Cybersecurity 101back-iconWhat is SIM swapping?

What is SIM swapping?

SIM swapping is a fraud technique that transfers a victim’s mobile number to a SIM card or eSIM controlled by an attacker.

Also called sim hijacking, it lets criminals receive calls, texts, and one-time codes meant for the victim. The main risk is not the SIM itself; it is account takeover through phone-based verification.

How does it work?

Attackers usually begin with phishing attempts, breached personal data, or social engineering against a mobile carrier. They convince the carrier to activate the victim’s number on a new SIM, often by pretending the phone was lost or upgraded.

Once the number moves, the victim may lose service while the attacker receives SMS-based MFA codes, password reset messages, and account alerts. That makes sim hijacking especially dangerous for banking, email, payroll, and administrator accounts.

Attack stage What happens
Reconnaissance Attacker gathers personal details, carrier data, or account answers from leaks, social media, or phishing.
Carrier manipulation Attacker requests a SIM change, eSIM activation, or number port using stolen identity information.
Account takeover Attacker intercepts verification codes and resets passwords before the victim or carrier reacts.

SIM swapping vs SIM cloning

SIM swapping moves the phone number to an attacker-controlled SIM or eSIM through carrier systems. It is usually a social engineering and identity verification failure.

SIM cloning copies SIM identifiers so another device can impersonate the original SIM. Both are cellular fraud, but cloning is more technical while SIM swapping depends more on account manipulation.

How Hexnode supports SIM swapping defense

Hexnode cannot stop a carrier from approving a fraudulent SIM transfer, but it can help reduce the enterprise impact of sim hijacking. The strongest defense combines carrier account PINs, phishing-resistant authentication, and managed endpoint controls.

With Hexnode UEM, IT teams can strengthen mobile device security through passcode policies, compliance checks, application controls, OS update workflows, and remote actions such as lock or wipe. Endpoint visibility also helps teams identify risky devices before granting access to business apps.

When should organizations use it?

Organizations should prioritize sim hijacking defenses when employees use phone numbers for account recovery, SMS-based MFA, help desk verification, or privileged workflows. The risk is higher for executives, finance teams, IT administrators, and customer-facing staff.

It is especially important during BYOD programs, remote work, mergers, and high-risk travel. Reducing dependence on SMS codes and enforcing device compliance can limit the damage even if a phone number is hijacked.

FAQs

No. Most attacks happen through carrier account manipulation or number porting, although stolen phones can make recovery and verification harder.

Sudden loss of mobile service, unexpected password reset alerts, failed calls, and account lockouts are common indicators that a number may have been transferred.

Yes. Passkeys and hardware security keys reduce reliance on SMS codes, making it harder for attackers to turn phone-number control into account access.