Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM What are the signs that a SIM swap…
Identity Beyond IAM

What are the signs that a SIM swap attack may be underway?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 17, 2026 Domain: Identity Beyond IAM

Common warning signs include sudden loss of mobile service, inability to send or receive calls and texts, unexpected password reset prompts, and lockouts from email or financial accounts. A carrier may also report a recent port request that the customer did not authorize. Any unexplained change in phone connectivity should be treated as a potential account takeover.

How to tell a SIM swap is in progress

A sim swap often looks like a sudden, unexplained interruption in mobile connectivity rather than a clean account notification. The key pattern is a change in service state that you did not initiate, especially when it is paired with account recovery prompts or other evidence that someone is attempting to take over your number.

Loss of service matters because the phone number is frequently used as a recovery factor for email, banking, and other high-value accounts. If an attacker succeeds in taking over the number, the disruption at the carrier can quickly become a broader identity compromise.

If the account is tied to The 52 NHI breaches Report, practitioners should think in terms of credential theft and takeover paths, not just telecom outage. Number hijack is usually a means to an end, especially when it precedes password resets or session recovery attempts.

Signals that usually appear before full account loss

The most common signs are sudden inability to send or receive calls and texts, especially after the device had been working normally. That can be accompanied by password reset messages you did not request, unexpected MFA prompts, or login alerts from email and financial services that rely on the phone number for verification.

Another practical signal is a carrier or provider message indicating a port request, SIM change, or number transfer that you did not authorize. In many cases, the first visible symptom is not the carrier event itself but the downstream lockout from the accounts that use the phone number as a recovery path.

The general abuse pattern is consistent with 52 NHI Breaches Analysis, where compromised access material is used to move from one identity checkpoint to another. For this topic, the useful warning is not just “phone stopped working”, it is “phone stopped working at the same time other recovery channels started failing.”

Risk and Threat Considerations

A SIM swap becomes materially dangerous when the mobile number is acting as a recovery or verification control for higher-value accounts. The attacker is often trying to intercept one-time codes, reset credentials, or bypass account recovery, so the mobile outage is a warning sign of a much larger compromise path.

Failure mechanism: A successful swap or port-out severs the victim’s control of the number and reroutes calls and texts to the attacker, allowing password resets, recovery flows, and MFA challenges to be intercepted.

Impact: The result can be email takeover, financial fraud, social account compromise, and loss of the victim’s ability to receive alerts or recover affected accounts quickly.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS 6 — Access Control ManagementSIM swap signs often precede account takeover via recovered credentials.
CIS 8 — Audit Log ManagementCarrier and account alerts are the earliest evidence of takeover activity.
Recommendation — Review and revoke exposed recovery paths, then reduce SMS-based recovery dependence. Centralise and monitor login, recovery, and port-change alerts for rapid triage.
NIST CSF 2.0DE.CM — Continuous MonitoringEarly detection depends on noticing service loss and unexpected account activity quickly.
Recommendation — Monitor identity and account events for unexplained number-transfer and recovery activity.
MITRE ATT&CKT1111 — Multi-Factor Authentication InterceptionSIM swaps are commonly used to intercept SMS-based verification flows.
T1098 — Account ManipulationAttackers use the swapped number to reset access and alter account recovery settings.
Recommendation — Assume SMS-delivered codes are exposed and move high-risk accounts to stronger factors. Investigate recent recovery and MFA changes as potential account-manipulation activity.

Practitioner Guidance

What to prioritise: Treat unexplained loss of mobile service as an account takeover event until proven otherwise. The immediate priority is to contact the carrier through a verified channel, freeze or reverse the port request if possible, and check whether any critical accounts are using SMS for recovery.

What to verify: Confirm whether the outage is limited to one device or affects the number itself, because a device problem and a number transfer are different incidents. Verify recent changes to recovery email, MFA settings, and account login history so you can distinguish telecom failure from active compromise.

Practitioner takeaway: The most important judgement is speed, once the number is unavailable and recovery prompts begin, assume the attacker may already be inside the account recovery path and act before trying to diagnose the carrier event in detail.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 17, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org