile providers, so check what yours supports.
Also make sure the email account associated with your mobile contract is properly secured.
If an attacker compromises that email account first, it may make impersonating you or resetting your mobile-provider credentials considerably easier.
2. Stop Using SMS as the Best Security Method Where You Have a Choice
If an important account offers:
Passkey
FIDO2 security key
Authenticator
SMS
consider choosing one of the stronger alternatives.
For particularly sensitive business accounts, SMS should increasingly be treated as a fallback rather than the preferred authentication method.
This is especially important for:
Microsoft 365 administrators.
Finance systems.
Password managers.
Cloud administrators.
Business owners.
Anyone with privileged access.
3. Protect Your Email Account Extremely Well
Your email account is often the master key to everything else.
Why?
Because many services use email for password recovery.
If an attacker controls both:
Your email account
and
Your mobile number
they can potentially defeat several ordinary account-recovery processes.
Protect important email accounts with strong, phishing-resistant authentication where possible.
For Microsoft 365 businesses, this may also involve controls such as Conditional Access, managed devices and restrictions around privileged administrators.
4. Use Unique Passwords
SIM swapping becomes far more powerful when the attacker already knows your passwords.
Never reuse the same password across important accounts.
A data breach involving one website should not provide the attacker with a password that also works for your:
Email.
Microsoft 365.
Mobile provider.
Bank.
Social-media accounts.
Use a reputable password manager to generate and store long, unique credentials.
And contrary to some older advice, modern browser password managers do not simply store all passwords as readable plain text. Modern browsers provide encrypted credential-storage systems, although organisations may still prefer dedicated enterprise password-management platforms for additional management, auditing and sharing controls.
5. Be Careful With Personal Information Online
Social media can reveal much more than people realise.
Think about information such as:
Your date of birth.
Children's names.
Where you went to school.
Your first employer.
Your home town.
Your mobile number.
Your job.
Your company's management structure.
Some of that information may be useful to criminals attempting social engineering.
This does not mean everybody needs to delete LinkedIn and disappear from the internet.
It means thinking before publishing information that could help somebody impersonate you.
6. Don't Treat Security Questions as Strong Authentication
Questions such as:
What was your mother's maiden name?
Where were you born?
What was the name of your first school?
are weak if the answers can be researched online.
Where services still force you to use security questions, avoid treating them as an opportunity to supply easily discoverable biographical information.
Ideally, store unpredictable answers securely in your password manager rather than relying on genuinely personal answers that somebody else may know.
Warning Signs of a SIM-Swap Attack
A SIM swap can sometimes reveal itself very quickly.
One of the strongest signs is your mobile unexpectedly losing service even though other people nearby have a signal.
Watch for:
Your phone suddenly showing no mobile service.
Calls and SMS messages unexpectedly stopping.
A notification from your mobile provider about a SIM or eSIM change you didn't request.
Unexpected account-recovery emails.
Password-reset notifications.
MFA changes you didn't make.
Banking transactions you don't recognise.
Emails saying new devices have logged into your accounts.
One symptom does not automatically prove that a SIM swap has occurred.
A mobile-network outage can also cause lost service.
But several of these happening together should be treated seriously.
What Should You Do If Your SIM Suddenly Stops Working?
If you suspect an unauthorised SIM swap, act quickly.
Contact Your Mobile Provider
Contact the provider using a trusted method and tell them that you suspect your telephone number has been fraudulently transferred.
Do not simply respond to an incoming caller claiming to be your network provider.
Use contact information obtained independently.
Protect Your Email Account
Check your email account immediately.
Change compromised credentials where necessary.
Review:
Login activity.
Recovery methods.
MFA methods.
Forwarding rules.
Active sessions.
Connected applications.
If this involves a business Microsoft 365 account, tell your IT provider immediately.
Simply changing a password may not be sufficient if an attacker already has an authenticated session.
Contact Your Bank
If banking details or financial accounts may be affected, contact your bank immediately through an official channel.
Do not wait until you see money disappear.
Explain that you suspect your mobile number may have been taken over.
Secure Other Important Accounts
Prioritise:
Email.
Banking.
Password managers.
Microsoft 365.
Apple/Google accounts.
Social media.
Financial services.
Look for changed passwords, recovery methods or unfamiliar devices.
Report the Fraud
One important change since the older version of this article is that Action Fraud has been replaced.
On 4 December 2025, the City of London Police launched Report Fraud as the new national platform for reporting cyber crime and fraud in England, Wales and Northern Ireland.
People in Scotland should report fraud through Police Scotland.
This means older advice directing people to Action Fraud should now be updated.
Suspicious scam texts can also be forwarded free of charge to 7726, allowing mobile providers to investigate them. Ofcom reinforced this reporting route again in July 2026.
Businesses Should Reduce Their Dependence on SMS Authentication
SIM swapping should also make businesses think more broadly about account recovery.
Ask:
Which of our systems still depend on SMS codes?
Can administrators reset accounts using a mobile number?
Could somebody taking over one executive's number access important systems?
Are passkeys or FIDO2 available?
Are privileged accounts protected differently from normal accounts?
For businesses running Microsoft 365, authentication should increasingly be designed so that possession of a telephone number is not enough to take control of an important account.
That might include:
Phishing-resistant MFA.
Passkeys.
FIDO2 security keys.
Microsoft Entra Conditional Access.
Separate administrator accounts.
Managed endpoints.
Login monitoring.
Strong account-recovery procedures.
The objective is defence in depth.
If one security control fails, another should stop the attacker.
SIM Swapping in 2026: The Key Message
SIM swapping remains dangerous because your telephone number is still used as proof of identity by many online services.
But your mobile number should not be treated as a security key.
The strongest protection is to reduce how much your important accounts depend upon it.
Use unique passwords, secure your email and mobile accounts, enable strong MFA and move towards passkeys or FIDO2 authentication wherever practical.
And if your phone unexpectedly loses service while account-reset or banking notifications start appearing, don't assume it is simply a mobile-network glitch.
Investigate it immediately.
Protect Your Business Accounts With Hamilton Group
Hamilton Group can help businesses reduce the risks associated with account takeover, phishing, stolen credentials and weak authentication.
We can help with Microsoft 365 security, Microsoft Entra ID, Conditional Access, passkeys and phishing-resistant MFA, endpoint protection and EDR, password management, security awareness training and managed IT support.
We can also review existing Microsoft 365 authentication methods and identify accounts that still rely heavily on weaker authentication or recovery methods.
And if an employee believes an account has been compromised, rapid action matters. Our aim is to make first contact on IT support requests within 15 minutes.
Call Hamilton Group on 0330 043 0069 or visit hgmssp.com to speak with one of our IT and cyber-security experts.