Can someone steal my phone number, and how would I know?
How a number is taken over, why losing signal is the alarm, the accounts to secure first, and the port-out protections most networks offer but do not advertise.
- Difficulty
- beginner
- Time
- 12 min
- Read
- 3 min
- Safety
- warning
Short answer
Yes. A criminal persuades your network to move your number to their SIM, usually with details gathered from breaches and social media. Your phone then loses signal permanently while theirs receives your calls and codes. If your phone suddenly has no service and others do, ring your network from another phone at once and say you suspect a fraudulent port.
SIM swapping is rarer than phishing but far more damaging when it happens, because a phone number is the recovery route for a great many accounts. It is a social engineering attack on your mobile network rather than an attack on your phone, which is why nothing on the handset can prevent it.
Safety
Step by step
- Understand the chain.Personal details are gathered from breaches, public records and social media. The criminal contacts your network posing as you and requests a replacement SIM or a port to another provider. Once it activates, your SIM stops working and all calls and texts go to them.
- Recognise the alarm.Your phone shows no service or emergency calls only, and it stays that way, while other phones on the same network work. Restarting and reseating the SIM changes nothing. That combination is the signal.
- Act from another phone immediately.Ring your network's fraud line from a landline or someone else's mobile. Say you believe your number has been fraudulently ported and ask them to stop it and restore the number.
- Secure email before anything else.From a computer, change the email password and remove the phone number as a recovery method or as a second factor while you sort it out. Email is what they will use next.
- Ring your bank on 159 or the number on your card.Banks rely on the number for one-time codes and for identifying you. Tell them the number is compromised so they stop trusting it.
- Move important accounts off SMS codes.Replace SMS with an authenticator app or a passkey on email, banking, the password manager and cloud storage. This is the durable fix, and it is worth doing before anything happens.
- Add a port-out protection with your network.Most UK networks can add a port-out PIN, an account password, or a note requiring extra verification before any SIM change. It is not on by default and you usually have to ask.
- Reduce what is publicly available about you.The attack needs enough personal detail to convince a call handler. Date of birth, address history and the answers to standard security questions are the ingredients — see the guides here on data brokers and security questions.
- Report it.Action Fraud, or Police Scotland on 101 in Scotland, plus your network's fraud team. Keep the timings — the exact minute the signal dropped is useful evidence.
Tips
- An eSIM does not remove the risk, because the attack targets the network's account process rather than the physical card.
- If you use a phone number as your username anywhere, treat that account as being at the same risk as an SMS second factor.
- Losing signal abroad is far more likely to be roaming than a port. Check whether other people on your network in the same place have service before panicking.
Common mistakes
- Waiting to see whether the signal comes back — Every minute is a minute where password reset codes reach someone else. Ring from another phone straight away.
- Relying on SMS as the second factor for email — It puts the most important account in the catalogue behind the credential most easily stolen. Move it to an app or a passkey.
- Assuming a strong password protects you — This attack does not need your password. It needs the reset code, which is now arriving on their device.
Questions people ask
How do they get past the network's checks?
By supplying enough personal detail to satisfy a call handler — date of birth, address, sometimes recent call or billing detail from a breach. It is social engineering of the network, not a technical exploit.
Am I liable for what happens?
That depends on the facts and on whether the network followed its own process. Complain to the network in writing, and if you are unhappy with the response, take it to the communications ombudsman scheme your provider belongs to.
Does a PAC code protect me?
Porting a number normally needs a PAC obtained from the losing network, which is a barrier. Fraudulent ports usually happen because that process was circumvented or the criminal obtained the PAC by impersonating you.