Stand Against Crime

Impersonation, AI & Phishing · Global

Account Takeover & SIM-Swap Fraud

Your phone goes dead at 2am. By breakfast your email, your bank, and your exchange account belong to someone else. Here is how account takeover actually works — including the versions that walk straight past two-factor authentication — and exactly what to do in the first hour.

Updated Oct 2026 · 10 min read

SIM Swap

SMS · Your mobile operator

“Your number has been successfully transferred to a new SIM. If you did not request this, contact us immediately.”

This message arrives on their phone, not yours

Account takeover is the quiet one. There is no persuasion, no relationship, no story to see through — just a morning where your password no longer works and the recovery email on file is not yours. It is also the scam most likely to hit people who consider themselves careful, because several of the routes in do not require you to make a mistake at all.

The part that surprises people most is that two-factor authentication, on its own, does not settle it. Plenty of victims had 2FA switched on. It was redirected, relayed, or skipped entirely.

The thing to understand

Your email address and your phone number are not accounts. They are the master keys that reset every other account you own.

Whoever controls either one can reset their way into the rest. That is why a phone number is a weak place to receive security codes, and why hardening your email matters more than any individual password.

How Accounts Actually Get Taken

Six routes account for nearly all of it. Only two involve guessing a password.

1

SIM swap and port-out fraud

Someone persuades your mobile operator that they are you — using details scraped from breaches and your social media — and moves your number to a SIM they control, or ports it to another network. Your phone drops to “No Service” and every SMS code you own now arrives on their handset.

2

Stolen login sessions (infostealer malware)

The fastest-growing route, and the one that defeats 2FA. Malware picked up from a cracked download, a fake installer, or a malicious browser extension copies the session cookies your browser uses to stay logged in. The attacker imports them and is simply… already inside. No password, no code, nothing to approve.

3

Real-time code phishing

A convincing login page sits between you and the real site, passing everything through live. You type your password, it is relayed instantly; the site sends your genuine code, you type that too, and it is used within seconds. The 2FA worked exactly as designed — it just authenticated the attacker.

4

Old breaches and reused passwords

Your password from a site that was breached years ago is tried automatically against hundreds of other services. Nothing is hacked in the dramatic sense. One reused password simply still works somewhere that matters.

5

The “send me the code” hijack

A friend messages asking you to forward a six-digit code that has just arrived — they are “locked out” and gave your number as a reference. The friend’s account is already stolen, and the code is the one that transfers yours. This is how most WhatsApp and Telegram accounts change hands.

6

Account-recovery abuse

Rather than defeating your security, they go around it: a support agent is talked into a reset, or a recovery form is filled in with personal details that are easy to find. Your date of birth and the last four digits of a card are not secrets.

What a SIM Swap Looks Like From Your Side

Your signal dies

The phone shows “No Service” or “SOS only” and stays there. Calls and texts stop arriving. It is easily mistaken for a network problem at a bad moment — which is exactly why it is usually done overnight or at a weekend.

The codes start arriving somewhere else

Every SMS one-time code tied to your number now lands on their device: bank, email, exchange, payment apps. Some carriers send a “your number has been transferred” notice, but it goes to the new SIM.

Email falls first

They reset your email password using an SMS code, then change its recovery address and phone number so you cannot reset it back. Everything else resets through email, so this is the real prize.

The money moves

Bank, payment app, and crypto-exchange logins fall next. Transfer limits get raised, new payees are added, withdrawal addresses are whitelisted. Crypto exchanges are a favourite target because once a withdrawal clears, it is unrecoverable.

You find out late

Most people discover it hours later — when the phone is still dead, when a bank app refuses to log in, or when a friend asks why they got a strange message. The window where the damage can still be contained is the first one or two hours.

The Warning Signs

  • Your phone loses service suddenly and stays dead while other phones on the same network are fine.
  • A text or email saying your number is being transferred, ported, or that a new SIM has been activated — one you did not request.
  • An email confirming a password, recovery-address, or phone-number change you did not make.
  • Sign-in alerts, or logins from a country or device you do not recognise.
  • You stop receiving expected emails — a sign a forwarding rule or filter has been added to hide the alerts from you.
  • Being logged out of several accounts at once, or a password that suddenly does not work.
  • Friends receiving messages from your accounts that you did not send.
  • A phone call “from your bank or carrier” asking you to read out a code, immediately before any of the above.

How to Harden Your Accounts

You cannot stop a carrier employee being deceived, but you can make your number worthless to whoever gets it. Work down this list in order — the first two do most of the work.

  1. Put a port-out PIN or number lock on your mobile account. Every major carrier offers one, usually called a port freeze, number lock, or transfer PIN — it is the single most effective block on a SIM swap, and it takes five minutes in the carrier app.
  2. Move off SMS codes wherever an alternative exists. An authenticator app, a passkey, or a hardware security key cannot be redirected by swapping a SIM. Switch your email, bank, and any exchange first.
  3. Secure your email like it is the master key, because it is. Unique password, strongest available 2FA, and check its recovery phone and address now — that is where an attacker quietly plants their own.
  4. Use a different password on every account so a years-old breach cannot be replayed against you.
  5. Remove your phone number as a recovery or login method on accounts that no longer need it, and keep a separate, private recovery email that is not used anywhere else.
  6. Review active sessions and connected devices on your email and main accounts, and sign out of everything you do not recognise. Do this after any malware scare — stolen sessions survive a password change until the sessions are revoked.
  7. Never forward a verification code to anyone, including a friend, your bank, or your carrier. No legitimate organisation needs you to read one out.
  8. Turn on transaction alerts at your bank, and in the US place a free credit freeze so new accounts cannot be opened in your name.
  9. Set a voicemail PIN. Some automated reset systems call and leave a code, and default voicemail PINs are still trivially guessed.

Our pick

A password manager is what makes “a different password everywhere” realistic rather than aspirational. pCloud Pass is a privacy-first option — zero-knowledge, AES-256 encryption, with a free tier to try. Protect it with a master password you use nowhere else, and turn on 2FA for the manager itself.

Partner link — it may earn us a commission at no cost to you. Learn how we make money.

For the groundwork — choosing a manager, the different grades of 2FA, and locking down your email — see passwords & 2FA.

Free tool · runs in your browser

Got a “Security Alert” You Are Not Sure About?

Fake sign-in warnings and “verify your account” emails are how a lot of takeovers start. Paste the message and check it against the known patterns before you click anything.

Open the Email Scam Checker →

If It Has Already Happened

Order matters more than thoroughness here. Reclaim the two master keys first, then the money, then everything else.

  • 1. Your phone number. Call your carrier from another phone, say the words “SIM swap” or “unauthorised port”, and have the number returned to a SIM you control. Ask them to add a port freeze and note the fraud on the account.
  • 2. Your email. Reclaim it next, then immediately check three things most people miss: the recovery email and phone, any forwarding rules or filters that hide incoming alerts, and any app passwords or connected apps the attacker added.
  • 3. The money. Phone your bank, card issuer, payment apps, and any crypto exchange — the fraud line, not a web form. Freeze accounts, reverse what is still pending, and check for new payees, raised limits, and whitelisted withdrawal addresses.
  • 4. Sign out everywhere, then rotate. Revoke all active sessions and devices before changing passwords — otherwise a stolen session stays logged in through the reset. Then change passwords, starting with email and bank, and regenerate your backup codes.
  • 5. Assume the device is dirty if malware is possible. If a stolen session is the likely cause, scan the computer, or reset it, before you log back in — otherwise you simply hand over the new credentials too.
  • 6. Report it. US: the FTC at identitytheft.gov, the FBI at ic3.gov, and place a free credit freeze. UK: Action Fraud. India: 1930 / cybercrime.gov.in. Australia: Scamwatch and IDCARE. Keep the case reference — banks often ask for it.
  • 7. Warn your contacts. Hijacked accounts are used to run the next scam on the people who trust you — usually a “can you forward me a code” or an urgent money request.
  • Ignore anyone who appears afterwards offering to recover your accounts or funds for a fee. Victim lists get resold, and that is the follow-up scam.

Can You Get Your Money Back?

Honest answer: it depends almost entirely on how you paid and how fast you act. Speed is everything — report within hours, not days.

  • Credit cardOften

    You can dispute the charge (a “chargeback”) through your card network. The strongest protection of any payment type.

  • Bank transfer, UPI or debit cardSometimes — if you’re fast

    Report within hours so the bank can try to freeze the receiving account before the money is moved on. In India, call 1930 or file at cybercrime.gov.in immediately.

  • Payment apps (Zelle, Venmo, Cash App, PayPal)Varies

    Often treated like cash. PayPal “Goods & Services” has buyer protection; “friends & family” and most instant transfers usually don’t. Report to the app and your bank.

  • Gift cardsRare

    Contact the card issuer immediately — occasionally they can freeze an unredeemed balance. After that, it’s almost always gone.

  • CryptocurrencyHardest — usually not

    Crypto transfers are irreversible and cross-border. Recovery is rare, but act fast: report the transaction (with the wallet address and transaction hash) to the exchange involved and to law enforcement. If the funds land in a regulated exchange, it can sometimes freeze them.

What Actually Helps

  1. 1Act immediately — the faster you report, the better any chance of a freeze or reversal.
  2. 2Contact your bank, card issuer, or payment app now and ask them to dispute, recall, or freeze the payment.
  3. 3Report it to the authorities — here’s who to contact wherever you live. You often need a police or report reference number to pursue a dispute.
  4. 4Save everything: transaction IDs, wallet addresses, screenshots, phone numbers and usernames.

!Beware “recovery” scams

After you’ve been scammed, you may be contacted by someone promising to recover your money for an upfront fee, a “tax”, or a crypto payment. That is a second scam — often run by the same people, working from lists of known victims. No legitimate agency, lawyer, or service guarantees recovery or asks you to pay up front, and real police and banks never charge you to investigate. Never pay anyone to get your money back.

Frequently Asked Questions

I had 2FA turned on and was still hacked. How?

Almost always one of three things: your logged-in session was stolen by malware, so no login was needed at all; your code was phished in real time through a fake login page and used within seconds; or your SMS codes were redirected by a SIM swap. All three are routine, and none of them mean you did something stupid — they mean SMS codes and passwords alone are no longer sufficient.

My phone suddenly has no service. How do I tell a SIM swap from a network fault?

Check whether other phones on the same network nearby are working, and try your number from another phone — if it rings or texts deliver but you receive nothing, treat it as a swap. Do not wait it out. Call your carrier from another phone immediately and ask them to check for a recent SIM change or port request.

Is an authenticator app really safer than text messages?

Yes, against this attack. Codes generated on your device are not tied to your phone number, so moving your number elsewhere gains the attacker nothing. Passkeys and hardware keys are stronger still, because they also resist real-time phishing. SMS is better than nothing, but it is the weakest option and the one to move away from first.

They have my email. Why does that matter so much?

Because nearly every other account resets through it. Whoever controls your email can request a password reset almost anywhere and receive the link. That is why email is the first thing to reclaim and the first thing to harden — ahead of your bank.

Someone is asking me to forward a code that just arrived on my phone. Is that ever legitimate?

No. A code sent to you authorises something on your account, never on someone else's. If a friend is asking, their account is already compromised and the message is not really from them. Call them on a number you already have.

Will I get my money back after an account takeover?

It depends on the rail and your speed. Card payments have the best odds, bank transfers sometimes if reported within hours, and crypto withdrawals almost never. Report it to the bank or exchange the moment you are back in control — many have a fraud line that can freeze an account faster than a web form.

Informational only — not legal or financial advice. Sources: FBI IC3 public-service guidance on SIM-swap fraud, FTC consumer advice and identitytheft.gov, CISA guidance on phishing-resistant multi-factor authentication, and UK Action Fraud. Carrier controls and reporting routes vary by country — check with your own operator and regulator.

Warn someone — share this