Someone who takes control of your mobile number may be able to receive the texted login or recovery codes that protect your accounts. That is different from hacking your phone: a criminal can hijack the number through a SIM swap or port-out fraud without taking your handset. If your phone suddenly loses service or your carrier reports an unexpected SIM or number transfer, contact the carrier immediately through a known official channel.
How a phone-number takeover can expose your accounts
A SIM swap occurs when a fraudster persuades a mobile provider to activate a new SIM connected to your number. Calls and texts—including one-time login or account-recovery codes—may then go to the fraudster instead of your phone. The attacker does not need to physically steal your handset. The Federal Trade Commission’s SIM-swap guidance explains the scam and its warning signs.
Port-out fraud is related but distinct: the number is transferred to an account with another provider that the fraudster controls. The FCC’s 2023 order addresses both SIM-swap and port-out fraud and sets provider requirements for customer notification and protections. Carrier procedures and available controls can vary.
Once someone controls the number, they may use texted codes to sign in to or reset accounts that rely on SMS. This does not mean every account is automatically compromised: the attacker still needs to reach an account that accepts that number for authentication or recovery, and other security measures may matter. But SMS two-factor authentication cannot fully protect an account against a takeover of the number receiving its codes.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Warning signs that the number—not just an account—may be compromised
- Your phone suddenly has no cellular service, calls, or texts, and the loss is not explained by an outage or device problem.
- Your carrier sends an unexpected notice that a SIM was activated on a new device or that your number is being transferred.
- You receive account alerts about password resets, sign-ins, or changed recovery details that you did not request.
A hacked email or social-media account and a hijacked phone number are not the same incident, though one can enable the other. If service disappears unexpectedly, contact your carrier promptly; do not wait to see whether it returns on its own.
What to do if someone may have taken your number
- Contact your carrier immediately through a known official channel. Use its official app, type its website address yourself, or use a number from a bill or trusted account record—not contact details in an unsolicited message. The FTC advises: “Contact your cellular service provider immediately to take back control of your phone number.”
- Restore and secure the line. Ask the provider to recover your number and secure the cellular account against further unauthorized changes. Ask what account PIN or password and SIM-change or number-transfer protections are available; controls differ by carrier.
- Recover affected accounts through each service’s official process. Use the provider’s own account-recovery page or app. Avoid links or phone numbers sent in unexpected texts, emails, or calls. The FTC’s account-recovery guidance outlines steps for email and social accounts.
- After regaining access, change passwords and end other sessions. Use each service’s security settings to sign out other devices or sessions, turn on two-factor authentication, and confirm that the recovery email and phone number are yours.
- Inspect accounts for changes you did not make. Check sign-in history where available, messages, forwarding rules, connected apps, profile details, recovery settings, and recent activity. Remove unfamiliar access and report unauthorized activity to the service.
- Check financial accounts and alert contacts if needed. Look for unauthorized charges or changes and report them to the relevant bank or financial institution. If personal information was stolen, the FTC recommends using IdentityTheft.gov for a recovery plan. If a compromised social account sent messages, warn affected friends or followers so they do not trust suspicious requests.
Which two-factor method is less exposed to a SIM swap?
Authentication methods generally rely on something you know, something you have, or something you are. SMS codes are convenient and widely supported, but they depend on control of your phone number. An authenticator app generates codes on a device instead of sending them to the number, reducing exposure to a SIM-swap attack. A security key is another option when the service supports it. No option is universally invulnerable, and account recovery arrangements still matter.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
| Method | Exposure to number takeover | Support and recovery considerations | Practical trade-off |
|---|---|---|---|
| SMS code | Codes sent to a hijacked number may reach the fraudster. | Availability depends on the service; recovery may rely on the same number. | Simple and familiar, but tied to the phone number. |
| Authenticator app | Not susceptible to a SIM-swap attack in the same way as SMS because codes are generated in the app. | The service must support it; plan for access to the app and its recovery method if the device is lost. | Reduces reliance on the number, but requires access to the authenticator. |
| Security key | Does not rely on receiving SMS codes at the hijacked number. | The service must support security keys; keep an appropriate recovery method available. | Can reduce dependence on the phone number, but requires a compatible key and account. |
The FTC says of authenticator apps: “But using an app is safer because the passcode isn’t susceptible to a SIM card swap attack or to someone hacking your email.” Choose the strongest method the account supports and keep recovery details current. If SMS is the only second-factor option, the FTC says it is better than having no second factor. Its two-factor authentication guide describes these options, including security keys.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How to make a future takeover harder
- Set a PIN or password on your cellular account if your carrier offers one, and ask about available SIM-change and number-transfer protections.
- Do not share one-time verification codes with an unsolicited caller or texter. Contact the company independently using a known website or number if a request seems legitimate.
- Limit personal details shared publicly and be cautious about requests for sensitive information; details about you may help a fraudster impersonate you.
- Where available, use an authenticator app or security key instead of SMS for important accounts, and confirm that you can recover the account if you lose access to the device or key.
- Keep the recovery email and phone number on important accounts current, and review account activity and recovery settings periodically.
The FCC’s FCC 23-95 order provides the 2023 regulatory context for provider protections, but it does not guarantee a particular carrier procedure or recovery outcome.
Quick Recap
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

