Check for more than an ordinary outage
No service by itself does not prove a SIM swap. Check whether other customers nearby are affected and whether your device shows a routine network or billing problem. Warning signs become stronger when the outage is paired with a carrier notice about a new SIM, eSIM, device, password, or number-transfer request you did not make.[1]
Contact the carrier through a trusted route
Do not use a link or phone number in an unexpected alert. On another device or a trusted connection, open the carrier's official app, type its known website address, call a number from a bill, or visit a store. Ask the carrier to stop or reverse any unauthorized SIM activation or port, restore your number, and tell you what changed and when.
Lock down the mobile account
After the carrier has verified you, change the account password and add or replace the account PIN. Ask which protections it offers for SIM changes and number transfers. A PIN is useful as one layer, not a guarantee; continue with the account checks below because the number may already have been used.[1]
Secure email and password recovery
Email often receives password resets for other services. From a device you trust, change any exposed or reused passwords, review recovery addresses and phone numbers, remove unfamiliar sessions or devices, and inspect forwarding rules. Start with email and any password manager before moving through other accounts.
Call financial providers using known contact details
Review bank, card, payment, and investment accounts for unfamiliar logins, transfers, charges, new recipients, or changed contact details. If anything is wrong, use the number on the card, statement, or provider's official site to report it promptly. Do not approve a verification request you did not initiate.[1]
Move sensitive accounts away from SMS when possible
Text-message codes are vulnerable when someone controls your number. Where a service supports them, prefer an authenticator app or security key, save new backup codes securely, and remove unknown authentication methods. Keep MFA enabled even when the strongest available option is SMS; it still adds a factor beyond the password.[1][2]
Document the incident and check the wider impact
Record carrier case numbers, timestamps, account changes, and unauthorized activity. Search your inbox for password-reset and security notices, and review important accounts for changed recovery settings. If a scammer has sensitive identity or payment information, use IdentityTheft.gov to build a recovery plan for the information involved.[1]
Educational information only. This is not legal, financial, or telecommunications advice. Carrier controls and account-recovery processes vary; follow current instructions from the provider through a verified channel.