SIM swap — Subscriber Identity Module swap
Qué es SIM swap?
Esta entrada está disponible actualmente solo en inglés.
A SIM swap is the carrier-side replacement of the SIM card associated with a mobile number: the subscriber's MSISDN is re-registered onto a new SIM, and the old card's identity is deactivated on the network. SIM swaps happen legitimately when a subscriber upgrades a phone or replaces a lost card, but the same procedure is the end state of an account-takeover attack, where a fraudster convinces a mobile operator to re-issue a victim's number and then intercepts the victim's SMS messages — including one-time passcodes.
More detail
From the network's point of view a SIM swap is a normal provisioning action: the operator re-issues the MSISDN onto a new SIM profile and the old IMSI stops authenticating. The network itself has no way to tell a fraud-induced swap from a customer-requested one at the moment it happens, which is why the recency of a swap became a fraud signal in its own right.
Swap recency matters because of what follows it: with the victim's number moved to a device the attacker controls, every SMS and voice call addressed to that number — password resets, sign-in OTPs, banking alerts — reaches the attacker. Verification and step-up-authentication flows therefore screen for a recently swapped SIM before sending an OTP or approving a sensitive action, weighing it as one risk signal rather than an automatic block. The queryable form of this signal is covered separately under SIM swap API, the CAMARA network API that answers whether a number's SIM changed inside a look-back window.
Preguntas frecuentes
- What is a SIM swap?
- A SIM swap is when a mobile operator re-issues a subscriber's phone number onto a new SIM card, replacing the old one on the network. It happens legitimately during device upgrades and card replacements, but it is also the move an account-takeover attacker completes after convincing the operator to re-issue a victim's number.
- Is every SIM swap fraudulent?
- No. Most SIM swaps are legitimate — subscribers swap SIMs when they upgrade a phone, damage a card, or move to an eSIM. Fraud teams treat a recent swap as one risk signal among several: it raises the chance that SMS messages now reach someone else, so sensitive flows add a check or step-up rather than blocking outright.
- How does a SIM swap lead to account takeover?
- Once a victim's number is registered on the attacker's SIM, every SMS and voice call addressed to that number reaches the attacker's device — including password-reset links and one-time passcodes. The attacker can then reset credentials on any account that verifies identity by SMS, which is why sign-in flows screen for a recently swapped SIM before delivering an OTP.
- How can an application check whether a number's SIM was recently swapped?
- Through a network API such as the CAMARA SIM Swap API, which asks the mobile operator whether the SIM behind a number changed within a look-back window and returns a carrier-asserted answer. Devotel Orbit exposes that signal through its Number Intelligence lookups and network-API surfaces.
See also
Build it on Orbit
Voice, messaging, email, video, and AI agents on one platform and one pay-as-you-go bill. Start free — no credit card required.