SIM Swap Fraud: Warning Signs, Prevention and What to Do If Your Number Is Stolen

A practical Australian guide to SIM swaps, unauthorised number ports, eSIM takeover, stronger MFA and mobile-number incident response.

A SIM swap does not copy everything from your phone. It does something more targeted: it transfers control of your mobile service to another SIM or eSIM. If important accounts still trust that mobile number for password resets or SMS verification, control of the number can become a shortcut into email, banking, social media, cloud services and business systems.

That is why SIM-swap fraud should be treated as an identity-and-account takeover problem rather than a purely mobile-phone problem. The phone may still be physically in your hand while the attacker controls the number that banks, email providers and online services use to verify you.

Australia now has stronger identity-authentication rules for high-risk telecommunications transactions, including SIM swaps. Those rules have reduced mobile-number fraud, but recent enforcement action shows that unauthorised swaps can still occur when controls fail or identity information is abused.

The Short Answer: Protect the Number, but Protect the Accounts Behind It

The strongest defence is layered. Secure the telco account, reduce reliance on SMS for high-value authentication, protect the primary email account, use phishing-resistant multi-factor authentication where available and know what to do if your mobile service suddenly changes without explanation.

Risk What It Means Best Defensive Focus
SIM swap Your existing service is activated on a replacement physical SIM or eSIM that you did not authorise. Telco account controls, fraud flags and stronger account authentication.
Unauthorised number port Your number is transferred to another provider without your consent. Pre-port identity controls, rapid telco escalation and reversal.
Account takeover after number loss The attacker uses control of the number to reset or access other services. Passkeys, security keys, authenticator apps and hardened recovery settings.
Identity fraud Stolen personal information is used to impersonate you to a telco or another service. Protect identity data, monitor account changes and respond quickly to compromise.

What Is SIM Swapping?

SIM swapping is a form of mobile-number takeover. A criminal impersonates the customer or abuses an account process so that the customer’s mobile service is activated on another SIM profile. The replacement may be a physical SIM card or an eSIM. Once the change is completed, calls and SMS messages intended for the legitimate customer can be redirected to the attacker-controlled service.

The attacker does not automatically receive the contents of the victim’s original phone. Photos, locally stored messages, documents and applications do not simply copy across because a SIM is changed. The danger is that many online services still treat control of a mobile number as evidence that the person requesting a login, password reset or verification code is the account holder.

SIM Swap, Number Porting and eSIM Takeover Are Related but Different

SIM Swap

A SIM swap usually occurs within the existing telecommunications provider. The same service and number are associated with a replacement SIM or eSIM.

Unauthorised Number Port

A number-port attack transfers the victim’s mobile number to another telecommunications provider. The victim may suddenly lose service while the attacker receives calls and SMS messages through the new provider.

eSIM Takeover

An eSIM does not remove the fraud risk. A replacement or newly activated eSIM can be the mechanism by which a SIM swap is carried out. The attack is still about unauthorised control of the subscriber service, not about cloning the entire handset.

Why Criminals Want Control of Your Mobile Number

The mobile number is valuable because it often sits inside the recovery and authentication chain of other accounts. Once an attacker controls the number, the next target is usually not the telecommunications account itself.

  1. Primary email accounts that can reset passwords for many other services.
  2. Banking, payment and cryptocurrency accounts that use SMS codes or mobile-number recovery.
  3. Apple, Google or Microsoft accounts linked to devices, cloud storage and identity services.
  4. Password managers or high-value business applications where the number is a recovery factor.
  5. Social-media and messaging accounts that can be used for impersonation or further fraud.
  6. Corporate systems where a personal or executive number remains part of the recovery process.

The primary email account deserves particular attention because it often functions as the master recovery point for multiple services. An attacker who gains both the mobile number and the primary email account may be able to reset a much wider set of credentials.

Warning Signs of a SIM Swap or Unauthorised Port

A sudden loss of mobile service is the classic warning sign, but it is not proof on its own. Network outages, billing issues, device faults and coverage problems can produce similar symptoms. The concern increases when loss of service appears together with account-change or authentication activity you did not initiate.

Warning Sign Why It Matters Important Caveat
Unexpected loss of service Calls, SMS and mobile data stop working while nearby users still have service. Could also be a network, billing or handset issue.
SIM/eSIM or port notification you did not request May indicate a high-risk telco transaction has been initiated. Verify the message through the telco’s official contact channel.
Unexpected password-reset or MFA alerts An attacker may be using the number to enter other accounts. Phishing messages can imitate legitimate alerts.
Changes to telco account details A fraudster may alter contact or recovery settings before or during the takeover. Confirm directly with the provider.
Bank or email security alerts The mobile-number compromise may already be spreading into financial or identity accounts. Treat as urgent even if no loss is yet visible.

Australia Has Stronger SIM-Swap Protections – but They Are Not Infallible

The Australian Communications and Media Authority (ACMA) treats SIM swaps as high-risk customer transactions. Telecommunications providers must use multi-factor identity authentication for high-risk transactions and must maintain additional fraud-mitigation protections for customers identified as being at risk.

Those protections can include account notifications, high-risk flags, restricted authentication channels or pausing certain transactions. Customers who believe they are at increased risk can ask their provider what additional fraud protections are available on the account.

Recent enforcement shows why the controls still matter. On 3 September 2026, ACMA announced that Telstra had paid a $277,200 penalty after an investigation found required identity-authentication processes were not used in 15 unauthorised SIM swaps between January and October 2025. ACMA also found failures to provide additional fraud protections in some at-risk customer cases. The point is not that one provider is uniquely vulnerable; it is that the threat remains real even under a stronger regulatory framework.

How to Reduce the Risk of SIM-Swap Fraud

1. Use Stronger MFA Than SMS for High-Value Accounts

SMS multi-factor authentication is still better than relying on a password alone, but it depends on control of the mobile number. Where a service supports stronger methods, use phishing-resistant authentication such as passkeys or FIDO2 security keys. Where passkeys are not available, an authenticator application or hardware token is generally preferable to SMS for high-value accounts.

The Australian Cyber Security Centre currently recommends phishing-resistant MFA such as passkeys and recommends authenticator applications where passkeys are unavailable.

2. Secure the Primary Email Account First

Use a unique password, strong MFA and carefully reviewed recovery settings. Remove obsolete phone numbers and email addresses, review active sessions and ensure recovery options cannot be changed easily by someone who knows old personal information.

3. Ask Your Telco About Additional Fraud Protections

Do not assume every provider implements the same customer-facing controls. Ask what account PINs, fraud flags, transaction restrictions, notifications or additional identity checks can be applied. If you are at elevated risk, make that clear to the provider and ask what protections are available for at-risk customers.

4. Reduce the Value of Stolen Identity Information

SIM-swap fraud often begins with enough personal information to impersonate the customer. Be cautious with phishing messages, identity documents, account screenshots and information that answers security questions. If identity documents are lost or stolen, notify relevant organisations promptly rather than waiting for fraud to appear.

5. Review Recovery Settings, Not Just Login MFA

An account can have strong MFA but still be vulnerable if password recovery falls back to SMS or a weak secondary email account. Review the recovery path for your primary email, financial accounts, cloud accounts, password manager and business systems.

6. Turn On Account and Transaction Alerts

Alerts will not stop every attack, but they can shorten the time between an unauthorised change and your response. Telco, email and banking alerts should go to channels the attacker cannot easily change at the same time.

What to Do Immediately If Your Mobile Number Is Hijacked

Speed matters. The objective is to stop the mobile-number takeover from becoming a broader account compromise.

Priority Action Purpose
1 Contact your telco immediately from another phone. Ask whether there has been a SIM replacement, eSIM activation, number port or account change. Confirm the event and stop further unauthorised control.
2 If there was an unauthorised SIM swap, request deactivation and restoration. If there was an unauthorised port, request reversal. Return control of the number to the legitimate account holder.
3 Contact banks and financial institutions immediately. Protect funds, cards and payment services before visible loss occurs.
4 Secure the primary email account from a trusted device. Prevent password resets and revoke suspicious sessions or recovery changes.
5 Secure other high-value accounts and replace SMS authentication where possible. Contain secondary account takeover.
6 Preserve alerts, emails, screenshots, timestamps and transaction records. Create a reliable incident record for the telco, bank, police or forensic investigation.
7 Report cybercrime or identity fraud through appropriate Australian channels. Support investigation, identity remediation and fraud response.

ACMA recommends contacting the telco and financial institution immediately, asking for an unauthorised port to be reversed or an unauthorised SIM to be deactivated, and reporting relevant fraud to police, ReportCyber, IDCARE and Scamwatch.

Do Not Treat Loss of Service as a Reason to Reset the Phone

A SIM swap normally targets the subscriber service and account-recovery chain, not the data stored on the handset. Factory resetting the phone will not reverse an unauthorised port or SIM swap and may destroy useful evidence if a broader compromise is being investigated.

If the incident also involves suspicious applications, unexpected account activity, spyware indicators or unexplained device behaviour, preserve the device state and obtain forensic advice before making unnecessary changes.

Can a SIM Swap Give Someone Everything on Your Phone?

No. A SIM swap does not automatically clone the handset or transfer all local data. It gives the attacker control of the mobile number and the calls or SMS messages routed to that service. What happens next depends on which accounts trust that number for login, recovery or verification.

This distinction matters because victims sometimes assume that every photo, message or file has been copied simply because the phone loses service. That is not how a SIM swap works. Separate endpoint compromise – for example spyware or malware – is a different problem and requires separate forensic analysis.

SIM Swap Fraud Is Not the Same as SS7 or Cellular Signalling Interception

SIM-swap fraud is primarily an identity and account-takeover attack. The attacker gains control of the subscriber service by manipulating a telco process, using stolen identity information or otherwise causing an unauthorised service change.

SS7, Diameter and other signalling-layer attacks operate differently. They target weaknesses or misuse within telecommunications signalling networks and may be used for subscriber tracking, interception or other network-level activity. A SIM swap and a signalling attack can both affect mobile communications, but they should not be described as the same attack.

For a detailed explanation of network-based surveillance, see Can a Mobile Phone Be Bugged Without Spyware? SS7 and Network-Based Surveillance.

Why SIM Swapping Matters to Executives and Organisations

For executives, finance teams, privileged IT administrators, lawyers and staff with access to high-value systems, mobile-number takeover can become one stage in a larger intrusion. A criminal who controls an executive’s number may attempt to reset email credentials, access cloud services, impersonate the victim, compromise messaging accounts or exploit recovery paths into business systems.

Organisations should therefore identify which privileged accounts still depend on SMS and which employees’ personal mobile numbers remain embedded in administrative or recovery processes. The objective is not to eliminate SMS from every low-risk use case; it is to remove a fragile recovery dependency from the accounts where compromise would have the greatest impact.

Higher-Risk User Potential Consequence Control Priority
CEO / board member Impersonation, confidential communications exposure, account takeover. Passkeys/security keys, hardened recovery and telco fraud controls.
CFO / finance team Payment fraud, banking access, business email compromise. Phishing-resistant MFA and transaction verification independent of SMS.
Privileged IT administrator Cloud or infrastructure compromise. Hardware-backed MFA, separate admin identities and restricted recovery paths.
Lawyer / adviser Exposure of privileged or confidential client matters. Strong account security and communications-risk assessment.
High-value or targeted individual Identity fraud, financial loss, impersonation and wider compromise. Layered identity, telco, email and device-security controls.

When a SIM-Swap Incident Becomes a Forensic Matter

A straightforward unauthorised number transfer may be resolved by the telco and financial institutions. Forensic investigation becomes more important when the event is part of a broader compromise: email accounts were accessed, cloud sessions appeared from unknown locations, credentials were changed, money was moved, business systems were entered or there is concern that the handset itself was also compromised.

Depending on lawful authority and scope, an investigation may need to correlate telco notifications, email security events, cloud-session records, device artefacts, banking alerts, authentication changes and the incident timeline. The objective is to distinguish the mobile-number takeover from any separate endpoint, cloud or identity compromise and to preserve evidence for legal, regulatory or internal response.

How NSI Global Can Assist

NSI Global provides communications-security and digital-forensic services for corporate, government and appropriately authorised clients. Where a mobile-number takeover forms part of a broader security incident, the investigation can extend beyond the SIM event to account compromise, endpoint examination, spyware or malware analysis, telecommunications risk and evidentiary reporting.

Relevant NSI capabilities include Communications Security (COMSEC), Digital Forensics and Forensic Spyware and Malware Detection.

For organisations with elevated communications exposure, SIM-swap fraud should be considered alongside phishing, credential theft, cloud-account compromise, spyware and telecommunications-layer threats. The correct control depends on which layer is actually being targeted.

Frequently Asked Questions

What is SIM swapping?

SIM swapping is the unauthorised transfer or activation of your mobile service on another physical SIM or eSIM. It can allow an attacker to receive calls and SMS messages intended for your number.

Can someone SIM swap an eSIM?

Yes. A SIM swap can be carried out through unauthorised activation of a replacement eSIM. The fraud is about gaining control of the subscriber service, not whether the replacement is physical or embedded.

How do I know if my SIM has been swapped?

Unexpected loss of service, unauthorised telco notifications and simultaneous password-reset or banking alerts are important warning signs. Loss of service alone is not proof because outages and device faults can look similar.

Can a SIM swap bypass two-factor authentication?

It can defeat SMS-based verification if the attacker controls the number receiving the code. It does not automatically defeat passkeys, security keys or authenticator methods that do not rely on the stolen number.

Is SMS two-factor authentication safe?

SMS MFA is better than password-only security, but it inherits the risk of mobile-number takeover. For high-value accounts, use phishing-resistant MFA such as passkeys or security keys where supported, or an authenticator application where passkeys are unavailable.

How do I stop someone porting my mobile number?

Use your telco’s available account-security controls, ask about additional fraud protections, protect identity information and ensure high-value accounts do not rely solely on SMS recovery. No single setting guarantees prevention.

What should I do if my phone suddenly loses service?

Check whether there is a network or account problem. If the loss is unexplained or accompanied by account-change alerts, contact the telco immediately from another phone and ask whether a SIM swap, eSIM activation or number port occurred.

Can my bank account be accessed through a SIM swap?

Potentially. If the bank or a connected email account relies on the stolen number for authentication or password recovery, the attacker may attempt to use the number to gain access. Contact financial institutions immediately if you suspect a mobile-number takeover.

Can I get my number back after an unauthorised port?

ACMA advises victims to contact the telco immediately and request reversal of an unauthorised port. If an unauthorised SIM swap occurred, ask the provider to deactivate the fraudulent SIM and restore the legitimate service.

What is the difference between SIM swapping and SS7 hacking?

SIM swapping is an identity and service-account takeover in which control of the subscriber number is moved to another SIM or eSIM. SS7 or Diameter attacks target telecommunications signalling. They are different threat mechanisms even though both can affect mobile communications.

Does a SIM swap copy everything on my phone?

No. A SIM swap does not automatically copy local photos, messages, apps or files from the handset. It transfers control of the mobile service. Separate device compromise, such as spyware, is a different issue.

Sources and Further Reading

  1. Australian Communications and Media Authority – Customer Identity Authentication Rules – Current requirements for identity authentication on high-risk telco transactions and protections for at-risk customers.
  2. Australian Communications and Media Authority – What to Do If Your Number Has Been Stolen – Consumer response guidance for unauthorised number ports and SIM swaps.
  3. Australian Communications and Media Authority – Keep or Transfer Your Phone Number – Explains number porting and customer identity protections.
  4. Australian Communications and Media Authority – Telstra Pays $277K After Consumer Fraud Losses – 3 September 2026 enforcement action involving unauthorised SIM swaps and at-risk customer protections.
  5. Australian Cyber Security Centre – Multi-factor Authentication: Switch It On – September 2026 guidance recommending phishing-resistant MFA such as passkeys and authenticator applications where passkeys are unavailable.
  6. NSI Global – Communications Security (COMSEC) – NSI Global communications-security capability for corporate and government sectors.
  7. NSI Global – Forensic Spyware and Malware Detection – NSI Global endpoint forensic examination and spyware/malware capability.
  8. NSI Global – Can a Mobile Phone Be Bugged Without Spyware? SS7 and Network-Based Surveillance – Related explanation of telecommunications signalling threats distinct from SIM-swap fraud.

Speak with NSI Global