We protect our passwords, we turn on two-factor authentication, we keep an eye on our bank statements. But very few of us stop to wonder what would happen if someone became, overnight, the official owner of our phone number.
That is precisely what SIM swapping promises: not hacking your phone, but convincing your carrier that you have switched devices. Once the line has been hijacked, every verification text — bank, email, social media, trading platforms — lands with the attacker. And you? You're left staring at a screen reading "No service."
In 2026, with eSIM now everywhere and remote activation just a few taps away, this attack has changed its face. It has become faster, quieter, and sometimes entirely paperless.

What exactly is SIM swapping?
SIM swapping (or a SIM swap) refers to a fraudster getting your phone number transferred to a SIM card or eSIM that they control.
This is not a technical hack of your smartphone. It is identity fraud committed against your carrier. The attacker impersonates you with customer service, in a store, or through the carrier's online account portal, and asks for:
- either a SIM replacement ("I lost my phone");
- or the activation of an eSIM on a new device;
- or a port-out to another carrier, using your porting authorization code.
In all three cases the outcome is identical: your SIM card is deactivated by the network, and the number switches over to the attacker's device.
Why your number is worth so much
For fifteen years, SMS has established itself as the default authentication factor. France's central bank and the Observatoire de la sécurité des moyens de paiement regularly point out that the strong authentication mandated by the European PSD2 directive still relies heavily, in practice, on codes sent by message or on validations tied to the line's number.
In concrete terms, a hijacked number unlocks a cascade:
| Targeted service | What the stolen number makes possible |
|---|---|
| Online banking | Approving transfers, adding payees |
| Password resets by SMS | |
| Social media | Account takeover, impersonation with friends and family |
| Crypto platforms | Withdrawing funds, often irreversibly |
| Government accounts | Account recovery, access to identity documents |
The number is no longer a simple contact identifier: it has become a master key. And that is exactly what makes it a target.
How fraudsters prepare the attack
SIM swapping is never a lucky break. It is the culmination of an information-gathering effort carried out beforehand, often over several weeks.
Step 1: harvesting personal data
To convince an agent or clear an automated check, the attacker needs to know you: date of birth, address, customer number, the amount of your last bill, answers to security questions.
This information comes from three main sources:
- Data breaches. In recent years the CNIL has documented a string of massive breaches affecting French telecom carriers, insurers and retailers, exposing identities, contact details and contract numbers.
- Smishing. A fake text message from a carrier, delivery service or government agency prompts you to enter your details on a pixel-perfect copy of a legitimate page.
- Social media. Dog's name, mother's first name, hometown: so-called "secret" questions are often public knowledge.
A good habit: treat any piece of information that could serve as a security question like a password. It should never be public, nor consistent from one service to the next.
To limit physical exposure, many users also adopt a privacy screen filter, which stops anyone from reading the codes you receive over your shoulder on a train or in an open-plan office. It isn't spectacular, but social engineering often starts with a perfectly mundane observation.
Step 2: contacting the carrier
Next comes the call — or the online request. The most common scenarios:
- "I've been robbed, I need to activate an eSIM immediately."
- "My phone fell in water, can you send a new SIM to this address?"
- A port-out request to a competing carrier, using an authorization code obtained through phishing.
French carriers have tightened their procedures: enhanced identity verification, cooling-off periods, security notifications. But the human weak point remains, particularly when the fraudster plays on urgency and distress.
Step 3: exploitation, in under an hour
Once the number has switched over, the attacker fires off password reset requests in quick succession. The window of vulnerability is short but sufficient: most victims don't immediately understand why their phone has lost signal, and assume a local outage first.

What eSIM really changes in 2026
Now that virtually every smartphone sold in France includes an eSIM — and some models have dropped the physical SIM tray altogether — the debate has shifted. Is eSIM safer, or more dangerous?
The upsides
- No physical SIM left to steal. A stolen phone no longer yields a removable card that can be slotted into another device.
- Hardware-level locking. The eSIM profile is stored in a secure element, making it hard to clone.
- Traceability. Every activation leaves a timestamped record on the carrier's side, which helps investigations.
The watch-outs
- Activation is fully digital. No more waiting for a card to arrive in the mail: a QR code or an in-app activation is enough. The victim's reaction window shrinks accordingly.
- The customer account becomes the weak link. If the carrier's online portal is compromised (reused password, data breach), an eSIM can be generated without any human contact at all.
- The QR code is a secret. An activation QR code that is photographed, forwarded, or intercepted in an inbox is a line profile handed over on a plate.
Put plainly: eSIM removes one physical attack vector and reinforces another, digital one. Protection is no longer about the SIM tray, but about the strength of your carrier account.
Warning signs you should never ignore
SIM swapping shows up through very recognizable symptoms. If you spot one, act within the minute.
- Your phone suddenly displays "No service," "SIM not provisioned" or "No network," while devices around you work fine.
- You receive a confirmation email for a SIM or eSIM order you never placed.
- You get a text announcing a port-out request or the release of your porting authorization code.
- Friends or family report strange messages sent from your number.
- You notice unusual login attempts on your accounts.
The simplest test: try calling yourself from another phone. If the call doesn't go through while the network is clearly available elsewhere, treat it as a security incident until proven otherwise.
Emergency response: the checklist
Time is the deciding factor. Here is the order of priorities.
- Contact your carrier from another line (landline, a relative's phone) and ask for an immediate line block and the cancellation of any recent SIM or port-out request.
- Alert your bank and have your cards blocked. In France, the Perceval service (a Ministry of the Interior platform) lets you report bank card fraud.
- Take back control of your email from a computer: change the password and replace SMS-based two-factor authentication with an authenticator app.
- File a police report at a police station or gendarmerie. The Cybermalveillance.gouv.fr portal lists the steps to take and points you to local providers.
- Report fraudulent texts to 33700, France's official reporting service for SMS spam and fraud.
- Document everything: screenshots, timestamps, case numbers. These items will be decisive in establishing any failure of due diligence on the carrier's part.
Keeping a secure password notebook offline, stored at home, also remains a surprisingly effective lifeline when all your digital access collapses at once.

Seven genuinely effective preventive measures
1. Lock down your carrier account
This is the first line of defense. A long, unique password, two-factor authentication enabled if your carrier offers it, and above all never the same password as your email account. Some carriers let you add a PIN that is required before any sensitive operation: turn it on.
2. Enable your SIM PIN
Many users have disabled it for convenience. Yet this code protects against the immediate use of a stolen SIM. And do change the default code (0000, 1234) supplied by the carrier.
3. Drop SMS as a second factor wherever you can
This is the most structural measure of all. The US NIST, as far back as its authentication guidelines, has considered SMS a weakened factor. Favor instead:
- an authenticator app (TOTP codes);
- a FIDO2 physical security key, in USB or NFC format, for your most critical accounts: this is currently the most robust protection against number hijacking, since the key cannot be transferred remotely;
- passkeys, now widely deployed, which do away with the password entirely.
4. Compartmentalize your numbers
Using a secondary number for public sign-ups, classified ads and non-essential services dramatically reduces the exposure of your main line. That's precisely the point of an online SMS-sending service that requires no registration: not scattering your personal number across every one-off interaction.
5. Back up your recovery codes
Every serious service provides single-use recovery codes. Print them out and store them away from your phone. A small fireproof document safe is a more serious storage solution than a desk drawer, especially if you also keep your PUK codes and subscription contracts in it.
6. Limit what the network and apps know about you
The less information circulates, the less material social engineering has to work with. Check what data is publicly visible on your profiles, disable SMS content previews on the lock screen, and be wary of apps requesting access to your messages.
7. Educate yourself, and those around you
The most frequent victims aren't the least connected, but the least informed about how social engineering works. A good everyday cybersecurity book, left on the coffee table, often teaches the whole family more than a long explanation. The guides published free of charge by ANSSI and Cybermalveillance.gouv.fr are also an excellent starting point.
And where does RCS fit into all this?
The gradual shift from SMS to RCS, accelerated by recent iOS and Android updates, changes nothing about the underlying problem. RCS is still anchored to the phone number as its primary identifier. An RCS profile reactivates on the line, not on the device.
In other words: even with end-to-end encryption, an RCS conversation thread can be taken over by whoever controls the number. Encryption protects the message in transit, not the legitimacy of the line's holder. That distinction is essential and often misunderstood.
It reinforces a simple principle: the security of your messaging starts at your carrier, before it ever starts in your app.
What French law says
Line hijacking falls under several criminal offenses: identity theft (Article 226-4-1 of the French Criminal Code), fraud (Article 313-1), and unauthorized access to an automated data processing system (Article 323-1).
On the carrier side, the GDPR imposes an obligation to secure data processing (Article 32) and to notify data breaches. ARCEP also regulates porting procedures and the applicable timeframes. Several court decisions, in France and elsewhere in Europe, have held carriers liable for carrying out a SIM change without sufficiently verifying the requester's identity.
In practice, then, a victim does have real leverage — provided they have kept the evidence and acted quickly.
In summary
SIM swapping illustrates an uncomfortable truth about modern messaging: our digital security rests on an identifier we don't fully control, managed by a third party, and transferable on request.
The three habits worth remembering:
- Armor-plate your carrier account — it's the real front door.
- Take SMS out of your critical authentication — use a dedicated app or a physical key.
- Treat a loss of signal as a security alert, not as an outage.
SMS remains a wonderfully simple and universal tool. But it was never designed to be the guardian of your digital identity. In 2026, knowing that is already a form of protection.



