# sim-swap

Source: https://startwithidentity.com/glossary/sim-swap/
Last updated: 2026-09-29
License: content by Start with Identity. Cite the source URL.

---

A SIM swap is an attack in which a criminal gets a victim's mobile number moved to a SIM or eSIM they control, usually by deceiving or bribing mobile carrier staff, so that calls and text messages for that number, including one-time codes, go to the attacker.

SIM swapping defeats SMS and voice MFA and, more damagingly, SMS-based account recovery, which often resets both the password and the second factor at once. It is one reason NIST's digital identity guidelines have treated codes sent over the public telephone network as a restricted authenticator since 2017, and in the United States the FCC adopted rules in 2023 requiring carriers to authenticate customers before SIM changes and number transfers. The durable fix is to stop relying on the phone number: move sign-in to [passkeys](https://startwithidentity.com/glossary/passkey/) or other [phishing-resistant MFA](https://startwithidentity.com/glossary/phishing-resistant-mfa/), and remove SMS from recovery for high-value accounts. Microsoft Entra ID is [ending the SMS and voice codes it delivers itself in 2027](https://startwithidentity.com/blog/2026-09-21-entra-id-stops-delivering-sms-and-voice-codes-february-1-and-global-admins-go-last/).

See also: [MFA](https://startwithidentity.com/glossary/mfa/), [account recovery](https://startwithidentity.com/glossary/account-recovery/), [account takeover](https://startwithidentity.com/glossary/account-takeover/), [OTP relay social engineering](https://startwithidentity.com/techniques/otp-relay-social-engineering/)
