Join our Newsletter — 33% off our NHI Course
Authentication, Authorisation & Trust

SIM-jacking

← Back to Glossary
By NHI Mgmt Group Updated October 11, 2026 Domain: Authentication, Authorisation & Trust

SIM-jacking is the takeover of a mobile number so an attacker can intercept calls or SMS messages sent to that line. It matters for authentication because SMS-based 2FA depends on the number remaining under the legitimate user’s control, not just the device itself.

How SIM-jacking works

SIM-jacking is a number takeover, not a device compromise. The attacker aims to move the victim’s phone number onto a SIM or eSIM they control, so inbound calls and text messages are delivered to them instead of the legitimate user.

The practical significance is that the phone number is often treated as a trusted recovery and verification channel. Once that number is diverted, the attacker can receive one-time codes, password reset links, and voice callbacks that were meant to confirm the real user’s control of the account.

Why SIM-jacking breaks authentication assumptions

Many systems still use the mobile number as a weak proxy for identity, especially where SMS-based 2FA is used. That model assumes the carrier route to the number remains trustworthy, but SIM-jacking severs that assumption and lets an attacker inherit the trust placed in the line.

This is why the issue is not limited to phone service abuse. It affects the authentication layer itself, because the authentication decision may hinge on possession of the number rather than possession of the original device, strong cryptographic proof, or a phishing-resistant factor.

For organisations that want stronger identity assurance, NIST SP 800-63 Digital Identity Guidelines are a useful reference point for understanding why authenticator strength matters more than convenience-based SMS verification.

Common takeover paths and enabling conditions

SIM-jacking usually succeeds through a process weakness rather than technical malware on the target phone. Attackers may abuse carrier support procedures, social engineering, insider access, or exposed personal data to convince a carrier to port the number or issue a replacement SIM.

The attack is especially effective when accounts reuse the same phone number for login, account recovery, and high-value approvals. A single compromised number can then become a pivot into email, financial services, messaging, and any system that still trusts SMS delivery as proof of control.

At the control level, NIST Cybersecurity Framework 2.0 helps frame the issue as both an identity assurance problem and a resilience problem, because prevention, detection, and recovery all matter when a recovery factor can be hijacked.

Security consequences and safer alternatives

The main consequence of SIM-jacking is account takeover through a trusted-but-intercepted channel. Once the attacker receives authentication traffic, they can reset passwords, approve sign-ins, intercept transaction codes, and lock the legitimate user out of recovery paths.

Risk is highest when SMS is the only second factor or when the phone number doubles as the account recovery mechanism. Stronger options include phishing-resistant authenticators, app-based cryptographic factors, and recovery flows that do not depend on the same telephone number the attacker is trying to steal.

For teams that are replacing legacy SMS dependence, phishing-resistant authentication guidance is the clearest benchmark for designing a safer path away from number-based verification.

Risk and Threat Considerations

SIM-jacking is dangerous because it turns a telecom routing change into an authentication bypass. The attacker does not need to break the cryptography of the service they are targeting; they only need to become the recipient of the SMS or voice channel that the service treats as proof of control.

Failure mechanism: carrier takeover or number porting diverts the victim’s messages and calls to the attacker, allowing reset codes and login challenges to be intercepted.

Impact: account takeover, loss of recovery access, unauthorized transactions, and broader compromise of linked services can follow, especially where the phone number is the last remaining recovery factor.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-63Digital Identity GuidelinesDefines authenticator assurance and phishing-resistant authentication for SMS-reliant access.
Recommendation — Replace SMS-based verification with phishing-resistant authenticators and recovery flows.
NIST CSF 2.0PR.AA-05 — Protective Technology, Identity Management, Authentication and Access ControlSIM-jacking exploits weak identity and access assumptions around a phone number.
RC.RP-01 — Recovery Plan ExecutedA hijacked number can cut off the legitimate user’s normal recovery path.
DE.CM-06 — External service provider activities are monitoredCarrier-side takeover attempts depend on monitoring externally managed access paths.
Recommendation — Reduce reliance on SMS factors and enforce stronger authentication controls. Verify account recovery procedures still work without the compromised phone number. Monitor carrier and account recovery activity for anomalous number-porting events.

Practitioner Guidance

What to watch for: Treat SMS as a recovery convenience, not a high-assurance authenticator. If a system still depends on a phone number for critical access, replace it with a stronger factor and add alternate recovery paths that do not collapse when the number is moved.

For user education and policy, the key judgement is to separate device possession from number possession. A user can still hold the phone while the attacker controls the number, so operational ownership of the line must not be mistaken for proof of the account holder.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org