Your phone loses signal in the middle of the day. You restart it. Nothing changes. You blame the network and move on.
Meanwhile, someone else may be getting your calls and messages. That is how a SIM-swap attack can start, and a sudden “No Service” message can be an important warning sign.
What Is a SIM Swap?
Your phone number is linked to your account with your telecom company, rather than being permanently tied to the physical SIM card in your phone. If the number is transferred to a replacement SIM, the old SIM stops working and the replacement SIM becomes active.
This is a normal process when you lose your phone or need to replace a damaged SIM. SIM-swap fraud abuses that same process: a criminal tries to get your number transferred to a SIM they control.
How Attackers Take Over a Number
It can begin with personal details such as your name, date of birth, address and phone number. Some information may come from data breaches, while other details can be gathered from social media or through phishing and impersonation.
The attacker may then try to convince a telecom provider that the legitimate SIM was lost or needs to be replaced. They may use stolen information or fraudulent documents as part of the attempt.
Another route is mobile number porting, which allows a subscriber to move the same number to another network. If a fraudulent porting request succeeds, the original SIM can lose service while the number becomes active with the new operator.
Why SMS Codes Are the Weak Spot
Many banks, UPI apps, email services and social media accounts use one-time passwords (OTPs) sent by SMS as one form of account verification.
A SIM swap can undermine that protection because the SMS is delivered to the mobile number, not necessarily to the original physical SIM. If an attacker gains control of the number, they may receive SMS-based verification codes and attempt to use them to access accounts.
SMS-based verification therefore should not be treated as the only layer protecting important accounts. Where available, stronger options such as authenticator apps, security keys or passkeys can reduce reliance on a mobile number.
What India Has Done About It
India introduced an additional safeguard against fraudulent mobile number porting after a SIM swap or replacement. TRAI's Telecommunication Mobile Number Portability (Ninth Amendment) Regulations, 2024 came into force on 1 July 2024. Under the amended rules, a Unique Porting Code (UPC) cannot be allocated if the request is made before seven days have passed since the SIM swap or replacement. This measure was specifically introduced to help curb fraudulent porting after a SIM swap or replacement.
The seven-day restriction applies to mobile number portability. It does not mean that every type of SIM-swap fraud is prevented, so users still need to protect their accounts and respond quickly if their mobile service suddenly stops working.
How to Protect Yourself
You cannot control every step of a telecom company's SIM-replacement process, but you can make a stolen number less useful. Take an unexpected loss of mobile service seriously. If your signal stays dead while other phones nearby are working normally, contact your operator from another phone and check your bank and UPI accounts for unusual activity.
Never share OTPs or sensitive personal details with callers, even if they sound official. Be especially cautious of anyone asking for verification codes or account information.
For important accounts, consider moving away from SMS-based verification where stronger options are available. An authenticator app or passkey can reduce your dependence on your phone number. Secure your email account carefully because it can be used for password recovery for other services.
Finally, turn on transaction alerts. If you notice a transaction or account activity you did not authorize, contact your bank immediately and take steps to secure the affected account.
A SIM swap is not necessarily a hack of your phone itself. It is an attack on the system surrounding your mobile number. That is why the safest approach is simple: do not let one phone number be the only lock protecting your important accounts.