Your Phone Number Was HijackedAct Fast to Limit the Damage
SIM swap attacks let criminals take over your phone number, bypass SMS 2FA, and drain bank accounts, crypto wallets, and email in minutes. The FBI Internet Crime Complaint Center 2024 Annual Report logged 982 SIM-swap complaints totaling approximately $26 million in direct losses in 20241. Speed is everything.
5 Steps After a SIM Swap
Most financial theft happens within the first two hours.
Call your carrier NOW to report and freeze the account
Change passwords from a secure device, starting with email
Remove SMS-based 2FA everywhere and switch to app-based or hardware keys
Audit all financial accounts for unauthorized transactions
File reports with FBI IC3, FTC, and local police
What a SIM Swap Attack Is and How It Happens
A SIM swap attack, sometimes called SIM hijacking or port-out fraud, is identity theft aimed at the one credential almost every online account trusts: your mobile phone number. The attacker does not need to touch your phone. Instead, they convince your wireless carrier, or exploit a weakness in the carrier's process, to move your number onto a SIM card they control. From that moment, every call and every text message meant for you arrives on the criminal's device instead, including the one-time passcodes that banks, exchanges, and email providers send by SMS.
The attack usually unfolds in three phases. First comes reconnaissance. Criminals assemble a profile of the target from data broker records, previous breach dumps, and social media. They are looking for the details a carrier support agent might use to verify identity: full name, address history, date of birth, account numbers, and answers to common security questions. High-value targets, such as executives, cryptocurrency holders, and owners of desirable social media handles, are often researched for weeks before the swap is attempted.
Second comes the takeover itself. The most common route is social engineering: the attacker calls the carrier posing as you, claims a lost or damaged phone, and asks to activate service on a new SIM. Some groups instead recruit or bribe retail store employees, use stolen carrier account credentials to process the change online, or exploit the number porting process by moving your number to an entirely different carrier. However it happens, your handset abruptly loses service, which is often the only warning a victim gets.
Third comes the harvest. With your number in hand, the attacker triggers password resets on your email, banking, brokerage, and cryptocurrency accounts, intercepts the SMS verification codes, and locks you out of your own digital life. Because so many institutions treat possession of a phone number as proof of identity, a single successful swap can cascade into full account takeover in under an hour. The FBI Internet Crime Complaint Center 2024 Annual Report logged 982 SIM-swap complaints totaling approximately $26 million in direct losses in 20241, and those figures capture only what victims reported to one federal channel.
Why SMS Two-Factor Authentication Fails Against This Attack
Text-message verification codes were designed to prove that a login attempt came from someone holding your phone. A SIM swap breaks that assumption completely: the attacker does not bypass your second factor, they become it. This is why security frameworks and federal guidance have steadily moved away from SMS as an authentication channel for sensitive accounts. App-based authenticators generate codes on the device itself, and hardware security keys bind the login to a physical token, so neither can be intercepted by taking over a phone number. Migrating your critical accounts off SMS verification is the single highest-impact step you can take after a swap, and Petronella Technology Group, Inc. walks every recovery client through that migration account by account.
How to Tell You Have Been SIM Swapped
The signs appear quickly. Your phone drops to no service or shows an emergency-calls-only state in a location where coverage is normally solid. Restarting the handset does not restore it. Password reset emails you never requested start arriving, or you find you can no longer sign in to your primary email account. Friends may report strange calls or texts from your number. Some victims first learn of the attack from a low-balance alert or a transfer confirmation from their bank. If two or more of these happen together, treat it as an active incident and work the five steps above immediately, starting with your carrier.
SIM Swap Recovery Services
Carrier Escalation
Direct work with carrier fraud departments to expedite number recovery. Account lockdown with PINs, port freezes, and SIM locks.
Full Account Audit
Systematic identification and securing of every account tied to your phone number across 50+ services.
Device Forensics
Analysis for keyloggers, RATs, and credential-stealing software that may have enabled the initial data gathering.
Dark Web Monitoring
Ongoing monitoring of dark web markets for your credentials, email addresses, and financial account details.
How a SIM Swap Recovery Engagement Works
Petronella Technology Group, Inc. treats a SIM swap the way we treat any active intrusion: contain first, investigate second, harden third. When you call (919) 348-4912, the first conversation is a rapid triage. We establish whether the number is still in the attacker's hands, which accounts have already been touched, and where the highest-value exposure sits, usually primary email, banking, brokerage, and any cryptocurrency holdings. You get a prioritized action list on that first call, because the order in which accounts are secured matters enormously in the first hours.
Containment: Taking Your Number and Accounts Back
Carrier fraud departments have their own escalation paths that are faster than general customer support, and the fastest resolution of all is usually a visit to a physical store with government identification. We guide you through that process, help you insist on a fraud investigation rather than a routine SIM change, and make sure the account leaves the incident with a unique PIN, a port freeze, and a SIM lock so the attacker cannot simply repeat the swap next week. In parallel, we work the account list: primary email is always first, because whoever controls your inbox can reset nearly everything else. Each account is recovered from a known-clean device, given a new unique password, and moved off SMS verification onto an app-based authenticator or a hardware security key.
Investigation: Finding Out How It Happened
A SIM swap is rarely the first event in the chain. The attacker needed enough personal data to impersonate you, and sometimes that data came from spyware or a credential-stealing infection on one of your own devices. Our forensic team, led by a North Carolina licensed digital forensic examiner, examines the devices involved for keyloggers, remote access tools, and malicious profiles, and reviews account activity logs to reconstruct the timeline of what the attacker reached and when. That reconstruction matters for more than curiosity: it determines which accounts and documents must be treated as exposed, and it produces the evidence package you will need for law enforcement reports, bank fraud claims, and any dispute over liability for stolen funds.
Hardening: Making Sure It Does Not Happen Again
The engagement closes with a hardening pass across your digital footprint. We remove your phone number as a recovery factor wherever it lingers, set up dark web monitoring for your credentials, review the exposure of your personal data with brokers, and document the carrier-side protections now in place. For clients who lost cryptocurrency in the attack, we coordinate directly with our crypto theft tracing service so blockchain analysis starts while the trail is fresh, and for business victims we extend the review to corporate mail tenants and finance workflows, since a swapped executive number is a common opening move in business email compromise operations.
Hardening Your Phone Number Before the Next Attempt
Every major U.S. carrier now offers account-level protections that make a SIM swap dramatically harder, but none of them are enabled by default. Prevention is a checklist, and it takes less than an evening:
- Set a carrier account PIN or passcode. Choose one that appears nowhere else in your life. This single control blocks the most common social engineering script, because the support agent will require it before processing a SIM change.
- Enable the port freeze and SIM protection features. Carriers offer number lock or port-out protection settings that prevent your number from being moved to a new SIM or a new carrier until you explicitly unlock it.
- Get SMS out of the authentication path. Move every account that matters to an app-based authenticator or, better, a hardware security key. Where an account insists on keeping a phone number, consider using a number that is not publicly associated with you.
- Remove your number as a recovery option. The recovery settings of your email and financial accounts are where SIM swaps do their damage. Replace phone-based recovery with backup codes stored offline.
- Starve the reconnaissance phase. Limit what you share publicly about your carrier, your investments, and your holdings. Criminals select SIM swap targets based on what they can learn in advance.
For organizations, the same logic scales up. Executives, finance staff, and anyone with wire authority or administrative access should carry carrier-level port protection, phishing-resistant authentication, and a documented incident procedure that assumes their number can be taken at any time. Petronella Technology Group builds those protections into our managed cybersecurity programs, and our security awareness training teaches teams to recognize the early signs of number hijacking before the losses start.
The First 48 Hours After a SIM Swap, in Detail
Hour one belongs to the carrier and your email. Call your carrier's fraud line from any working phone, report the unauthorized SIM change, and ask them to suspend the line or return it to your SIM. Insist that the incident be logged as fraud, not as a routine service issue, and ask for the case number. While you are on hold, use a separate, known-clean device to sign in to your primary email account. If you still have access, change the password and revoke all active sessions. If you are locked out, start the provider's account recovery process immediately, because every downstream reset the attacker attempts flows through that inbox.
Hours two through six are the account race. Work outward from email in order of damage potential: banking, brokerage, cryptocurrency exchanges, payment apps, then cloud storage and social accounts. For each one, change the password, remove your phone number from the recovery and verification settings, switch verification to an authenticator app, and review recent activity for changes you did not make. Watch specifically for new payees, linked devices, forwarding addresses, and altered contact details, which are the footholds attackers leave behind for a second round.
The rest of day one is for evidence and notifications. Photograph or screenshot everything as you find it: the no-service screen, unauthorized transactions, password reset emails, and timestamps. Notify your bank's fraud department about any suspicious transfers, place a fraud alert or credit freeze with the credit bureaus, and file your FBI IC3 and FTC reports while details are fresh. If cryptocurrency moved, record the transaction hashes and destination addresses exactly; those identifiers are the starting point for tracing.
Day two is verification and cleanup. Confirm the carrier protections are actually in place by attempting nothing less than a full review of the account settings: PIN set, port freeze on, SIM lock enabled. Sweep the long tail of accounts that still reference your number, including shopping, travel, and subscription services. If there is any chance your devices contributed to the attack, stop using them for sensitive logins until they have been examined. This is the point where victims most often bring in Petronella Technology Group, Inc., either to run the forensic examination or to audit that nothing in the first-day scramble was missed, and a single missed forwarding rule or recovery number is exactly the kind of thing a systematic audit exists to catch.
Frequently Asked Questions
What is a SIM swap attack?
A criminal convinces your carrier to transfer your number to their SIM card. They then receive all calls and texts, including SMS 2FA codes, giving access to email, banking, and crypto. The FBI IC3 2024 Annual Report recorded 982 SIM-swap complaints and roughly $26 million in direct losses that year1.
Can I get my number back?
Yes. Contact your carrier immediately. Most reverse the swap within hours once you verify identity. Visit a physical store with government ID for fastest resolution.
How do I prevent future SIM swaps?
Set a unique PIN with your carrier. Enable SIM lock and port freeze. Replace SMS 2FA with app-based authenticators or hardware keys. Consider Google Voice for 2FA numbers.
What does Petronella Technology Group do for SIM swap victims?
Carrier escalation, full account audit, SMS 2FA replacement, device forensics, dark web monitoring, and law enforcement filing assistance. Call (919) 348-4912.
How do criminals get the information needed to impersonate me?
Mostly from data that already exists about you: breach dumps sold on criminal markets, people-search and data broker sites, and your own public social media. Phishing messages and infostealer malware fill in whatever is missing, such as carrier account logins. In some cases attackers recruit insiders at carrier retail stores. This is why our recovery process includes device forensics and a data exposure review, not just getting the number back.
How quickly do I need to act after a SIM swap?
Immediately. The attack is designed to convert control of your number into drained accounts before you can react, and much of the financial damage typically happens within the first couple of hours. Call your carrier the moment your phone loses service unexpectedly, then secure your primary email from a separate clean device. Recovery of the number itself usually takes hours once you verify identity, but the account lockdown race starts the minute the swap happens.
How long does a full recovery take?
Restoring phone service is normally same-day. The full engagement, recovering and re-securing every affected account, completing device forensics, filing law enforcement and bank reports, and migrating your authentication off SMS, typically runs from a few days to about two weeks depending on how many accounts were touched and whether funds or cryptocurrency were stolen. You receive a written timeline and evidence summary at the end.
Will my bank or carrier reimburse stolen money?
It depends on the institution, the type of transfer, and how quickly the fraud was reported and documented. Banks handle unauthorized electronic transfers under their fraud processes, and outcomes improve significantly when you can present a clear, professionally documented timeline showing the account takeover was outside your control. That evidence package is a standard deliverable of our engagements. Cryptocurrency transfers are far harder to claw back, which is why tracing needs to start fast.
Does eSIM protect me from SIM swapping?
Not by itself. eSIM removes the physical card, but the attack targets the carrier's account and porting process, not the plastic. A criminal who convinces the carrier to move your line can have it provisioned to an eSIM on their own device. The protections that matter are the carrier PIN, port freeze, and SIM lock settings, combined with getting SMS out of your authentication entirely.
My cryptocurrency was stolen through the swap. Can it be traced?
Often, yes. Stolen funds move across public blockchains, and professional chain analysis can follow them through intermediary wallets toward exchanges where law enforcement can act. Speed matters enormously. We start tracing as part of the same engagement; see our crypto theft recovery service for how that process works.
Are businesses targeted by SIM swaps, or just individuals?
Both. Attackers use swapped executive and finance-team numbers to intercept verification calls and texts, reset corporate account access, and lend credibility to fraudulent wire requests. A SIM swap against one employee is frequently the opening move of a broader intrusion, so business incidents get an expanded review covering the mail tenant, finance workflows, and wire controls alongside the personal recovery work.
Should I file a police report for a SIM swap?
Yes. File with the FBI IC3 at ic3.gov, the FTC at reportfraud.ftc.gov, and your local police department. Individual reports are rarely investigated in isolation, but they establish the official record your bank and carrier will ask for, and IC3 aggregates complaints into cases that do get worked. We prepare the evidence package and help you file so nothing is missing.
What does the free assessment include?
A confidential conversation about what happened, an initial read on which accounts are most exposed, and a prioritized list of the actions to take right now, whether or not you engage us for the full recovery. If professional help is warranted, we scope it and quote it before any work begins. Call (919) 348-4912 or use the contact form.
SIM swap victims come to us after the worst hour of their digital lives. The job is to end the attack fast, document everything, and make sure the same door can never be opened again.
Recovery engagements are led by Craig Petronella, founder and principal of Petronella Technology Group, Inc., serving clients since 2002. Craig is a CMMC Registered Practitioner and a North Carolina licensed digital forensic examiner (License #604180) with an MIT certification in artificial intelligence and more than 30 years of hands-on cybersecurity and incident response experience. The same team handles emergency incident response for ransomware and network intrusions, so your case is worked with full intrusion-response discipline, not a call-center script.
Related Resources
Every Minute Your Number Is Compromised, Accounts Are at Risk
Attackers move fast after a SIM swap. The sooner you lock down your number and secure your accounts, the less damage they can do.
Citations
- Federal Bureau of Investigation, Internet Crime Complaint Center, 2024 Annual Report. SIM Swap category statistics (982 complaints, approximately $26 million in direct losses). ic3.gov/AnnualReport/Reports/2024_IC3Report.pdf