SIM Swap Fraud: How Scammers Hijack Your Wallet via Your Phone Number
Most fraud advice focuses on protecting your passwords. Almost none of it explains that your phone number itself can be quietly stolen — and that once it is, your passwords barely matter, because every "forgot password" link, every banking one-time code, and every app login verification will start arriving on a stranger's phone instead of yours. This is what security researchers call SIM swap fraud, and it has a lesser-known cousin — the call-forwarding code scam — that's arguably even easier for a criminal to pull off, because it needs no carrier involvement at all. This guide explains exactly how both work and, more importantly, the specific checks and habits that stop them.
Why Your Phone Number Is the Real Target
Almost every meaningful account you own — banking, email, mobile wallets, social media — treats your phone number as proof of identity. Forgot your password? A code gets texted to your number. Logging in from a new device? A code gets texted to your number. Confirming a bank transfer? Often, a code gets texted or called to your number. This design choice made sense when a phone number reliably meant "only one physical device can receive this." Once a criminal can redirect that number to a device they control, every single one of those verification systems starts working perfectly — for them, not you.
Method One: Classic SIM Swap Fraud
In a traditional SIM swap, a fraudster convinces your mobile carrier — either over the phone, in person at a store, or through the carrier's online account portal — that they are you, and that your number needs to be moved onto a new SIM card or eSIM they control. To pull this off, they first gather enough personal information about you to pass the carrier's identity checks: your name, date of birth, address, and sometimes account PINs or security answers, typically harvested beforehand through phishing emails, data breaches, or social media oversharing.
Once the carrier approves the switch, your original SIM is deactivated and your number becomes active on the attacker's device. The very next thing you'll usually notice is that your phone suddenly shows no signal, or reads "SOS only" — calls stop coming in, texts stop arriving, and you have no way of knowing why until you try to use your phone and realise something is deeply wrong. Meanwhile, every one-time password meant for you — banking, email, crypto exchange logins — is now landing silently on the attacker's phone, and they move fast: password resets, wallet drains, and locked-out recovery loops typically happen within the first few hours, before most victims even realise their number has been compromised.
Method Two: The Call-Forwarding Code Scam — No Carrier Needed
This second method is less widely known, arguably more dangerous precisely because of that, and doesn't require fooling a carrier's staff at all. It relies on a completely legitimate telecom feature — call forwarding — and simply tricks you into activating it yourself.
Here's how it plays out. You get a call or a text from someone posing as a courier company confirming a delivery, or a telecom provider claiming there's an issue with your SIM, or occasionally a bank claiming a "security verification" is needed. They create urgency — a package that needs rescheduling right now, an account that will be suspended if you don't act — and then ask you to open your phone's dialer and type in a short code, something like an asterisk, the digits 21, another asterisk, a phone number, and a closing hash symbol. They might call it a "confirmation code" or a "tracking code."
It is neither. That sequence is a real, standard telecom command called a USSD code — Unstructured Supplementary Service Data — and codes starting with *21* specifically activate unconditional call forwarding, silently rerouting every incoming call on your number to whatever number follows in the sequence: the scammer's number. Because this is a genuine network-level feature rather than a hack, it works instantly, requires no internet connection, and typically gives you zero notification that anything changed. Your phone keeps its signal. You can still browse the internet and send texts. The only symptom is that calls quietly stop reaching you — which is exactly why most victims don't notice until their bank account has already been drained through a voice-call OTP the scammer intercepted, or their WhatsApp account has been hijacked using the "call me" verification option.
Why the Call-Forwarding Trick Is Especially Dangerous
Government cybercrime units have specifically flagged this scam as harder to detect than most fraud, precisely because it exploits a basic, legitimate telecom function rather than malware or a hacked system — meaning ordinary antivirus software and spam filters have nothing to catch. It also requires far less effort from a criminal than a full SIM swap: no need to impersonate you convincingly to a carrier's customer service team, no need to pass identity verification questions. It only requires convincing you, once, over a single phone call, to type eleven characters into your own dialer.
Warning Signs You Should Never Ignore
Sudden, unexplained loss of signal. If your phone shows "No Service" or "SOS Only" for longer than a brief, explainable dip — especially if you haven't travelled anywhere with poor coverage — treat it as an emergency, not a glitch.
Calls that mysteriously stop arriving. If friends or family mention they tried calling you and it rang out or went straight to voicemail, while your phone showed no missed call at all, that's a strong sign your calls are being silently forwarded elsewhere.
A text confirming a SIM swap or number change you didn't request. Carriers often send a confirmation message when a SIM change is processed. If you receive one you didn't initiate, that is not routine — it means an unauthorised swap may already be underway or complete.
Unexpected password-reset emails or 2FA prompts. If you're receiving "verify it's you" messages for logins or password resets you never triggered, someone may already be attempting to use your compromised number.
Being asked to dial any code starting with an asterisk, sent to you by an unknown caller or an unsolicited text. This is the single clearest red flag for the call-forwarding scam specifically. No legitimate courier, telecom provider, or bank will ever need you to type a dialer code to "confirm a delivery" or "verify your SIM."
How to Undo a Call-Forwarding Hijack Immediately
If you suspect call forwarding has been activated on your line without your knowledge, most networks let you cancel every form of it — busy, unreachable, no-answer, and unconditional — with a single universal code: dial ##002# and press call. This deactivates all call forwarding instantly, restoring normal incoming calls to your own device. You can also check whether unconditional forwarding is currently active by dialling *#21#, which displays the current status without changing anything. If you ever need to be certain forwarding is off after a suspicious call, dialling ##002# takes seconds and costs nothing — make it a habit to do this immediately after any call or message that mentions "confirming" something through a code.
What to Do If You Suspect a Full SIM Swap
If your phone loses signal unexpectedly and you suspect a fraudulent SIM swap rather than a simple network issue, move fast and in this order. Contact your mobile carrier immediately through an alternate phone, a friend's device, or their online chat, and report a suspected unauthorised SIM swap — ask them to lock your account and reverse the change. Contact your bank and any linked financial or crypto accounts right away to flag possible compromise, even before you've confirmed the swap, since the first few hours carry the highest risk of drained accounts. Change the passwords for your email and any financial accounts from a separate, trusted device, since attackers with control of your number can trigger further resets while you're still locked out. Enable additional identity verification with your carrier going forward — most providers offer an account PIN or passcode that must be provided before any SIM or number change is processed, and this single step blocks the majority of social-engineering-based swap attempts.
The Deeper Fix: Stop Relying on SMS and Calls Alone
Both of these attacks succeed for the same underlying reason: too many of your most important accounts trust a phone number as the final word on your identity. The most durable protection isn't remembering to check for warning signs — it's reducing how much any single account depends on SMS or voice calls in the first place. Where your bank, email provider, or crypto exchange offers an authenticator app as an alternative to SMS-based codes, use it; an authenticator app generates codes on your device itself, completely independent of your phone number, so neither a SIM swap nor a call-forwarding trick can intercept it. For your most sensitive accounts, check whether your provider offers a hardware security key or app-based push approval instead of a text message — these cannot be rerouted no matter what happens to your phone number.
It's also worth asking your carrier directly whether they offer a "port-out lock" or additional security PIN requirement for any changes to your account — many carriers now offer this specifically in response to the rise of SIM swap fraud, and it typically takes only a short call to enable, permanently raising the bar for anyone trying to social-engineer their way into your number.
The One-Sentence Version
Never type a code beginning with an asterisk into your phone because someone on a call told you to, and treat any unexplained loss of phone signal as a possible emergency rather than a technical glitch — because in both cases, the thing being stolen isn't your phone. It's every account that trusts your phone number to prove you're really you.
Discussion