SIM Swap Attacks: How They Work and How to Protect Yourself
SIM swap fraud lets criminals hijack your phone number. Learn how these attacks work, how data brokers enable them, and the steps to protect your accounts.
A SIM swap attack transfers your phone number to a criminal's SIM card, giving them access to your SMS two-factor authentication codes. With your phone number, they can reset passwords on your email, banking, and other critical accounts.
These attacks are more common than most people realize — and they are enabled in part by personal information available on data broker sites.
How SIM Swap Attacks Work
The attacker calls your mobile carrier, claims to be you, and requests a SIM transfer to their device. To 'verify' your identity, the carrier asks security questions — your address, date of birth, account PIN, or last four digits of your SSN.
Most of this information is available through data broker profiles. An attacker who has your name, current address, date of birth, and a family member's name can answer most carrier security questions convincingly.
Once the SIM transfer is approved, your phone loses service and the attacker receives all your calls and SMS messages — including one-time passwords.
How to Protect Yourself
Contact your carrier and set a unique PIN or passcode required for any account changes. Most major carriers offer this — ask specifically for 'port freeze' or 'SIM lock' protection.
Switch from SMS 2FA to authenticator apps (Google Authenticator, Authy) for your most critical accounts. Authenticator codes are generated on your device and cannot be intercepted via SIM swap.
Remove your home address, date of birth, and relatives from data broker profiles to reduce the information available for social engineering. CypherAvoid scans for this data and pursues removal across major broker platforms.
Run Exposure Scan
Check your current data broker and dark web exposure — free scan, no account required.