Start with Identity
Threat

SIM Swap

A SIM swap is an attack in which a criminal gets a victim's mobile number moved to a SIM or eSIM they control, usually by deceiving or bribing mobile carrier staff, so that calls and text messages for that number, including one-time codes, go to the attacker.

SIM swapping defeats SMS and voice MFA and, more damagingly, SMS-based account recovery, which often resets both the password and the second factor at once. It is one reason NIST's digital identity guidelines have treated codes sent over the public telephone network as a restricted authenticator since 2017, and in the United States the FCC adopted rules in 2023 requiring carriers to authenticate customers before SIM changes and number transfers. The durable fix is to stop relying on the phone number: move sign-in to passkeys or other phishing-resistant MFA, and remove SMS from recovery for high-value accounts. Microsoft Entra ID is ending the SMS and voice codes it delivers itself in 2027.

See also: MFA, account recovery, account takeover, OTP relay social engineering

Last reviewed By SWI Community TeamSuggest a correctionHow we research