The Complete Guide to SIM Swap Protection & Carrier Account Security
Your phone number has quietly become the master key to your entire digital life. Bank logins, email recovery, crypto exchanges, social media — nearly all of them will fall back to a text message when you click "forgot password." That is exactly why criminals no longer need to steal your phone. They steal your number. This guide explains how SIM swap and port-out fraud actually work, walks through the free protection tools every major US carrier now offers, and shows you how to lock your number down in under fifteen minutes.
What a SIM Swap Actually Is
A SIM swap (also called SIM jacking or SIM hijacking) happens when an attacker convinces your carrier to move your phone number onto a SIM card or eSIM that they control. The moment the transfer completes, your phone drops to "No Service" and every call, text, and two-factor authentication code meant for you lands on the attacker's device instead.
From there the playbook is fast and brutal. The attacker triggers password resets on your email, then uses the email to reset everything else. Banking apps, payment platforms, and cryptocurrency exchanges are the priority targets because that's where the money is. Victims routinely report losing access to dozens of accounts within the first hour — before they've even figured out why their phone stopped working.
The FBI's Internet Crime Complaint Center logged 982 SIM-swap complaints with roughly $26 million in reported losses in 2024 alone, and security researchers consider that a significant undercount since many victims report the downstream theft (the drained bank account) rather than the SIM swap that enabled it.
SIM Swap vs Port-Out Fraud: Two Different Attacks
People use "SIM swap" as a catch-all, but there are actually two distinct attacks, and the carrier tools that stop them are different:
- SIM swap: Your number stays with your current carrier, but it's moved to a new SIM or eSIM. The attacker impersonates you to customer support ("I lost my phone, can you activate my new SIM?") or bribes a retail employee. Blocked by SIM protection / SIM lock features.
- Port-out fraud: Your number is transferred to an entirely different carrier the attacker controls. This uses the same legitimate porting system you'd use when switching from one carrier to another. Blocked by number locks, port freezes, and transfer PINs.
Full protection means enabling both types of locks. Since 2023, FCC rules have required carriers to offer stronger safeguards against both attacks, which is why every major carrier now has free, user-controlled tools — but almost all of them ship turned off by default. You have to flip the switches yourself.
How to Lock Your Number at Every Major Carrier
Carrier app menus get reshuffled constantly, so if a setting name below doesn't exactly match what you see, search the carrier's app or support site for "SIM protection" or "number lock" and you'll land on the current equivalent.
AT&T: Wireless Account Lock
AT&T rolled out Wireless Account Lock to all customers in 2025, and it's one of the most comprehensive implementations. On a standard postpaid account it's a single master switch that covers every line and device on the account — phones, tablets, wearables, and hotspots. When enabled, it blocks SIM swaps, number transfers, and even billing changes, including changes attempted from inside an AT&T retail store.
- Open the myAT&T app (it must be installed on a device active on your account).
- Tap the person/profile icon.
- Scroll to Wireless Account Lock and switch it on.
On AT&T Prepaid the path runs through Profile & Settings › Account Info & Preferences › Wireless Account Lock, and you lock one number at a time, validating each change with an SMS code.
Verizon: SIM Protection + Number Lock
Verizon splits its defenses into two separate toggles, and you want both:
- Open the My Verizon app and sign in with Account Owner or Manager access.
- Go to Account › Profile and settings › Security settings.
- Turn on Number Lock — this blocks your number from being ported out to another carrier. While it's on, no one can even generate a Number Transfer PIN for your line.
- Turn on SIM Protection — this blocks SIM card and eSIM changes on the line.
Verizon sends a notification any time either setting is toggled, so you'll know immediately if someone who has compromised your online account tries to disarm your protections. Both features are also available on Verizon Prepaid.
T-Mobile (and Metro): SIM Protection + Port Out Protection
T-Mobile overhauled its SIM security system in 2025. Current protections include:
- SIM Protection: a per-line or account-wide toggle in the T-Life app or web portal that blocks SIM and eSIM changes. Removing the lock can require photo ID verification in a store — a deliberately high bar.
- Port Out Protection: found under your line's add-ons (Account › your line › Manage add-ons › Services), this blocks number transfers to other carriers.
- Account PIN: every T-Mobile account requires a 6–15 digit PIN, and a number cannot be ported without it. Make yours long and never reuse a PIN from anywhere else.
Metro by T-Mobile customers get equivalent protections through their Metro account settings.
MVNOs and Prepaid Carriers
Budget carriers were slower here, but the picture has improved substantially. Mint Mobile now offers user-controlled SIM protection settings, Google Fi supports account-level security controls tied to your Google account (which means hardware-key protection is possible — more below), and US Mobile offers port-out locks through its dashboard. If your MVNO offers nothing beyond an account PIN, weigh that seriously in your next carrier decision — a $15/month plan is no bargain if it leaves the master key to your bank account under the doormat.
Beyond the Carrier: Close the SMS Back Door
Carrier locks dramatically raise the cost of an attack, but the deeper fix is making your phone number worthless to steal. That means removing SMS as the recovery path for your most important accounts.
- Switch 2FA from SMS to an authenticator app (or better, passkeys) on email, banking, and any crypto or investment account. If an account supports both, delete the phone number as a recovery option after adding the app.
- Protect your email account above all else. Email is the recovery hub for everything. Google, Microsoft, and Apple accounts all support hardware security keys and passkeys that no SIM swap can touch.
- Use a hardware security key for your highest-value accounts. A physical key like a YubiKey means possession of your number — or even your password — isn't enough to get in.
- Set a device-level SIM PIN. In iOS (Settings › Cellular › SIM PIN) or Android (Security settings), this locks the physical SIM itself so it can't be popped into another phone and used. Note this protects the physical card, not the number — you still need the carrier locks above.
- Turn on account-change alerts with your carrier and your bank so any SIM change, port request, or new-device login pings you instantly.
Warning Signs an Attack Is In Progress
Speed matters enormously in a SIM swap. The typical drain happens within the first hours. Treat any of these as a fire alarm:
- Your phone suddenly shows "No Service" or "SOS only" in an area where you normally have coverage, and rebooting doesn't fix it.
- You receive a text about a SIM change, port request, or Number Transfer PIN you didn't initiate.
- You get password-reset emails you didn't request, or you're suddenly logged out of accounts.
- Your carrier app rejects your login, or shows a device you don't recognize.
What to Do If You've Been SIM Swapped
- Call your carrier immediately from another phone and tell them your number has been fraudulently transferred. Ask them to suspend the line, reverse the swap, and flag the account for fraud.
- Lock down email first, then banks. From a trusted device, change your email password, revoke unknown sessions, and remove your phone number as a recovery method. Then contact banks and freeze anything the attacker may have touched.
- Contact any crypto exchanges promptly — these are typically the first accounts drained and the least reversible.
- File reports. Report to the FBI's Internet Crime Complaint Center (ic3.gov) and the FTC (identitytheft.gov). These reports matter for reimbursement disputes with banks.
- Consider a credit freeze at all three bureaus, since attackers often harvest enough personal data during the attack to open new accounts.
Does Any of This Make You Un-Hackable?
No security measure is absolute — insider fraud at carriers has defeated locks before, and determined, targeted attackers (the kind that go after people with large public crypto holdings) have more tools than opportunists. But SIM swapping is mostly a crime of opportunity, and opportunists take the unlocked doors. An account with carrier-level SIM and port locks, a strong unique PIN, and no SMS recovery on critical accounts is simply not worth the effort when millions of unprotected numbers are a phone call away.
The protections in this guide cost nothing and take a single evening to set up across your whole family's lines. Of everything we cover on this site — saving $20 on a plan, squeezing more hotspot data out of a tier — this is the highest-value fifteen minutes you'll spend on your phone account this year.
Why Attackers Target Phone Numbers Instead of Passwords
It helps to understand the economics driving this crime, because they explain both why it exploded and why the defenses work. Passwords got harder to steal at scale: password managers, breach alerts, and mandatory 2FA closed the easy doors. But the industry's answer to weak passwords — texting a code to your phone — quietly moved the vulnerability rather than eliminating it. A six-digit SMS code proves only one thing: that the holder of the code controls the phone number. Steal the number, and every SMS-protected account inherits the theft.
That's why victims skew toward people with something worth taking quickly: crypto holders whose exchange accounts empty irreversibly, small-business owners whose payment platforms move real money, and increasingly ordinary people whose bank happens to allow SMS-only recovery. It's also why the attack often begins with reconnaissance you never see — a phishing email that harvests your carrier login, a data-breach record with your account number and billing ZIP, or simply your number and email scraped from a people-search site. The less of that raw material floating around, the harder you are to impersonate, which is why the privacy habits covered in our privacy-focused plans guide double as SIM-swap defense.
Special Cases Worth Extra Attention
Family plans and account managers
On a family plan, the account owner's credentials protect every line. A teenager's recycled password can be the way in to a parent's number, because customer support and online portals operate at the account level. Enable account-wide locks where offered (AT&T's master switch covers all lines), give every authorized user unique credentials, and treat the account PIN as family-critical information — shared carefully, reused nowhere.
Small business lines
A hijacked business number reroutes customers, intercepts payment confirmations, and can compromise every platform the business logs into. If a number appears on your trucks or your storefront, it deserves the strongest lock your carrier offers and a documented recovery plan. Our business plans guide covers ownership structures that keep numbers recoverable when staff change.
eSIM-era wrinkles
eSIM made legitimate transfers instant — and fraudulent ones too. An attacker with your carrier login can sometimes provision your number to a new device entirely online, no store visit, no physical card. This is precisely what SIM protection toggles block, and it's why securing the carrier account itself (unique password, app-based 2FA on the carrier login where offered) matters as much as the line-level locks.
A Layered Model to Remember
Security people think in layers, and the SIM-swap version is simple enough to memorize. Layer one, the carrier account: unique password, strong PIN, alerts on. Layer two, the line: SIM protection and number/port locks enabled. Layer three, the accounts behind the number: SMS removed as 2FA and recovery wherever something valuable lives, replaced by authenticator apps, passkeys, or hardware keys. Layer four, exposure: your number circulating in fewer public places. Any single layer can fail; the combination almost never does, because each layer defeats a different step of the attack chain. An attacker who phishes your carrier password hits the line locks. One who defeats the locks through an insider finds your bank doesn't trust SMS anyway. The fifteen-minute checklist earlier in this guide builds layers one through three; the fourth accrues over time as you tighten where your number lives.
Frequently Asked Questions
Is SIM swapping still common in 2026?
Yes. The FBI's Internet Crime Complaint Center logged 982 SIM-swap complaints with about $26 million in losses in its 2024 report, and researchers consider that an undercount. The good news is that FCC rules now require carriers to offer stronger protections, and all three major US carriers provide free SIM and port-out locks — they just ship disabled by default.
Do carrier SIM locks cost anything?
No. AT&T Wireless Account Lock, Verizon SIM Protection and Number Lock, and T-Mobile SIM Protection and Port Out Protection are all free features you enable in the carrier's app or web account. Several MVNOs including Mint Mobile and US Mobile now offer free equivalents.
Will a number lock cause problems when I legitimately switch carriers or phones?
Only in the sense that you must remember to disable the lock first. If you're porting your number to a new carrier, turn off the number/port lock, complete the transfer, and the new carrier's protections take over. For a new phone on the same carrier, temporarily disable SIM protection, activate the new device, then re-enable it.
Is a SIM PIN on my phone the same as carrier SIM protection?
No. A device-level SIM PIN locks the physical SIM card so it can't be used in another handset. Carrier SIM protection stops your number from being assigned to a different SIM or eSIM entirely. A SIM swap attack never touches your physical card, so you need the carrier-side locks — the device PIN is a useful extra layer, not a substitute.
What's the single most important step if I only do one thing?
Remove SMS as the two-factor and recovery method on your primary email account and replace it with an authenticator app or passkey. Email is the recovery hub for everything else you own, and securing it makes your phone number a far less valuable target.