Skip to content
FIN-CSIRT
RS
Report an incident

FIN-CSIRT / Practical lesson

Protect the number that receives login codes

Recognise a possible unauthorised SIM change and quickly protect accounts connected to the number.

Mobile, banking and online-service usersAbout 5 minutes of reading + 3 questions
Go to response steps Has your phone just lost service?

What you will learn

  • Recognise possible signs of phone-number takeover.
  • Contact the operator and bank without relying on the affected phone.
  • Reduce reliance on text-message codes where a stronger option exists.

What is SIM swapping?

SIM swapping is an unauthorised transfer of your number to another SIM or eSIM. A person controlling the number may receive calls and text messages, including codes used by some services for login or recovery.

A legitimate SIM change also occurs when you change devices or SIM format. The problem is a change you did not request.

Signals to connect

  • the phone unexpectedly loses mobile service while other devices have coverage;
  • the operator reports a SIM replacement or number transfer you did not request;
  • calls and messages stop reaching you;
  • password resets, new logins or security-setting changes occur at the same time.

If you suspect takeover

  1. From another phone or trusted device, contact the mobile operator through an official channel and check the number’s status.
  2. If the number is connected to banking, contact the bank and explain that you may no longer control calls and texts.
  3. Protect email and other important accounts: replace exposed passwords, end unknown sessions and review recovery details.
  4. Preserve alerts, the time service was lost and case numbers. For a work number, notify IT or security immediately.

Reduce reliance on the number

Where offered by the operator, add a PIN or another check for SIM replacement and number transfer. Avoid publishing your number and identification data without a need.

For important accounts, use a stronger factor where supported, such as a FIDO security key, passkey or authenticator app. Prepare recovery before losing the phone.

Practice example

The phone suddenly has no service

Mobile device
The phone suddenly has no service

SIM unavailable. At the same time, an email reports a password change you did not request.

Fictional situation for practice; loss of service alone does not prove an attack.
Show the example explanation
Service disappears unexpectedly
Check the number's status with the operator from another phone or device.
An account changes at the same time
Combined signals require faster protection of email, banking and other important services.
Text codes no longer reach you
A person controlling the number may try to receive codes intended for you.

Check your knowledge · 3

Your turn to choose the next step.

Choose one answer for each question shown. More complex lessons select three questions from a wider question bank when the lesson loads.

Questions and explanations are also available without JavaScript.

Your phone loses service and an unexpected password-change notice arrives. What first?

Why does this matter? Either event may have an ordinary cause, but together they require prompt independent verification.

  1. Wait until tomorrow for service to return.

    Waiting delays protection if the number was taken over.

  2. Use another device to contact the operator and check important accounts.Correct answer

    Another device allows verification without the affected SIM.

  3. Post the phone number publicly.

    Public posting may expose more information and does not restore control.

Does loss of mobile service automatically prove a SIM swap?

Why does this matter? Device, network and SIM faults can cause a similar symptom.

  1. Yes, always.

    One symptom does not establish the cause.

  2. No; it is a signal to verify with the operator.Correct answer

    The operator can check the number and any SIM change.

  3. No, so it should always be ignored.

    Uncertainty calls for verification, not permanent inaction.

A service offers text codes and a security key. What reduces SIM-swap exposure?

Why does this matter? A method that does not send approval to the number is not dependent on control of that SIM.

  1. A security key, with account recovery prepared.Correct answer

    A FIDO key does not receive its approval through the phone number and can resist phishing.

  2. Forwarding the same text code to two numbers.

    More destinations do not remove the weaknesses of text-message delivery.

  3. Turning off all additional verification.

    Without a second factor, a stolen password may be sufficient.

No registration. Your answers are not sent; the result is just for you.

Verify loss of service rather than guessing

Contact the operator, then protect financial and email accounts that use the number.

Choose a stronger second factor where available

References

Sources and further reading

The takeover mechanism is explained by the UK NCSC. CISA mobile communications guidance recommends carrier-account protection and methods that do not depend on text messages.

Content last reviewed