Skip to content

How to Prevent a SIM Swap or Port-Out Attack

Robert Johnson, CTOUpdated September 19, 20266 min readHow we verify

A SIM swap or port-out attack moves your phone number to a device the attacker controls, so your calls and text-message login codes reach them instead of you, and they use those codes to drain your accounts. The strongest defense is free: lock your number at your carrier and stop relying on text messages for two-factor login.

Your phone number has quietly become a master key. Banks, email providers, and crypto exchanges text a login code to it, and password resets run through it. So if a criminal takes control of your number, they can walk into those accounts one by one. That is what a SIM swap or a port-out attack does, and it can happen without the attacker ever touching your phone.

SIM swap vs port-out: same result, two methods

Both attacks end with your phone number ringing on a device the criminal holds. They get there two ways:

  • SIM swap. The attacker calls your carrier, pretends to be you, and talks them into activating your number on a new SIM card they control. Your number stays with your carrier but moves to their phone.
  • Port-out. The attacker signs up with a different carrier and asks to port your number over, as if you were switching companies. Your number leaves your carrier entirely.

In both cases your calls and texts, including the one-time codes your bank sends by message, now go to the attacker. They reset your passwords and empty accounts before you realize your phone has gone quiet. To pull it off they need a few personal details about you, which is where the same data-broker exposure that fuels property spam comes back around: your name, address, phone number, and date of birth are for sale, and they are exactly what a carrier representative asks for to verify your identity.

Warning signs

  • Your phone suddenly shows No Service, SOS, or SIM not provisioned for no reason, and it does not come back.
  • You get a text or email saying your SIM or number was changed, or that a line was added, when you did nothing.
  • Login codes you did not request start arriving, or you are suddenly locked out of email or banking.

If your service drops out of nowhere, do not wait for it to fix itself. Treat it as an attack in progress and call your carrier from another phone right away.

How to prevent it

1. Lock your number at your carrier (free, and the single best step)

Every major US carrier offers a free number lock or port-out PIN that blocks your number from being moved to a new SIM or carrier until you turn the lock off. Call your carrier or open their app and ask to add a Number Lock, Port-Out PIN, or SIM and account lock to your line. Set a transfer PIN that is required before your number can move, and leave it on except when you are intentionally switching phones or carriers. Each carrier has its own name for this, so ask for it by all three terms.

2. Set a strong, unique carrier account PIN

Your wireless account PIN should not be your birthday, the last four digits of your Social Security number, or anything guessable. That PIN is often the only thing standing between a caller and your number.

3. Stop using text messages for two-factor login

Text-message codes are the prize in a SIM swap. Wherever an account allows it, switch two-factor authentication from text messages to an authenticator app or a hardware security key, which stay on your device and do not follow your number to a new SIM. Do your email and financial accounts first, because email is the reset path for everything else.

4. Shrink the personal data used to impersonate you

Talking a carrier representative into a swap takes knowing your details. The less of your information sits on people-search and data-broker sites, the harder you are to impersonate. Check where your data is exposed and work through the removal guides to get it taken down. It is the same cleanup that cuts down wholesaler spam, doing double duty here. For how that data gets collected in the first place, see how someone got your phone number.

5. Never confirm details to an inbound carrier call

Attackers also call you, posing as a carrier fraud department, to phish the PIN or code they need. A real carrier will not call and ask you to read back a code. Hang up and call the number printed on your bill.

If it already happened

  • Call your carrier from another phone, tell them your number was hijacked, and have them restore it to your device and lock the account.
  • From a device you trust, change the passwords on your email and financial accounts first, then everything important, and switch those accounts to app-based two-factor.
  • Contact your bank and any payment or crypto accounts to flag fraud.
  • Report it to the FTC at reportfraud.ftc.gov, and if money was taken, to the FBI at ic3.gov.

Where FendLand fits

FendLand Firewall watches your number for exactly this. When you turn it on in the app, it records which carrier your number is on and what kind of line it is, then re-checks daily. If your number gets ported to a different carrier, or if your carrier reports a SIM swap on the line, FendLand alerts you and includes the specific steps to lock your number at your carrier. When the carrier does not report enough to be certain, it tells you that rather than giving a false all-clear, because a wrong all-clear on a security feature is worse than silence. It is part of Shield Pro, on iPhone and Android.

The short version

  • Lock your number at your carrier with a Number Lock or port-out PIN. It is free and it is the single best step.
  • Use a strong, unique carrier account PIN.
  • Move two-factor login off text messages to an authenticator app, starting with email and banking.
  • Remove your personal data from broker sites so you are harder to impersonate.
  • If your phone loses service for no reason, treat it as an attack and call your carrier now.

See where your address is exposed

FendLand finds where your name and address are published across the data-broker and people-search sites wholesalers pull from, files the removals, and keeps re-checking because they re-list you. Start with a free exposure check.

Check your exposure, free

Frequently asked questions

What is the difference between a SIM swap and a port-out attack?

Both move your phone number to a device a criminal controls. In a SIM swap, they convince your existing carrier to activate your number on a new SIM card they hold. In a port-out, they move your number to a different carrier entirely, as if you were switching companies. Either way, your calls and texts, including login codes, go to them.

How do I stop a SIM swap from happening?

Add a free number lock or port-out PIN at your carrier, which blocks your number from moving to a new SIM or carrier until you turn it off. Set a strong, unique account PIN, and move your two-factor logins off text messages to an authenticator app. Together those three steps close the paths an attacker needs.

What are the warning signs of a SIM swap?

The clearest sign is your phone suddenly losing service, showing No Service, SOS, or SIM not provisioned, for no reason and not coming back. You might also get a message that your SIM or number was changed when you did nothing, receive login codes you did not request, or find yourself locked out of email or banking.

Does removing my data from broker sites help prevent SIM swaps?

Yes, indirectly. To impersonate you to a carrier, an attacker needs personal details like your address, phone number, and date of birth, which are widely sold on people-search and data-broker sites. Removing that data makes you harder to impersonate, the same cleanup that reduces unwanted property and spam calls.

Get your address off the lists behind these texts

These are the exact sites and tools wholesalers pull from. Removing yourself is free, and each guide walks you through it step by step.