Join our Newsletter — 33% off our NHI Course

SIM Attack

A SIM attack is a phone number takeover technique where an attacker transfers or hijacks a victim’s mobile number to receive calls and text messages. It can defeat SMS based second factors and account recovery flows. High value targets are especially exposed because their phone number often anchors multiple services.

How SIM attacks work

A SIM attack succeeds by moving a victim’s mobile number to attacker-controlled SIM hardware or an eSIM profile. Once the number routes to the attacker, calls and SMS messages, including one-time codes, are delivered to the wrong party.

The practical detail that makes this technique effective is not the phone itself, but the trust many services place in the number. If a bank, email provider, or cloud account uses SMS for login or recovery, a successful number takeover can become a fast path into multiple accounts.

In that sense, the attack is both a telecom abuse case and an access-path compromise. The real objective is to intercept communications that were intended to prove control of the account holder’s phone number.

Why SIM attacks are so effective

SIM attacks work because mobile numbers are often treated as long-lived identity anchors. People reuse the same number for years, so a single takeover can unlock password resets, recovery links, and text-based MFA across many services at once.

They are also effective because the victim may not notice the handoff immediately. A device can lose service abruptly, but by the time the user realises what happened, the attacker may already have used the number to reset passwords, approve logins, or intercept sensitive messages.

For high-value targets, the risk increases further because the number is often tied to business email, financial services, and administrative tooling. That makes the mobile account a dependency that sits outside the application perimeter but still influences account security.

Security implications of phone number takeover

A SIM attack can defeat SMS-based second factors and undermine recovery flows that were meant to be a fallback. If the phone number is the trusted recovery channel, the attacker may not need the original password for long, because the reset process itself becomes the entry point.

The consequence is broader than one compromised account. A successful takeover can cascade into mailbox access, password manager resets, and session hijacking, especially when the victim uses the same number across multiple high-value services.

The strongest defensive lesson is that telephone numbers are not reliable proof of possession on their own. They should be treated as a convenience channel, not as a durable security boundary, especially where account recovery or administrative access is involved.

How organisations reduce exposure

Organisation-level exposure is lowered when the number is no longer the primary recovery factor. Stronger methods include phishing-resistant authentication, tighter recovery controls, and clear verification steps for number changes or account recovery requests.

Monitoring matters as well, because number-port events, sudden loss of service, and unexpected MFA resets can be early indicators of abuse. Where a service still depends on SMS, The 52 NHI breaches Report is useful background on how identity compromise and credential abuse translate into real-world access loss, and CISA’s cyber threat advisories remain a practical source for current attack patterns and defensive context.

Practitioner note: the common failure is not the SIM swap itself, but the decision to let a phone number act as both recovery mechanism and second factor. That design turns a telecom event into an account compromise event.

Risk and Threat Considerations

SIM attacks create concentrated account takeover risk because one phone number can anchor many downstream services. They also create a time-sensitive threat window, since the attacker can exploit number control quickly before the victim or provider detects the loss.

Failure mechanism: The attacker gains control of SMS delivery by porting or reissuing the number, then uses trusted text messages and recovery flows to reset credentials, intercept codes, or approve sessions.

Impact: The result can include mailbox takeover, financial fraud, identity recovery lockout, and broader compromise of linked accounts that depend on the same number.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
CIS Controls v8 6 — Access Control Management SIM attack defense depends on reducing reliance on SMS-based access paths.
Recommendation — Reduce SMS dependence and enforce stronger account access paths.
NIST CSF 2.0 PR.AA — Identity Management, Authentication and Access Control SIM attacks exploit weak authentication and recovery tied to a phone number.
DE.CM — Security Continuous Monitoring SIM takeover often shows up as abrupt service loss or recovery anomalies.
RS.MI — Incident Mitigation A takeover needs rapid containment once SMS interception is suspected.
Recommendation — Harden authentication and recovery so phone-number control is not sufficient. Monitor for number-port, MFA-reset, and recovery anomalies. Contain account abuse quickly when number takeover indicators appear.
MITRE ATT&CK T1556 — Modify Authentication Process Hijacking a phone number to intercept SMS challenges alters authentication paths.
T1111 — Multi-Factor Authentication Interception SIM attacks directly intercept SMS-based MFA codes.
Recommendation — Hunt for authentication interception and recovery abuse patterns. Prioritise phishing-resistant MFA to remove SMS interception value.

Practitioner Guidance

Why practitioners should care: If your service still uses SMS for MFA or recovery, a SIM attack can bypass protections that otherwise look strong on paper. The risk is highest where the number is used across several services, because one takeover can create a multi-account incident.

What to watch for: Unexpected loss of mobile service, delayed texts, account recovery prompts the user did not initiate, or notifications about phone number changes should be treated as possible takeover signals. Escalation should be fast because the attacker’s advantage is usually short-lived but highly effective.