If your phone abruptly shows ‘no service’ or ‘SOS only’ and nothing you do brings the bars back, you may be watching a SIM swap happen in real time. This isn’t a rare glitch: the FBI’s Internet Crime Complaint Center logged SIM swapping complaints with adjusted losses of $68 million in 2021. The problem was serious enough that the FCC adopted rules requiring carriers to authenticate customers before SIM swaps, citing a wave of consumer complaints about unauthorized transfers. The thirty minutes after you notice the signal drop are the window where you can still stop an attacker from draining accounts protected by SMS codes.

How a SIM swap actually happens

A SIM swap doesn’t require touching your phone at all. An attacker first gathers enough personal information about you — a name, date of birth, address, maybe the last four digits of a social security number — often pulled from a previous data breach or phishing message. Armed with that, they contact your mobile carrier’s support line or use a self-service portal and impersonate you, requesting that your phone number be transferred to a new SIM card they control. If the carrier’s verification step is weak, the swap goes through in minutes. The moment it completes, your real phone loses all signal because your number no longer belongs to your SIM. From there, the attacker’s device receives your calls and texts, including the one-time passcodes that banks, email providers, and crypto exchanges send to ‘verify it’s you.’ The FCC’s proposed authentication rules exist precisely because carrier-side verification has historically been the weak link in this chain, not your phone or your password habits. It’s worth understanding why this weak link persists: carrier support agents are trained to resolve customer problems quickly, and a caller who supplies a name, an address, and the last four digits of a social security number sounds, on the phone, exactly like the legitimate account holder. Speed and convenience on the carrier’s side become the very tools an attacker exploits. That mismatch between what a support script asks for and what actually proves identity is the entire mechanism behind a SIM swap, and it’s why regulatory pressure on carriers, not just personal vigilance, has become part of the fix.

A plausible sequence, not a real case

The following is an illustrative sequence built to show how a SIM swap escalates once initiated, not an account of a specific individual.

Picture someone whose phone shows full bars all morning, then suddenly reads ‘SOS only’ while sitting in a meeting. They assume a network outage and keep working. An hour later they try to log into their email from a laptop and find the password has been changed. Then a bank app sends a login alert to an unfamiliar device. By the time they call their carrier from a colleague’s phone, the SIM has already been swapped for roughly ninety minutes, and a password reset chain has moved through email, banking, and a crypto wallet in that time. The carrier confirms a swap request was processed that morning through the online account portal, approved with an account PIN that had apparently been guessed or leaked months earlier. In hindsight, the warning signs were there before the phone ever lost signal: a phishing email about a ‘billing issue’ a week earlier, a password reused across two old accounts, and a PIN that had never been changed since the line was first activated. None of those details would have seemed alarming on their own, which is exactly why SIM swaps succeed so often — the pieces only look connected after the damage is already done.

What to do in the first thirty minutes

Treat sudden, unexplained loss of signal as a security event first and a network problem second. Most legitimate outages affect a wide area and are visible on your carrier’s status page or social accounts; a SIM swap affects only you. The response sequence below assumes you have access to another device — a work laptop, a tablet, or a family member’s phone — since your own handset is temporarily useless for calls and texts.

Confirm it’s a swap, not an outage

Check your carrier’s outage map or status page from another device, and ask someone nearby with the same carrier whether their signal is normal. If theirs works and yours doesn’t, and nothing you did (no travel, no settings change) explains it, treat it as a likely SIM swap rather than waiting it out.

Call your carrier through an alternate channel

Use a landline, a friend’s phone, or the carrier’s app on a secondary device to reach account security, not general support. Tell them you suspect an unauthorized SIM swap and ask them to freeze the line and reverse the transfer immediately. Carriers that have adopted stronger verification, in line with the direction of the FCC’s rules, should be able to lock the account and require in-person or enhanced verification before any further changes.

Lock down accounts tied to SMS codes

From another device, log into email, banking, and any account you know relies on text-message codes, and change the passwords immediately. Where possible, switch two-factor authentication from SMS to an authenticator app or a hardware key, since the whole point of a SIM swap is intercepting those text codes. Prioritize the email account first, since it’s usually the recovery path for everything else.

Watch financial accounts and file reports

Check bank and card statements for unfamiliar logins or transfers over the following days, and report anything suspicious to the institution right away. File a report with your local police and, if you’re in the US, with the FBI’s IC3, since documented complaints — like the $68 million in adjusted losses reported in 2021 — are part of what drives carriers and regulators to tighten verification requirements.

Why a password manager closes this gap

A SIM swap succeeds because a single point of failure — your phone number — sits underneath too many accounts as the fallback for both password resets and two-factor codes. The fix isn’t a stronger phone; it’s removing SMS as the weak link wherever you can. A password manager that generates and stores unique, long passwords for every account makes carrier PINs and account recovery answers harder to guess in the first place, since attackers often start a SIM swap attempt after finding a reused password from an old breach. Many password managers also include a built-in authenticator function, letting you move two-factor codes off SMS entirely and onto app-based codes that a swapped SIM can’t intercept. Beyond the immediate defense, a password manager also flags reused or weak passwords across your accounts, so you can find and fix the exact kind of credential leak that gave an attacker enough personal detail to impersonate you at the carrier’s support desk in the first place. It won’t stop someone from calling your carrier, but it removes most of what they’d gain by doing so. Think of it as shrinking the attack surface on both ends of the SIM swap: a strong, unique password makes the initial breach that feeds an attacker your personal details less likely, and an app-based authenticator makes the swap itself useless even if it succeeds.

Numero eSIMaffiliate link

A second number without a SIM card, in 80+ countries

Phone