# SIM swapping: when a scammer becomes you by hijacking your phone number

> SIM swapping lets a scammer have your number transferred to their own SIM card and intercept your banking codes. Here's how to spot the early warning signs and lock down your mobile line.

- Source: https://www.envoyer-sms-gratuit.com/en/blog/2026-08-30/arnaque-sms-swap-sim-vol-numero-telephone
- Published: 2026-08-30 (30 August 2026)
- Author: L'équipe Envoyer SMS Gratuit
- Language: en
- Categories: Confidentialité
- Tags: Cybersécurité, Carte SIM, Protection des données, Smartphone, France 2026, Guide

---
It's 2:12 p.m. and you're on the underground. Your phone displays "No service". It's not the first time — that line has always been temperamental. You come back up to street level: still nothing. You restart the device, take out the SIM card, blow on it like an old game cartridge. Nothing.

Meanwhile, twenty miles away, someone is receiving your text messages. Including the one from your bank containing the confirmation code for a 4,800-euro transfer.

SIM swapping is one of the rare mobile attacks in which the criminal never touches your phone. They install no spyware, send you no booby-trapped link at the moment of the attack, and never guess your unlock code. They do something far simpler: they politely ask your carrier to switch your number onto a card they hold. And they get it.

![Person wearing glasses looking at the glowing screen of their smartphone in the dark, sitting on a sofa](/images/blog/2026-08-30-arnaque-sms-swap-sim-vol-numero-telephone/hero.jpg)

## Your number has become a key, not an address

For twenty years, a phone number served one purpose: making you reachable. Today it has become the master keyring of your digital life.

Think about what travels over your line by text message or phone call:

- your bank's transfer confirmation codes;
- account recovery codes for Google, Apple, Microsoft, Facebook, Instagram;
- login confirmations for your tax portal, your insurer, your health cover provider;
- password reset links for half the services you use.

An attacker who controls your number isn't stealing a contact detail: they're stealing the backup procedure for every one of your accounts. That's why SIM swapping, despite being far from new, remains one of the most profitable attacks in the mobile fraud landscape. Cybermalveillance.gouv.fr and ANSSI rank mobile line hijacking among the most destructive identity compromise vectors for private individuals, precisely because it grants access to everything else in a single move.

## How a scammer takes over your line in three steps

### Step 1: gathering the groundwork

SIM swapping never starts with the carrier. It starts with you — or rather with your public and leaked data. The attacker assembles a file: first name, surname, date of birth, home address, phone number, sometimes the last four digits of a bank card or a customer reference number.

This information comes from three main sources:

- **massive data breaches** at carriers, delivery companies or online retailers — France has seen several high-profile waves since 2024;
- **social media**, where people casually publish a date of birth, a home town, a mother's maiden name, a pet's name;
- **preparatory smishing**, a fake text message from a carrier or delivery service whose only purpose is to fill in the missing boxes of the file.

This groundwork is invisible. That's what makes SIM swapping so bewildering: the victim can't recall a single unfortunate click, because there wasn't one at the decisive moment.

### Step 2: requesting a replacement SIM

Armed with that file, the attacker contacts the carrier — in store, by phone, or through the online account if the password has leaked too. The pretext is mundane, universal, never suspicious:

> "Hello, my phone was stolen last night on the train. I've already bought a replacement handset, so I need a new SIM with my number."

There is nothing abnormal about this request. Thousands of honest customers make it every day. The advisor asks verification questions — which the attacker has prepared for. The replacement SIM is issued, or the eSIM is emailed as a QR code to scan.

### Step 3: the switchover

The second the new card is activated, yours is deactivated. It's an unavoidable technical rule: a number can only be attached to one active SIM. Your phone loses network. Calls and texts intended for your line now go to the attacker.

The exploitation window is short — often under an hour — but it's more than enough. Reset the email password, then the bank password, then approve the transfers using the codes now landing on their screen.

## The eSIM has changed the geography of the attack

Until recently, SIM swapping came with a physical constraint: someone had to collect a plastic card, meaning a trip to a store or waiting for the post. That friction offered a little protection.

The eSIM has removed that friction. A digital SIM activates remotely, in a few minutes, with a simple QR code received by email. For the legitimate user, it's genuine progress: no delay, no card to punch out, instant device switching. For the attacker, it's a shortcut.

French carriers have responded by tightening procedures: a confirmation code sent to the existing line, a waiting period of 24 to 72 hours before activation, systematic email notification. These safeguards do work — provided you read the notifications. An email saying "Your eSIM request has been received" that you never made is the single most important alarm bell in this entire article.

> If you receive a text or email confirming a replacement SIM request you didn't initiate: call your carrier immediately from another phone. You may be a few hours ahead of the attacker.

## The warning signs you must not ignore

Unlike spyware, SIM swapping is noisy. It produces very recognisable symptoms — as long as you don't write them off as a simple glitch.

| Observed signal | Naive interpretation | Interpretation to remember |
|---|---|---|
| Complete loss of network for no reason | "Carrier outage" | Line potentially deactivated |
| Text from a service you never contacted | "Spam" | Reset attempt under way |
| Email saying "your eSIM is ready" | "Carrier error" | Fraudulent request in progress |
| Friends and family say they can't reach you | "Network problem" | Your calls are being diverted |
| Sudden logout from your accounts | "App bug" | Takeover in progress |

The life-saving reflex fits in one sentence: **an isolated loss of network, while the people around you have normal coverage, is never trivial**. Ask someone next to you on the train, look at a colleague's phone. If everyone has signal except you, it isn't the network — it's your line.

![Hand holding a smartphone with a blank white screen against a bright, blurred background](/images/blog/2026-08-30-arnaque-sms-swap-sim-vol-numero-telephone/body-1.jpg)

## Locking down your line before an attack: six measures that work

### 1. Turn on your SIM card's PIN code

This is the most basic and most neglected measure. Many users disable the PIN to save three seconds at start-up. That code doesn't protect against SIM swapping itself, but it does prevent immediate exploitation of a physical SIM stolen along with the phone — a common scenario. Above all, change the default code (0000, 1234) supplied by your carrier.

### 2. Take SMS out of your banking authentication and critical accounts

This is the structural defence. As long as text messages remain your second factor, your security rests on a call-centre advisor you've never met. Prefer:

- **your bank's own app** with fingerprint or facial recognition approval (schemes such as "Sécur'Pass" or the equivalent depending on your bank);
- **[an authenticator app](https://www.amazon.co.uk/s?k=cl%C3%A9+authentification+double+facteur&tag=ds0608-21)** generating offline codes for your Google, Microsoft or social media accounts;
- **a physical USB-C or NFC security key** for genuinely sensitive accounts: it's the only factor a remote attacker cannot intercept, whatever control they have over your number.

### 3. Ask your carrier to lock your line

Orange, SFR, Bouygues Telecom and Free all offer protection mechanisms under different names: an additional password on the account, a secret question, blocking remote replacement-SIM requests, a requirement to come into a store with photo ID. These options are almost never enabled by default. A ten-minute call to customer service is enough to set them up — the best return on time invested in this whole article.

### 4. Clean up what your number reveals about you

Every loyalty form, every prize draw, every newsletter sign-up increases your attack surface. Regularly check whether your email address and number appear in known breaches via the Have I Been Pwned service, and exercise your right to erasure with the sites concerned — the CNIL sets out the procedure and the remedies available if a request is refused.

On the same principle, reserve your main number for serious uses. For a shopping site you'll visit once, a classified ad or a one-off sign-up, [a pay-as-you-go SIM card with no contract](https://www.amazon.co.uk/s?k=carte+SIM+pr%C3%A9pay%C3%A9e+sans+engagement&tag=ds0608-21) dedicated to online forms keeps you from scattering the number tied to your bank account.

### 5. Secure the link next door: your email address

SIM swapping only works fully when combined with access to your inbox. An address protected by a unique, long password stored in a password manager closes off half the attack scenario. If you prefer paper, [a secure password notebook](https://www.amazon.co.uk/s?k=carnet+de+mots+de+passe&tag=ds0608-21) kept at home remains infinitely safer than a "passwords.txt" file on your desktop.

### 6. Have a hardware plan B

If you lose your line, you'll need to call your carrier and your bank without using your number. Many households no longer have any alternative. Keeping [a basic backup mobile phone](https://www.amazon.co.uk/s?k=t%C3%A9l%C3%A9phone+mobile+basique+grosses+touches&tag=ds0608-21), charged, with a pay-as-you-go SIM from another carrier, turns a moment of panic into a minor inconvenience. It's also what will let you call emergency services if your main device is out of action.

## What to do within the hour

If you notice a suspicious loss of service, the order of operations matters more than speed.

1. **Call your carrier from another phone.** Report a suspected fraudulent SIM replacement and ask for the line to be suspended immediately. This is the action that cuts off the attacker's access.
2. **Call your bank** — using the card-blocking number printed on the back of your card, not a number found in a text message. Have transfers blocked and report that your second factor has been compromised.
3. **Change the password on your main email account** from a computer, and check the automatic forwarding rules: attackers often create them to keep intercepting messages afterwards.
4. **Log out of all active sessions** on your Google, Apple, Microsoft and social media accounts.
5. **File a police report.** For banking fraud, the complaint is what triggers the application of Article L133-18 of the French Monetary and Financial Code, which provides for the reimbursement of unauthorised transactions.
6. **Report the fraudulent text or message to 33700** if there is one in the chain of events, and report the incident on Cybermalveillance.gouv.fr to get support.

![Close-up of a woman's hands holding and using a black smartphone, blurred background](/images/blog/2026-08-30-arnaque-sms-swap-sim-vol-numero-telephone/body-2.jpg)

## Reimbursement isn't automatic — but it is possible

This is what worries victims most. The default rule favours the customer: an unauthorised payment transaction must be reimbursed by the bank, unless the account holder has been grossly negligent.

Everything therefore hinges on that notion of "gross negligence". France's Cour de cassation has handed down several important rulings recalling that merely having passed on a code received by text message is not enough, on its own, to establish gross negligence when the victim was deceived by a credible set-up. In a SIM swap case the argument is even stronger: you passed on nothing at all — the attacker obtained the codes directly.

So keep everything: screenshots of the loss of service, emails from your carrier, the log of your calls to customer services, the police report receipt. If you're refused, take the case to the banking ombudsman, then to the Banque de France if necessary.

## What this scam teaches us

SIM swapping says very little about your personal caution. What it really says is that we have turned an infrastructure designed for conversation — the telephone network — into the identity foundation for our entire digital lives.

As long as that foundation can be administered by an advisor at the end of a phone line, on the basis of information already circulating in stolen files, it will remain attackable. The good news is that the defence is entirely in your hands: every account you detach from SMS is an account SIM swapping can no longer reach.

Start with the most important ones — your email and your bank — and do it this week, not "one day". It takes twenty minutes. The theft takes five.

{/* image-sources: https://images.pexels.com/photos/26240403/pexels-photo-26240403.jpeg?auto=compress&cs=tinysrgb&dpr=2&h=650&w=940 https://images.pexels.com/photos/336948/pexels-photo-336948.jpeg?auto=compress&cs=tinysrgb&dpr=2&h=650&w=940 https://images.pexels.com/photos/8865050/pexels-photo-8865050.jpeg?auto=compress&cs=tinysrgb&dpr=2&h=650&w=940 */}
