SIM Swapping Has Moved Online—And Your Carrier Account Is the New Target

SIM Swapping Is Moving Online: How Criminals Can Steal Your Number Through Your Carrier Account

SIM swapping is no longer just about someone walking into a mobile phone shop with a fake ID and asking for a replacement SIM card. A growing risk now starts much closer to home: your online mobile carrier account.

German investigators have warned about a method that can allow criminals to take over a victim’s phone number without visiting a store, showing physical documents, or waiting for a plastic SIM card in the mail. Instead, attackers exploit online login systems, trick victims into sharing a one-time code, and activate an eSIM on their own device.

The result can be devastating. Your phone suddenly loses signal. Text messages stop arriving. Then your email, banking apps, social media accounts, or cryptocurrency wallets may become vulnerable because many services still use SMS codes for login, password resets, and identity verification.

How the eSIM SIM swapping attack works

The attack usually begins with the victim’s mobile phone number. In some carrier systems, a phone number can be enough to start the login process for an online customer account. Instead of entering a password, the system may send a one-time code by SMS.

That is where social engineering comes in.

The criminal calls the victim and pretends to be someone trustworthy, often a courier or delivery service. They may say a package is on the way and that delivery can only be confirmed if the victim reads out a security code sent by text message.

The text message really does arrive, which makes the story feel believable. But the code is not from a courier. It is from the mobile carrier. If the victim reads it out, the attacker can use it to access the carrier account.

Once inside, the attacker orders an eSIM for the victim’s existing mobile contract. Unlike a traditional SIM card, an eSIM is not a physical piece of plastic. It is a digital profile that can be activated on a compatible phone within minutes.

When the eSIM becomes active on the attacker’s device, the victim’s original SIM often stops working. The victim may see “no service” or lose mobile connectivity entirely. Meanwhile, calls and text messages start going to the criminal.

Why stealing a phone number can unlock everything

A stolen phone number is powerful because so many online services still treat SMS as proof of identity. If an attacker controls your number, they may be able to receive login codes, reset passwords, approve account changes, or bypass weak security checks.

Email accounts are especially important. Once attackers access your inbox, they can search for banking information, online shopping accounts, crypto exchange notifications, cloud storage alerts, and password reset emails. In one case described by investigators, a compromised email account revealed that the victim owned cryptocurrency. The funds were later stolen.

This is why SIM swapping is often more than a phone problem. It can become a full digital identity takeover.

Why porting locks are not the same everywhere

Many people assume they can simply lock their number to prevent it from being moved or misused. In some countries, carriers offer features designed to block unauthorized number porting or SIM changes. These tools can add friction before a number is transferred or reassigned.

In Germany, however, the situation is different. Number portability is a legal right, and mobile providers must allow customers to move their number. Because of this, a permanent customer-controlled porting lock is not commonly available in the same way it is in some other markets.

German mobile providers do offer other protections, such as hotline passwords, customer verification codes, service PINs, and the ability to block a SIM after it has been lost or stolen. But these measures may not always stop an online account takeover before it happens.

That means the most important security layer is often the login protection on the mobile carrier account itself.

The real weak point: your carrier account login

The attack depends on gaining access to the customer portal of the mobile provider. If criminals cannot enter that account, they cannot easily order an eSIM in the victim’s name.

Major German carriers now offer or require some form of two-factor authentication, but the exact setup matters.

Telekom offers multi-factor authentication that customers must activate themselves. Users can choose the method and decide whether the additional check is required for every login or only for sensitive actions.

Vodafone also supports extra login protection and recommends creating backup codes when enabling stronger security. Backup codes are important because they can help you regain access if your phone is lost, stolen, or no longer receiving messages.

O2 uses mandatory second-factor checks. In some cases, verification may rely on the customer number if no O2 number or verified email address is available.

These protections are useful, but there is one major catch: if the second factor is SMS, it may rely on the very phone number attackers are trying to steal.

Why SMS two-factor authentication can backfire

SMS two-factor authentication is better than having no second factor at all, but it has a serious weakness in SIM swapping cases. If criminals manage to take control of your number, SMS codes go to them instead of you.

That means the security feature designed to protect your account can start protecting the attacker’s access.

If your carrier gives you a choice between SMS verification and an authenticator app, the app is usually safer. An authenticator app generates codes directly on your device and does not depend on your mobile number. Even if your number is hijacked, the attacker does not automatically receive those app-generated codes.

If your provider only supports SMS for certain actions, then your email account becomes even more important. Make sure the email linked to your carrier account has a unique, strong password and two-factor authentication that is not tied to the same mobile number.

How to protect yourself from SIM swapping and eSIM fraud

Start by logging in to your mobile carrier account and reviewing your security settings. Check whether two-factor authentication is enabled. If an authenticator app is available, use it instead of SMS. If you can require the second factor for every login, enable that option.

Next, change your carrier account password if it is weak, old, or reused anywhere else. Your mobile carrier account should be treated like an online banking account because it can be used to order a replacement SIM or eSIM.

Then review the customer verification method used when contacting support. Depending on the provider, this may be a customer password, service PIN, or another identity check. Make sure you understand what it is, where it is stored, and whether it can be changed or reissued.

Also secure your email account. Use a long, unique password and enable two-factor authentication through an app, hardware security key, or another method that does not depend only on SMS. Your email is often the recovery hub for your digital life, so it needs stronger protection than a simple password.

Most importantly, never read out SMS codes to someone who calls you.

No courier needs a code from your mobile provider. No bank employee needs a login code over the phone. No customer service agent should ask you to forward or dictate a one-time password in a chat. If someone asks for a code, there is a good chance they are trying to confirm an action in your name.

Hang up and contact the company through its official customer service number or app. Do not use a phone number given to you during the suspicious call.

Warning signs that your SIM may have been hijacked

A sudden loss of mobile signal can be an early warning sign, especially if your phone previously had normal reception. Other red flags include unexpected messages about SIM activation, emails about account logins, password reset notifications, or alerts that a new device has been added to one of your accounts.

If your phone loses service for no clear reason, contact your mobile carrier immediately. Use another phone, Wi-Fi calling, or online support if necessary. Ask whether a new SIM or eSIM has been activated on your account.

At the same time, secure your most important accounts. Start with email, banking, payment services, cloud storage, messaging apps, and cryptocurrency platforms. Change passwords and revoke unfamiliar sessions where possible.

The simple rule that prevents many attacks

The easiest way to stop this type of SIM swapping attack is to treat every unexpected code as private. If you did not personally start the login, reset, or account change, do not share the code with anyone.

A one-time code is not just a number. It can be the key to your mobile account, your email, your bank login, or your entire digital identity.

SIM swapping has evolved from fake IDs and shop counters to online accounts and convincing phone calls. The best defense is a secure carrier login, app-based authentication where possible, strong email protection, and a firm rule: never give SMS codes to callers.