Identity · guide

SIM swap: what it is, and the free lock at your carrier

By Alberto Gulotta · Updated · 20 min read

A SIM swap moves your phone number to somebody else’s SIM card, so their phone receives your calls, texts and verification codes. The first sign is your own phone going quiet. The defence is a free lock every large carrier offers, under a different name at each one.

Nothing on this page is a product. The three locks below are free, they are described here in each carrier’s own words with the date the page was read, and the rest comes from the FTC, the FCC and the United States wireless industry body.

How a number is moved to somebody else’s SIM, and where the codes go afterwards The FTC describes the sequence: somebody calls your mobile provider and says the phone was lost or damaged, asks for a new SIM card connected to your number to be activated on a phone they own, and if the provider believes it, all your calls, texts and data go to that phone instead. Verizon adds that the first sign is often simply that your own phone stops working. From there, any account that sends its verification code by text message sends it to the new phone. THE SEQUENCE, AS THE FTC DESCRIBES IT 1 A call to your carrier they say “your phone was lost or damaged” 2 A new SIM is activated on your number, on a phone they own 3 Your phone goes quiet no calls, no texts, no data — and that is the sign Then every code sent by text goes to the other phone The FTC: they “could log in to your accounts that use text messages as a form of multi-factor authentication” — the bank, the email, the social accounts. AI Tools Primer · figure
The sequence and the quoted wording are the FTC’s, from its consumer alert on SIM swap scams. Figure drawn by AI Tools Primer.

What a SIM swap is, and the one sign that comes first

A SIM swap is not a break-in to your phone. Nothing is installed, nothing is downloaded, and the phone in your hand is not the thing that was attacked: your mobile account was. Verizon defines it as the case where “a customer’s phone number is transferred to a different SIM card or eSIM profile under the control of a criminal”, and adds, in the same definition, that “not all SIM changes are bad”, because the same operation is what happens when you upgrade a handset or replace a lost one.

The FTC describes the method from the outside: “They may call your cell phone service provider and say your phone was lost or damaged. Then they ask the provider to activate a new SIM card connected to your phone number on a new phone — a phone they own.” And it names the consequence in the same paragraph: “If your provider believes the bogus story and activates the new SIM card, the scammer — not you — will get all your text messages, calls, and data on the new phone.”

The first sign is silence. Verizon puts it as plainly as anyone: “In some cases, you might not know this has even happened until your phone no longer works.” A phone with full battery and no service, in a place where it normally has service, is worth thirty seconds of suspicion rather than a restart. CTIA, the United States wireless industry body, gives the same advice from the other side: “If you stop receiving any calls or texts, and you don’t know why, contact your wireless provider immediately.”

Why a phone number is worth stealing

The value is not the number. It is everything that treats the number as proof of who you are. The FTC: whoever controls it “could log in to your accounts that use text messages as a form of multi-factor authentication”, because “they’ll get a text message with the verification code they need to log in” — the same codes that, arriving when nobody asked for them, are the first sign anybody usually gets. Verizon lists the destinations from its own side: one-time security codes from “social media, banks, credit card companies, cryptocurrency exchanges, and other financial institutions”.

The FTC also names the second use, which is quieter and slower: the person holding your number “could open new cellular accounts in your name or buy new phones using your information”.

This is the part that changes what you should do about two-factor authentication in general. The FTC’s own advice is not to abandon it but to move it off the text message: “If you do use MFA, keep in mind that text message verification may not stop a SIM card swap. If you’re concerned about SIM card swapping, use an authentication app or a security key.” An authentication app produces its codes on the device itself, so moving the number moves nothing. If you have never set one up, the way the codes are generated is worth understanding before you rely on it, and if one has stopped producing working codes, that has its own causes.

The same free lock at three carriers, and only two names for it Verizon calls it SIM Protection and states it is at no cost, locking lines so that no request to change the SIM is processed until the feature is unlocked. T-Mobile uses the same name, SIM Protection, and states it is a free feature offered to all its Postpaid customers which prevents bad actors from moving a number to another device; T-Mobile also keeps a second, separate feature called Port Out Protection for transfers to another carrier. AT&T calls it Wireless Account Lock, describes it as a free security feature in the AT&T app that disables specific transactions and account changes for every device and line on the wireless account. ONE FREE LOCK, TWO NAMES ACROSS THE THREE CARRIERS Verizon “SIM Protection” locks the lines, and no SIM change is processed until you unlock it T-Mobile “SIM Protection” — same name stops your number moving to another device; porting has its own lock, Port Out Protection AT&T “Wireless Account Lock” disables account changes for every line, switched on in the AT&T app All three are free and all three are off until you turn them on. Verizon and T-Mobile use the same name for it; AT&T’s is called something else, and T-Mobile has a second lock for porting. AI Tools Primer · figure
Each box is quoted from that carrier’s own page, read on 10 September 2026. Figure drawn by AI Tools Primer.

The free lock, and what it is called at each carrier

Every large United States carrier now offers a switch that stops this, all three are free, and all three are off until you turn them on. Two of the three give it the same name and the third does not, and a name you have never heard is the single biggest reason people conclude their own carrier does not offer one.

Verizon: SIM Protection. In its own words, “At no cost to you, SIM Protection offers you the ability to lock lines on your account to prohibit changes to the SIM cards associated with those lines”, and — the sentence that describes the whole point — “No request to change your SIM will be processed until you unlock the SIM protection feature on the line.”

T-Mobile: SIM Protection, the same name Verizon uses. On its fraud page T-Mobile writes that “SIM Protection is a free feature offered to all T-Mobile Postpaid customers” and that “It prevents bad actors from moving your number to another device and using it for fraud.” Taking it off is deliberately harder than putting it on: “While you can add SIM Protection as an Authorized User, only the Primary Account Holder can remove the feature.” The same page carries a second and separate lock, for the other way a number is taken: “Port Out Protection is a free feature offered to all T-Mobile Postpaid, T-Mobile for Business, T-Mobile Prepaid, and Metro by T-Mobile customers”, which “adds additional security to your account by blocking unauthorized users from transferring your lines to another wireless carrier”. One stops the SIM being swapped under the number; the other stops the number being carried off to a different company.

AT&T: Wireless Account Lock. AT&T calls it “A free security feature” available through its app, and describes the effect: “When you turn on Wireless Account Lock, it disables specific transactions and account changes for all devices and lines on your AT&T Wireless SM account.” Its written route is: open the AT&T app, sign in, tap the person icon, scroll to and select Wireless account lock, then swipe to lock. It adds a notification rule worth knowing, because it is also an alarm: “Any time a user turns Wireless Account Lock on or off, we’ll send an email to the primary account holder and a text message to each active wireless number on the account.”

And the PIN, which is the older advice and still holds. CTIA’s first recommendation is to “Establish a PIN on your account that is required for account access”, with the warning that it should be “a unique number that cannot be easily determined” — explicitly not the last four digits of a Social Security number, a date of birth or an anniversary. The FTC says the same in one line: “Set up a PIN or password on your cellular account. This could help protect your account from unauthorized changes.”

The free lock at the three largest United States carriers, in each carrier’s own words, read on 10 September 2026. Two of the three use the same name; the switch locations differ.
CarrierWhat it is calledWhat it blocksWhere you switch it on
VerizonSIM Protection Changes to the SIM cards on the locked lines Account security settings; “At no cost to you”
T-MobileSIM Protection Your number being moved to another device T-Life or T-Mobile.com, Postpaid accounts
AT&TWireless Account Lock Specific transactions and account changes on every line The AT&T app, person icon, Wireless account lock

What the regulator has required, and when

This is not only a matter of what each carrier chooses to offer. The Federal Communications Commission has rules on it. Its own notice states that “At its November 15, 2023, Open Meeting, the FCC adopted a Report and Order implementing new rules to protect cell phone consumers from SIM swap and port-out fraud, two practices that bad actors use to take control of consumers’ cell phones.”

The same notice sets out an accessibility requirement that says something about how the rules were meant to work in practice: the authentication methods carriers adopt “must accommodate the needs of the broad spectrum of customers they may serve, including those who do not have data plans or data-enabled devices, have varying degrees of technological literacy, or have disabilities or accommodation needs”. The compliance date the FCC gives for that rule is “July 8, 2024, or after the Commission receives approval from the Office of Management and Budget under the Paperwork Reduction Act process, whichever is later”.

These are United States rules and they bind United States carriers. Elsewhere the protections exist under other names and other regulators, and a page that stated one country’s rule as though it were universal would be worse than no page at all.

What to do first if it has already happened, in the FTC’s order The FTC lists four actions for somebody who has been the target of a SIM swap: contact the mobile provider immediately to take back control of the number, then change account passwords once the number is back, then check card, bank and other financial accounts for unauthorised charges or changes and report any to the institution, and if a Social Security, credit card or bank account number has been exposed, go to IdentityTheft.gov for the specific steps. IF IT HAS ALREADY HAPPENED 1 Call the carrier immediately, to get the number back 2 Change the passwords after the number is back, not before 3 Check the money cards, bank, and anything else financial 4 If ID was exposed IdentityTheft.gov The order is not arbitrary: until the number is back, a password reset sent by text message arrives on the other phone, so step two undoes itself if it is done first. AI Tools Primer · figure
The four steps and their order come from the FTC’s consumer alert. Figure drawn by AI Tools Primer.

If it has already happened

The FTC’s list is four items long and the order is the useful part. “Contact your cellular service provider immediately to take back control of your phone number. After you re-gain access to your phone number, change your account passwords.”

Those two are in that order for a mechanical reason: until the number is back, a password reset sent by text message arrives on the other phone. Changing passwords first hands over the new ones.

Then: “Check your credit card, bank, and other financial accounts for unauthorized charges or changes. If you see any, report them to the company or institution.” And finally, if identifying details are involved: “If you think a scammer has your information — like your Social Security, credit card, or bank account number — go to IdentityTheft.gov to see the specific steps to take.”

IdentityTheft.gov is run by the FTC and it costs nothing. Anything charging you for the same thing is worth reading about on what identity theft protection services actually do before you pay for it.

One thing this attack is not

It is not something you did. There is no password strong enough to prevent it, no setting on the handset that blocks it, and no app that detects it. The decision that matters is taken by somebody at a carrier, on a phone call you were not part of, and the only lever you have is the lock described above — which exists precisely because that decision can be got wrong.

CTIA lists what the caller usually needs to bring: “your email, home address, and your phone number”, and notes that “Often, this information is available online, either through a search engine or social media”. Reducing what is findable about you is a slower job with its own page, your digital footprint, and it is worth doing, but it is prevention rather than repair.

Twenty minutes, tonight

Nothing here costs anything, and all of it is on the carrier’s own site or app.

Turn on your carrier’s free line lock Verizon: SIM Protection. T-Mobile: SIM Protection too, on Postpaid lines. AT&T: Wireless Account Lock, in the app.
Set an account PIN that is not guessable CTIA: not the last four of a Social Security number, not a date of birth, not an anniversary.
Move your codes off text messages The FTC’s wording: if you are concerned about SIM swapping, “use an authentication app or a security key”. Start with the bank and the email.
Know the sign A phone that stops receiving calls and texts for no reason. Contact the provider immediately rather than restarting it and waiting.

The related question, which is a different one. What somebody can do with a phone number on its own is a narrower list than this page might suggest: a SIM swap needs a good deal more than the number, and most of what gets attributed to a number alone requires something else as well. That is separated out on what someone can actually do with your phone number, which lists what the number alone allows and what it does not.

Where this fits. A SIM swap is usually a step rather than a destination: the number is taken so that a code can be intercepted, so that an account can be reset. If that has already happened to a social account, the recovery route is the next page. If what was reused was a password rather than a number, that is the door. And if the whole thing started with a message asking you to confirm something, it started with phishing — or, if it started with a call from a number you recognised, with a screen that proves nothing.

Where to start

Four ways into this page.

“My phone suddenly has no service.”
The sign, and what it means — what it is
“How do I stop it happening?”
The free lock, per carrier — the free lock
“It already happened.”
The four steps, in order — if it happened
“Why is my number worth anything?”
What it unlocks — why the number

The codes and the second factor

A SIM swap is an attack on the second factor, so what the second factor is decides whether it works.

What the number is used to reach

The number is taken for what it unlocks, and these are the usual destinations.

Questions people also ask

How do I know if I have been SIM swapped?

The first sign is your own phone going quiet. Verizon: “In some cases, you might not know this has even happened until your phone no longer works.” CTIA’s advice is that if you stop receiving calls or texts and do not know why, contact your provider immediately.

Can you protect yourself from SIM swapping?

Yes, and it is free. Verizon and T-Mobile both call it SIM Protection, AT&T calls it Wireless Account Lock, and all three block the change until you unlock them. All three are off by default, and all three are switched on in the carrier’s app or account settings.

Does two-factor authentication stop a SIM swap?

Not when the codes arrive by text message. The FTC states that “text message verification may not stop a SIM card swap” and advises an authentication app or a security key instead, because those generate the code on the device rather than sending it to a number. It is also why a code arriving that nobody asked for is worth reading rather than dismissing.

What should I do first if it has already happened?

Call the carrier and get the number back before anything else. The FTC’s order is: contact the provider immediately, then change your account passwords once you have the number again, then check financial accounts, then use IdentityTheft.gov if identifying details are involved.

Is there a rule that carriers have to follow?

In the United States, yes. The FCC states that at its 15 November 2023 Open Meeting it “adopted a Report and Order implementing new rules to protect cell phone consumers from SIM swap and port-out fraud”. The rules bind United States carriers.

What information does someone need to do this?

CTIA lists what is usually gathered first: “your email, home address, and your phone number”, and notes that this is “often” available online through a search engine or social media. That is why the account PIN matters more than the handset does.

Not covered here. It does not describe how to persuade a carrier to move a number, and it never will. The sections above are written from the carriers’ and the regulator’s own published material, at the level they publish it.

It does not cover carriers outside the United States. The lock exists elsewhere under other names, but the wording quoted here is from three United States carriers and the rules from the FCC, which binds only them.

And it does not cover eSIM transfers between your own devices, which use the same underlying operation for an entirely ordinary reason and are not what this page is about. What holds instead is simple: each carrier’s lock is quoted from that carrier’s own page with the date it was read, the sequence and the recovery steps are quoted from the FTC, the rule and its dates come from the FCC’s own notice, no product is named or recommended, and the page says plainly which country the rules apply in.

Sources

  1. Federal Trade Commission — SIM Swap Scams: How to Protect Yourself (23 October 2019): the method described from the outside, what the person holding the number can reach, the warning that text message verification may not stop a SIM card swap and the advice to use an authentication app or a security key, the account PIN, and the four steps for somebody who has already been targeted including IdentityTheft.gov — consumer.ftc.gov, read 10 September 2026.
  2. Federal Communications Commission — FCC Announces Effective Date for SIM Swapping Item: that the Report and Order on SIM swap and port-out fraud was adopted at the 15 November 2023 Open Meeting, the accessibility requirement placed on the authentication methods carriers adopt, and the compliance date of 8 July 2024 or approval under the Paperwork Reduction Act, whichever is later — www.fcc.gov, read 10 September 2026.
  3. Verizon — SIM swapping: the definition of an unauthorised SIM change, the note that not all SIM changes are bad, the list of accounts whose one-time codes are the target, the point that the first sign is often the phone no longer working, and SIM Protection described as at no cost with no SIM change processed until the line is unlocked — www.verizon.com, read 10 September 2026.
  4. T-Mobile — Protect your T-Mobile account from fraud: SIM Protection described as a free feature for all Postpaid customers which prevents a number being moved to another device, the note that only the Primary Account Holder can remove it, and Port Out Protection as the separate free feature that blocks transfers of lines to another carrier — www.t-mobile.com, read 10 September 2026.
  5. AT&T — Learn About AT&T Wireless Account Lock: that it is a free security feature in the AT&T app, that it disables specific transactions and account changes for all devices and lines on the wireless account, the steps to turn it on, and the email and text notification sent whenever it is switched on or off — www.att.com, read 10 September 2026.
  6. CTIA — Protecting Your Wireless Account Against SIM Swap Fraud: the definition, the information a fraudster gathers first and the note that it is often available online, the recommendation to establish an account PIN that cannot be easily determined, and the advice to contact the provider immediately if calls and texts stop arriving — www.ctia.org, read 10 September 2026.

Written by Alberto Gulotta

Founder and editor of AI Tools Primer, writing from Palermo, Italy. Thirty-five years of taking computers apart, starting with a Commodore 64 — the long version is on the about page.

Something wrong on this page? Write to aitoolsprimer@gmail.com and it gets fixed.

Written on 10 September 2026.

Independence and limits

No affiliate links and no paid placements anywhere on this site. Nobody pays to appear here, and no company has seen this page before you did.

This is general information, not professional advice. Where a page touches money, health, safety or the law, it names its source and the date it was read — and your situation may still differ. See the privacy page and the cookie policy.