SIM Swap Attack
Pronunciation: SIM SWAP uh-TAK
Also known as: SIM Hijacking
Definition
SIM Swap Attack is an account takeover attack in which a criminal causes a mobile carrier to transfer a victim’s phone number to a SIM or device controlled by the attacker. The phone number is the takeover channel; the attack is not the same as physically stealing the victim’s handset. It should be interpreted alongside Adaptive Authentication, which may affect the same workflow without representing the same control, event, or risk.
Overview
SIM Swap Attack is an account takeover attack in which a criminal causes a mobile carrier to transfer a victim’s phone number to a SIM or device controlled by the attacker. The phone number is the takeover channel; the attack is not the same as physically stealing the victim’s handset. It should be interpreted alongside Adaptive Authentication, which may affect the same workflow without representing the same control, event, or risk.
Attackers can intercept SMS codes, reset passwords, impersonate the victim, access financial accounts, and combine carrier fraud with phishing or leaked personal data.
Organizations should avoid SMS as the sole high-risk authenticator, use phishing-resistant MFA, add carrier account protections, detect number or device changes, and require step-up checks for withdrawals.
Retain carrier-change signals, authentication events, recovery actions, device history, withdrawal attempts, analyst decisions, customer notifications, and containment timestamps.
Assessment of SIM Swap Attack should trace the use of a mobile carrier to transfer a victim’s phone number to a SIM or device controlled by the attacker from prerequisite and entry point through observable impact on the affected service. A theoretical weakness or scanner result involving device controlled by the attacker should not be reported as exploitation without corroborating logs, transactions, or configuration evidence. Prevention, detection, containment, and recovery for the SIM Swap attack path should be tested against the architecture associated with device controlled by the attacker.
Retesting for SIM Swap Attack should reproduce the SIM Swap attack path involving device controlled by the attacker, examine adjacent paths, and verify the conditions for safely returning the affected service to normal operation.
Key Takeaway
SIM Swap Attack is an account takeover attack in which a criminal causes a mobile carrier to transfer a victim’s phone number to a SIM or device controlled by the attacker.
Sources
- Digital Identity Guidelines, SP 800-63-4 — NIST (2026-08-03)
- Web Authentication: An API for Accessing Public Key Credentials Level 2 — W3C (2026-08-03)
- Phishing-Resistant Authenticator Guidance — CISA (2026-08-03)