How the attack works

A SIM swap does not involve touching your phone. The attacker persuades your mobile provider that they are you, and that they need your number moved to a SIM card they control. From that moment every call and text intended for you arrives with them.

In the UK this usually happens one of two ways: a replacement SIM issued on your existing account, or a port to a different network using a Porting Authorisation Code, the PAC. Both routes end in the same place.

What follows is quick. Reset the password on your email using the phone number, then use the email to reset everything else. Bank, exchange, cloud storage. Anything that trusts a code sent by text has already been handed over.

If your phone unexpectedly loses all service and a restart does not fix it, treat it as an attack until proven otherwise. Use another device to contact your provider and to check your email account for password reset activity. The window in which this is recoverable is measured in minutes.

Why the usual advice does not fit the UK

Most guidance on this topic is written for the United States, where networks offer a port-out PIN or passcode you can set on your account. British readers then ring their provider, discover there is no equivalent universal setting, and conclude there is nothing to be done.

The accurate position is messier. UK protections vary by network and by account, and they are not consistently strong. Some networks apply extra verification, such as asking for a date of birth before issuing a PAC, or offering an account level PIN on certain accounts, or a state that forces PAC requests through a human check. Others have been shown to be considerably weaker than that.

Which? published findings in April 2026 documenting UK cases in detail, including one where a network allowed sensitive account changes after scammers repeatedly failed its own security questions, and another where a customer alerted her provider immediately and still waited ten days to get her number back while fraudsters intercepted codes from her bank and email. Ofcom does not set a mandatory timeframe for returning a stolen number.

The honest conclusion: ask your provider what protection exists on your account and apply whatever they offer, but do not treat it as the defence. Design your setup so that losing your number is survivable rather than catastrophic.

The four steps that actually work

1. Secure the email first

Your email account is the real target. The phone number is only the route to it. Put the strongest authentication your provider supports on your primary email, before anything else on this list, and make sure your phone number is not a recovery method on it.

An email account protected by a passkey or a hardware security key cannot be reset by someone holding your SIM, which breaks the chain at the point it matters most.

2. Move two factor authentication off SMS

Any account tied to money should use a hardware key, a passkey, or an authenticator app rather than text messages. Codes sent by SMS are only as secure as your SIM, which is precisely the thing under attack. There is a full article on choosing between them.

3. Ask your network what it can do

Ring them and ask two specific questions: what security is currently applied to my account, and what exactly would someone need to provide in order to move my number to a new SIM or obtain a PAC? The answers tell you how exposed you are, and often prompt them to add whatever extra checks they do offer.

4. Consider a number nobody knows

Level 2 territory, covered in phone privacy. The number attached to your important accounts does not have to be the number printed on your business cards. A separate number used only for account recovery is a target that nobody knows to attack.

Ten minute drill

Decide now what you would do. Which device would you use to call your provider, what is their number, and which accounts would you lock first? Write it down. In the moment, people lose time working out who to ring, and time is the entire resource you have.

Why holders are targeted specifically

SIM swaps are rarely random. Target lists are built from breached databases, social media and public chain analysis, and holders of meaningful Bitcoin sit near the top. Every mention of your holdings, anywhere public, moves you up that list. The cheapest control on this site remains declining to confirm that you hold anything at all.

Sources