SIM Swap
A SIM swap is an attack in which a criminal gets a victim's mobile number moved to a SIM or eSIM they control, usually by deceiving or bribing mobile carrier staff, so that calls and text messages for that number, including one-time codes, go to the attacker.
SIM swapping defeats SMS and voice MFA and, more damagingly, SMS-based account recovery, which often resets both the password and the second factor at once. It is one reason NIST's digital identity guidelines have treated codes sent over the public telephone network as a restricted authenticator since 2017, and in the United States the FCC adopted rules in 2023 requiring carriers to authenticate customers before SIM changes and number transfers. The durable fix is to stop relying on the phone number: move sign-in to passkeys or other phishing-resistant MFA, and remove SMS from recovery for high-value accounts. Microsoft Entra ID is ending the SMS and voice codes it delivers itself in 2027.
See also: MFA, account recovery, account takeover, OTP relay social engineering
Related on Start with Identity
- GlossaryVishing (Voice Phishing)
Vishing, short for voice phishing, is social engineering carried out over a phone call, in which an attacker impersonates a trusted party to get the target to r
- GlossaryPassword Spraying
Trying a few common passwords across many accounts to avoid lockouts. Effective against weak password policies and accounts without MFA. Spraying is designed to
- GlossaryAuthenticator Assurance Level (AAL)
NIST 800-63B levels describing authentication strength. AAL1: single factor. AAL2: multi-factor. AAL3: multi-factor with phishing-resistant cryptographic authen
- CVEOkta Verify for Windows local privilege escalation
Okta Verify on Windows could be turned into a local privilege escalation. The MFA app on the endpoint is part of the identity plane. Pair with Okta's 2024 FastP
- BlogThe SMS off-ramp has a date now: what Entra, GOV.UK and America.gov mean for your MFA plan
Microsoft stops delivering SMS and voice codes in Entra ID on February 1, 2027. The UK has put passkeys in front of 23 million citizens, and the new federal fro
- CVEZimbra ZCS chained with CVE-2025-48700 to steal MFA backup codes
Zimbra Collaboration Suite, chained with CVE-2025-48700, was used to steal MFA backup codes and app passwords (CERT-UA UAC-0233). Added to CISA KEV in mid-March