SIM Swapping: When a Stolen Phone Number Defeats Text-Message MFA

Text-message codes are the most familiar form of multi-factor authentication, and they are far better than a password alone. But they have a known weakness: they depend on the security of a phone number, and phone numbers can be stolen. The attack is called SIM swapping, and healthcare organizations that rely on SMS codes for email and remote access should understand it.

What a SIM swap is

Your phone number is tied to a SIM card, or an electronic equivalent, issued by your mobile carrier. In a SIM swap, a criminal convinces the carrier to move your number to a SIM or device they control. Once that happens, calls and text messages meant for you go to the attacker's phone, including the one-time codes used to sign in or reset passwords.

How attackers pull it off

Attackers typically do not hack the phone. They target the process around it:

Social engineering of the carrier. They contact customer service or a store, pretend to be the account holder and claim to have lost a phone.

Insider help. In some cases, a carrier employee has been bribed or tricked.

Gathering personal details. They use information from past data breaches, social media or phishing to answer verification questions.

Port-out requests. They request to transfer the number to another carrier, using stolen account details.

The attack is usually combined with a stolen password. The attacker already knows or has phished the username and password, then uses the swapped number to receive the text code and complete the login.

Why it matters at work

An administrator, billing manager or executive whose email is protected only by SMS codes is an attractive target. Control of their email can enable password resets for other systems, fraudulent payment requests or access to patient information. Staff often use personal phones for work codes, which places part of your security in the hands of a mobile carrier you do not manage.

Signs of a SIM swap

A phone suddenly loses service or shows "SOS only" for no clear reason

Unexpected texts or emails about account changes or carrier activity

Alerts about sign-in attempts the person did not make

Friends or coworkers receiving odd messages from the person's number

If someone notices these, they should contact the carrier immediately from another phone, then change passwords from a secure device.

Stronger alternatives to SMS codes

Authenticator apps

Apps that generate time-based codes on the device are not tied to the phone number, so a SIM swap does not give the attacker the code. They are a major improvement and widely supported.

Push approvals with number matching

Some authentication apps send a prompt to approve a sign-in, and require the user to enter a number shown on screen. This resists accidental approvals, though staff should be trained to deny prompts they did not start.

Hardware security keys

Small physical keys that plug in or tap to a device are among the strongest options, because they resist phishing, not only SIM swapping. They are well suited to administrators and other high-risk roles.

Passkeys

Passkeys replace passwords with cryptographic credentials stored on a device, and support is growing across services. Evaluate them where your systems support them.

Reduce risk from the carrier side

Even if you keep SMS for some uses, add protections:

Ask carriers about account PINs or port-out protection, and enable them

Use a strong, unique PIN on the mobile account

Limit personal information shared publicly

Use a business-owned phone number for sensitive accounts where practical

Avoid using the same number for high-value accounts and public contact

A practical plan for an organization

Identify which accounts rely on SMS, starting with email, remote access and financial systems.

Move administrators and executives to hardware keys or app-based methods first.

Roll out authenticator apps to all staff, with simple instructions and help desk support.

Keep SMS only as a last-resort fallback, or disable it where you can.

Protect the account recovery process, since attackers target "forgot password" flows.

Train staff to report sudden loss of cell service immediately.

Keep perspective

SMS-based MFA still stops many attacks, including the common reuse of stolen passwords. The goal is not to abandon it overnight in a panic, but to move toward stronger methods in order of risk.

Where we help

UnityCare IT helps healthcare and senior-living organizations in Oklahoma, Texas and Arkansas roll out stronger multi-factor authentication, with a focus on the accounts that would do the most damage if taken over.

Related service

An outsourced IT department with proactive maintenance and one number to call.

Related articles

Keep reading

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172