Responsibility is shared, but the carrier is the key control point because it authorizes number porting. Security and fraud teams should enforce stronger identity checks, customers should enable port locks and avoid SMS verification, and banks or exchanges should not treat a phone number as a strong proof of identity. Effective prevention requires coordination across all three.
Shared accountability starts with the control point, not the blame point
sim swap fraud sits at the intersection of telecom identity proofing, account recovery design, and downstream fraud prevention. The carrier is usually the control point with the decisive authority to port or rebind a number, but the organisation using that number for recovery also influences whether the number becomes a weak recovery factor. That is why accountability is shared, even if the carrier owns the highest-leverage control.
When a mobile number is treated as a recovery credential, the security model shifts from “customer convenience” to “who can reliably resist takeover of the number itself.” A phone number can be useful for notification or step-up friction, but it is a weak standalone proof of identity for sensitive recovery. That distinction matters because the attacker does not need to defeat the whole account system, only the recovery path.
For background on how identity-bearing access material can become the weak link in an access chain, see NHIMG’s Ultimate Guide to NHIs section on identity and access material and the broader Ultimate Guide to Non-Human Identities. The same practical lesson applies here: if the recovery factor is easy to rebind, the rest of the control stack becomes much easier to bypass.
Why carriers, security teams, and customers all have distinct duties
The carrier should own anti-fraud checks for SIM change, port-out, and account reset requests because it controls the lifecycle event that makes SIM swap possible. Security and fraud teams at the relying organisation should decide whether a phone number is allowed to recover accounts at all, and they should add stronger verification for high-risk resets. Customers still have an active role, but only as a last layer of defence, not as the primary control.
That division of responsibility is important because each party can only control one part of the chain. Carriers can harden identity verification and porting workflows. Banks, crypto exchanges, and other relying parties can stop over-trusting SMS as a factor and can require step-up methods that are resistant to number transfer. Customers can reduce exposure by enabling carrier port locks and by moving account recovery away from SMS where a stronger option exists.
Carrier controls are only partially visible to the organisations relying on them, so governance should assume some residual failure risk. If a business continues to rely on SMS recovery, it should treat that as a compensating control with known limits rather than as a strong authenticator. For practitioners, the question is not whether SMS is convenient, but whether it is suitable for the account value and the likely fraud impact.
What strong practice looks like when mobile recovery is in scope
Effective prevention is mostly about removing weak assumptions. The best outcome is one where account recovery does not depend on possession of a phone number alone, and where the carrier, fraud team, and customer each have a clear escalation path for suspicious number changes. For sensitive accounts, recovery should be bound to stronger methods than SMS, especially where takeover would enable financial transfer, data access, or further identity compromise.
- What to verify: Confirm that carrier port-out and SIM change events are protected by additional identity checks, not just routine customer service workflows.
- What to prioritise: Replace SMS-based recovery for high-value accounts with stronger step-up methods and recovery options that are harder to rebind.
- What to measure: Track how many account recoveries still depend on SMS and how often SIM change alerts trigger fraud review.
- Common mistake: Treating the phone number as proof of identity instead of treating it as a mutable delivery channel.
NHIMG’s broader identity guidance also shows why recovery design matters at scale. In Dropbox Sign breach, Internet Archive breach, and similar credential exposure events, the lesson is that whichever factor can be reset or reused fastest becomes the practical route for takeover. For mobile-number recovery, the carrier is the gatekeeper, but the relying organisation decides whether that gate should be trusted at all.
Risk and Threat Considerations
SIM swap fraud is attractive because it converts a telecom workflow into account access. Once an attacker takes over a number, they can intercept one-time codes, trigger password resets, and sometimes pivot into banking, exchange, or enterprise accounts that still trust SMS for recovery.
Failure mechanism: Weak or socially engineered carrier verification allows a number to be ported or reissued to the attacker, and SMS-based recovery turns that compromise into account takeover.
Impact: The result can be unauthorized access, financial theft, locked-out customers, and a wider fraud chain if the stolen number is reused to reset additional accounts.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while CIS Controls v8, NIST CSF 2.0 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | 6 — Access Control Management | SMS recovery risk is reduced by limiting account recovery paths and privileged access. |
| 8 — Audit Log Management | SIM swap and recovery events need alerting and review to detect takeover attempts. | |
| Recommendation — Restrict recovery pathways and require stronger verification for sensitive account resets. Log and review number-change, recovery, and reset events for fraud indicators. | ||
| NIST CSF 2.0 | PR.AA — Identity Management, Authentication, and Access Control | The question centers on whether a phone number should be trusted for account recovery. |
| GV.RM — Risk Management Strategy | Responsibility allocation between carrier, customer, and relying party is a governance decision. | |
| Recommendation — Treat mobile-number recovery as a weak authenticator and strengthen account recovery controls. Assign recovery risk ownership and set policy for when SMS-based recovery is prohibited. | ||
| NIST SP 800-63 | IAL — Identity Assurance Level | Phone-number recovery depends on the strength of identity proofing behind reset decisions. |
| AAL — Authentication Assurance Level | SMS is a weak authenticator for recovery of high-value accounts. | |
| FAL — Federation Assurance Level | Recovery flows often depend on downstream identity federation and session re-establishment. | |
| Recommendation — Use higher-assurance recovery methods when account impact exceeds low-assurance verification. Require stronger authenticators than SMS for recovery of sensitive accounts. Align recovery assurance with the trust level required for downstream sessions and federation. | ||
| OWASP Non-Human Identity Top 10 | NHI-01 — Secrets and Credential Management | SIM-based recovery failures often lead to credential reset and abuse of recovery secrets. |
| NHI-04 — Privilege and Access Governance | Recovery paths should not grant excessive authority when a number is changed or reused. | |
| NHI-06 — Lifecycle and Offboarding | Number changes and recovery re-binding are lifecycle events that create takeover exposure. | |
| Recommendation — Eliminate SMS as a sole recovery secret for high-value accounts. Bound recovery authority and require step-up checks before granting privileged resets. Treat number reassignment and recovery re-enrolment as controlled lifecycle events. | ||
Practitioner Guidance
What to prioritise: Decide which accounts are too sensitive to recover through SMS at all, then remove that path first for privileged users, financial accounts, and support workflows that can change credentials quickly.
What to verify: Make sure SIM change and port-out events are routed into fraud monitoring or step-up review, and confirm that customers can see and act on carrier security features such as port locks.
Decision rule: If a number change can unlock money movement or high-value data access, treat SMS as a fallback notification channel, not as an identity proof.
Practitioner takeaway: SIM swap prevention is a shared duty, but the most important design decision is whether your organisation will continue to trust a phone number as a recovery factor after its control can be transferred outside your environment.
Related resources from NHI Mgmt Group
- Who is accountable when a fraud model misses account takeover or SIM swap abuse?
- Who is accountable when a compromised business account is used for ad fraud or SSO pivoting?
- Who is accountable when an executive account is used for fraud after MFA success?
- Who is accountable when a compromised official account is used for fraud or surveillance?