Switching Phones Without Opening the Door to Scams: Which Texts to Save, Delete and Never Migrate

Back to the blog
27 September 202610 min read

"I sold my old phone through a trade-in platform. Three weeks later, I got a text that used my bank's name, my first name, and the exact amount of a transfer I'd made in March. I never found out whether there was a link in it, but it chilled me to the bone."

Accounts like this circulate among consumer advocacy groups, and they are hard to verify in detail: you almost never know where a specific leak comes from. But it points to a genuine blind spot. Switching phones is treated as a logistical chore — move the photos, reinstall the apps — when it is first and foremost a security operation. For a few days, your text messages exist in duplicate, your two-factor authentication is out of sync, and a device holding years of messages is left unsupervised.

This guide sets out the order of operations: what you actually need to keep, what you must absolutely not migrate, and how to handle the old device so it doesn't become the source of the next perfectly documented scam text.

Woman holding a smartphone with a blank screen in front of a laptop, overhead view of a desk

Why those few days are risky

Your number becomes temporarily unstable

When you activate a new line, a new SIM or an eSIM, there is almost always an interval during which the old carrier still works partially, or during which nothing receives messages properly. In practical terms:

  • bank verification texts may land on the old device if the physical SIM is still in it;
  • messages can be held by the network and then delivered in a burst several hours later, making it impossible to tell a legitimate code from one triggered by someone else;
  • your contacts know you're switching phones: the perfect pretext for a message along the lines of "Your new number isn't going through, confirm it here."

That confusion is the fuel of smishing. A fraudulent text doesn't succeed because it's well written, but because it arrives at a moment when you were expecting precisely that kind of message. Switching phones artificially creates that moment.

The old phone remains a goldmine of information

A five-year-old smartphone typically holds several thousand text messages, including one-time codes, order confirmations with a delivery address, medical appointment reminders, and insurance messages mentioning a policy number. None of that is confidential in isolation. Put together, it's a dossier that makes it possible to write a credible scam message.

France's data protection authority, the CNIL, regularly points out in its practical guidance on reselling devices that manually deleting files is not enough: only a full factory reset, on an encrypted device, makes data genuinely inaccessible. That's the point where most people stop too soon.

Step 1: sort before you transfer

The temptation is to migrate everything. That's a mistake: you duplicate sensitive data for no benefit whatsoever.

The texts worth keeping

There are fewer than you'd think, but they matter:

Type of messageWhy keep it
Exchanges with a tradesperson, landlord or buyerEvidential value in a dispute
Confirmations of medical or administrative appointmentsA record of dates
Personal messages (loved ones, condolences, announcements)Sentimental value
Fraudulent texts already received and reportedUseful if you file a complaint

For these messages, exporting is preferable to simple syncing. On Android, apps that export to text or spreadsheet formats let you archive a conversation and then delete it from the phone. On iPhone, an encrypted local backup via a computer serves the same purpose. In both cases, the archive is best kept on offline storage: an encrypted USB drive costs about as much as a tank of petrol and puts your evidence beyond the reach of a cloud account breach.

The texts you should never migrate

  • All one-time codes. They've expired, they serve no purpose, and they reveal which services you use. A scammer who sees codes from an online bank, a crypto platform and a mobile carrier knows exactly which script to write.
  • Texts containing a password in plain text. Some services still send them. Delete them, and change the password in question.
  • Old delivery notifications. They contain your address and sometimes the contents of the order.
  • Conversations with commercial short codes. No value at all, and they clutter up searches in your messages.

This sorting takes twenty minutes and mechanically reduces the exploitable surface, on both the old and the new device.

Step 2: move two-factor authentication before the SIM

This is the most common sequencing mistake, and the most painful to fix.

Many accounts send their verification code by text. As long as the line is active on a device you control, all is well. But if you swap the SIM before checking your access, you can find yourself locked out: unable to receive the code, and therefore unable to log in to change the verification method.

The order that works:

  1. List the accounts that rely on text messages. Bank, mobile carrier, email, social media, resale platforms, tax authority. A simple paper list will do — and this is exactly the moment when a small password notebook kept at home, off the phone, comes in handy.
  2. Switch whatever you can to an authenticator app. Text messaging remains the weakest factor: it is vulnerable to SIM-swap attacks and interception. France's cybersecurity agency ANSSI has for several years recommended favouring apps that generate codes locally, or even a physical security key for the most critical accounts.
  3. Retrieve the backup codes for each service and note them down offline.
  4. Only then activate the new SIM or eSIM.

If you use an authenticator app, don't forget to migrate it explicitly: most do not carry over with a standard backup restore. Losing those tokens is far more painful than losing text messages.

The special case of eSIM

More and more plans are moving to eSIM, which changes the logistics: there's no longer a card to move, but a profile to transfer from your carrier's online account or via a migration feature built into the operating system. Two practical consequences:

  • you need an internet connection at the moment of transfer, so Wi-Fi, so not in the middle of the street;
  • the old profile is deactivated, but the old phone is still full of your messages — the risk shifts, it doesn't disappear.

Also bear in mind that a text telling you "your eSIM is about to be deactivated, confirm your identity" is a smishing classic. No carrier will ever ask you to validate an eSIM via a link sent by message.

Step 3: genuinely empty the old phone

What isn't enough

Deleting conversations one by one, removing the SIM, erasing the photos: none of these actions cleans the device. The data remains recoverable, and above all many items escape a manual sweep — app caches, local backups, MMS attachments.

The sequence that works

  1. Sign out of your Google or Apple account. This is the forgotten step: a device still tied to an account stays locked for the buyer, and some data keeps syncing.
  2. Log out of sensitive apps one by one (bank, messaging, carrier account) rather than relying on a blanket wipe.
  3. Check that encryption is active. It is by default on all iPhones and on recent Android devices, provided a lock code exists. Without a passcode, encryption protects nothing.
  4. Run the factory reset.
  5. Physically remove the SIM card and the memory card. A microSD card is almost never encrypted and may contain MMS attachments. If you're not reusing it, destroy it.
  6. Restart the device and check that it displays the initial setup screen.

If you're keeping the old phone "just in case," an antistatic pouch or a small storage box for electronic devices stops it lingering in a drawer with a SIM still inside — that's how lines keep receiving codes for months on end.

Step 4: the first few days on the new phone

Reconfigure the protections, not just the apps

Restoring a backup does not automatically reinstate your filtering settings. To check on day one:

  • filtering of unknown senders in the Messages app;
  • built-in scam protection, which Google strengthened on Android in France during 2026 and which Apple offers as automatic message sorting;
  • the number blocklist you'd already built up: that list doesn't always migrate;
  • system updates, often behind on a brand-new device that has been sitting in stock.

Tell your contacts without creating confusion

If you're also changing your number, announce it through a channel your friends and family recognise — a call, a message in an existing conversation — and not via a text sent from an unknown number. That's precisely the format used by the "I've changed my number" scam. A new number that announces itself out of the blue is never credible, and that's a good thing.

When in doubt, a ten-second voice check settles the matter. It's also a good reason, if you're on the phone a lot, to invest in a comfortable Bluetooth earpiece: verifying by call is infinitely more reliable than trading messages with a number you don't know.

Watch your bank statements for a month

The consequences of a data leak during a device switch don't show up immediately. For four to six weeks, go through your statements line by line, including small recurring amounts — fraudulent subscriptions often hide below the €10 mark. In the event of an unauthorised debit, the Banque de France and the DGCCRF stress that you must report it to your bank immediately, and that a prompt stop request is a condition for reimbursement.

The ten-line recap

ActionWhenWhy
Sort and export the texts worth keepingBefore any transferAvoid duplicating sensitive data
Delete codes and passwords received by textBefore transferShrink the exploitable surface
List accounts using text-based two-factor authenticationBefore transferAvoid getting locked out
Migrate the authenticator appBefore the SIMTokens don't carry over with backups
Note the backup codes offlineBefore the SIMSafety net
Activate the new SIM or eSIMOn Wi-Fi, at homeeSIM transfer requires a connection
Sign accounts out of the old deviceBefore the resetAvoid lockout and residual syncing
Factory reset + remove SIM and microSDBefore resale or storageThe only reliable method
Recheck filtering, blocklists and updatesDay 1 on the new phoneThese settings don't always migrate
Monitor bank statements4 to 6 weeksSpot a fraudulent subscription

The takeaway

Switching phones isn't dangerous in itself. What is dangerous is doing it out of order, leaving a device full of messages lying around and two-factor authentication half moved. Scammers don't need to hack anything: they exploit a period when you're expecting unusual notifications and have let your guard down on verification.

The habit to build is simple: security moves before data. Access first, accounts next, photos and texts last. And the old phone doesn't leave your home until it has been reset, with the SIM removed and the welcome screen showing.

Finally, one reflex worth keeping throughout: any text received during a device switch that asks you to confirm an identity, a line, a number or a payment deserves maximum suspicion, even if it seems to arrive at just the right moment. That timing is precisely what should raise the alarm. If in doubt, in France the message can be forwarded free of charge to 33700, then deleted — without ever clicking the link.

#SMS#Sécurité#Mobile#2026#Vie privée#smishing#données personnelles#Guide#Opérateurs

Related articles

Envoyez votre SMS gratuitement

Service 100% gratuit et sans inscription. Envoyez vos SMS vers la France en quelques secondes.

Envoyer un SMS