Skip to main content
Search

What is SIM swap fraud and how can you spot it?

Date: 11 September 2026

4 minute read

SIM swap fraud happens when a criminal gets your mobile number transferred from your SIM card to one they control. If they succeed, calls, texts, and some security codes meant for you may be sent to them instead.

That matters because many accounts still use text messages to check it’s really you. If a criminal receives those codes, they may try to reset passwords or access email, banking, social media, shopping, or other online accounts.

Most people wouldn’t spot a SIM swap scam straight away. It often starts with something that feels like a normal phone problem.

A normal morning, until your phone stops working

You glance at your phone and notice it isn't connected to the network. You restart it, but nothing changes. That's irritating, but hardly unusual. You assume it will sort itself out and carry on with your morning.

Later, a text you were expecting still hasn't arrived. Someone mentions they tried to call you, but it didn't connect. You might put it down to a network problem, especially if some apps are still working over WiFi.

A sudden loss of service, not being able to make calls or send texts, and no longer receiving messages can all be warning signs of SIM swapping.

Then the account alerts start

Just before lunch, an email lands in your inbox asking whether you requested a password reset. You didn’t. A few minutes later, there’s another notification about a login attempt from a device you don’t recognise. On their own, these messages might be easy to dismiss. Together, they start to look more concerning.

If a fraudster has control of your mobile number, they may be able to receive text-message security codes intended for you. Those codes may then help them try to access online accounts or reset passwords.

How SIM swap fraud happens

A SIM swap scam often starts before your phone loses signal. A criminal may collect personal information about you through phishing emails, scam calls, social media, previous data breaches, or other sources. They can then use that information to impersonate you and try to pass security checks with your mobile provider.

If the provider transfers your number to a SIM card controlled by the criminal, your calls and texts may begin going to that SIM instead of your phone.

Why your email account can be affected

SIM swap fraud isn’t only about losing phone service. Once someone can receive text-message codes, they may try to access other accounts linked to your mobile number.

Email often sits at the centre of your digital life. It can contain account alerts, password reset requests and clues about which banks, retailers and services you use.

That’s why a SIM swap can quickly become more than a mobile phone issue.

Warning signs of SIM swap fraud

Any one of these signs could have a simple explanation. If several happen at the same time, it's worth acting quickly. Watch out for:

  • your phone suddenly losing signal
  • being unable to make calls or send texts
  • expected text messages not arriving
  • a notification that your SIM or phone number is being used on another device
  • one-time passcodes you didn't request
  • password reset emails you didn't ask for
  • being locked out of email, banking, or social media accounts.

Why it’s easy to miss

A SIM swap scam can begin with something that looks completely ordinary: a phone losing signal, a message that never arrives, or an email notification that seems slightly out of place.

Seen in isolation, none of those things necessarily point to fraud. When they start happening together, it's worth paying attention.

How to reduce your risk

No single step will prevent every scam, but a few simple habits can make your accounts harder to target:

  • Ask your mobile provider what additional security protections are available on your account. Some providers offer extra checks before changes can be made.
  • Use strong, unique passwords for your mobile provider account, email account and banking apps. If one password is compromised, it reduces the risk of other accounts being affected.
  • Be careful about sharing personal information online, particularly details that could help someone answer security questions. Criminals often build a picture of their target using information gathered from social media, phishing attempts and previous data breaches.
  • Multi-factor authentication can add another layer of protection. Where you have the option, consider using an authenticator app or biometric authentication rather than relying solely on text-message codes.

What to do if you think you’ve been targeted

If your phone suddenly loses service and something feels wrong, contact your mobile provider using trusted contact details. Ask whether your SIM or number has been changed.

Then check your email and other important accounts for password reset messages, login alerts, or changes you don’t recognise. If you can still access those accounts, change your passwords, starting with your email account.

If you think your bank account or other financial accounts may be at risk, contact your bank straight away. Finally - report what’s happened. Contact Report Fraud on 0300 123 2040, or Police Scotland if relevant.

Frequently asked questions

SIM swap fraud happens when a criminal gets your mobile number moved to a SIM card they control. This means calls, texts, and some security codes meant for you may go to the fraudster instead.

A mobile number can be used to receive text-message security codes, password reset codes, and account verification messages. If a criminal receives those messages, they may try to use them to access your online accounts.

Yes. If a criminal can receive text-message verification codes meant for you, they may try to use those codes to access or reset an email account. Once inside an email account, they may be able to target other connected accounts.

Common warning signs include a sudden loss of phone signal, being unable to make calls or send texts, expected messages not arriving, unexpected security alerts, and being locked out of online accounts.

Text-message authentication can add protection, but SMS has weaknesses and can be targeted by criminals. Where available, authenticator apps or biometric authentication may offer stronger protection than relying only on text-message codes.

Reports of SIM swap fraud have increased significantly in recent years. Cifas reported a 1,055% increase in unauthorised SIM swap cases in 2024, while Report Fraud received more than 2,000 reports by the end of November 2024.