Situation

Your phone suddenly loses service shortly after a breach, and your carrier says the number or SIM was moved to another device.

Recognize the signs that your number was hijacked

FTC describes a common SIM-swap warning pattern: your phone suddenly stops getting data, texts, or calls, or you receive an unexpected notice that your SIM was activated on a new device. Port-out fraud is similar in effect but moves the number to another provider. Both can cut you off from a phone number that many accounts use for password resets and verification codes.

A simple carrier outage can also cause lost service, so confirm the account status with your wireless provider. If the carrier says a SIM change or number port occurred and you did not authorize it, treat the event as an active account takeover.

Contact the wireless provider before chasing every other account

FTC guidance says targets of SIM-swap scams should contact the cellular provider immediately to take back control of the phone number. Use another trusted phone or device if necessary, and reach the provider through its official app, website, store, or published support number.

Tell the fraud team that the SIM or port was unauthorized and ask what it needs to reverse the change. Save the case number and any documentation the carrier provides. The mobile number is a recovery channel for other services, so restoring it early can stop the thief from receiving additional verification codes.

Ask whether the carrier offers an account lock or port protection

The FCC adopted rules requiring wireless providers to strengthen authentication, notify customers about SIM-change and port-out requests, and offer account protections that can block unauthorized changes. Ask your provider what account lock, number lock, port PIN, or similar protection it currently offers and how to enable it after recovery.

Use the provider’s actual terminology rather than assuming every carrier calls the feature the same thing. The practical goal is to add a barrier that a fraudster would have to clear before moving your number again.

Change the passwords that the phone number could unlock

After you regain control of the number, FTC says to change account passwords. Start with the primary email account because it can reset many other services, then move to banking, brokerage, payment, cloud-storage, social-media, and other high-impact accounts. Review recovery phone numbers and email addresses while you are there.

Do not change only the wireless password and assume the problem is contained. The thief may already have used SMS codes to reset another account while your number was out of your control.

Replace SMS verification on sensitive accounts when possible

FTC notes that text-message verification may not stop a SIM-swap attack because the thief who controls the number can receive the codes. For high-value accounts, consider an authentication app or hardware security key when the service supports it.

This does not mean SMS authentication is useless in every situation. The lesson is narrower: if a phone number was just hijacked, reduce the number of critical accounts that depend on that same number as their only second factor.

Review financial accounts for the period you lost service

FTC advises victims to check credit-card, bank, and other financial accounts for unauthorized charges or changes. Focus first on the window from shortly before the phone stopped working until after the number was restored. Look for password resets, new payees, transfers, card changes, or account-contact updates.

If money moved, contact the financial institution’s fraud department immediately and follow its dispute process. Keep the carrier case number because it can help explain why verification messages were intercepted.

Check email sessions and password-reset history

A hijacked phone number is especially dangerous when it can reset your email. Review recent login sessions, security alerts, forwarding rules, filters, app passwords, and recovery methods. Remove devices or sessions you do not recognize and verify that messages are not being silently forwarded to another address.

If the thief controlled email as well as the phone number, assume other account resets may have occurred. Search the inbox and trash for password-change, new-login, bank-transfer, and account-recovery messages from the time of the takeover.

Report broader identity theft if personal data was used

If the SIM swap was part of a larger identity theft involving your SSN, bank information, or new-account fraud, report the theft at IdentityTheft.gov and follow the recovery steps for those data types. FTC specifically directs people whose sensitive information may have been stolen to use IdentityTheft.gov for situation-specific guidance.

A carrier case alone documents the phone-number takeover, but it does not clean up a fraudulent credit account or bank transfer. Keep one recovery file that connects the carrier incident with the other institutions affected.

Preserve carrier notifications and fraud documentation

Save texts, emails, account alerts, store receipts, and support transcripts showing the unauthorized SIM change or number port. FCC rules emphasize provider processes for reporting, investigating, remediating, and documenting SIM-swap and port-out fraud. Ask the carrier what documentation it can provide about the incident once the account is secured.

That record can be useful if a bank, email provider, or other company later asks how the thief intercepted verification codes. Keep the documentation offline or in a secure account the attacker never controlled.

Example: your phone goes dark before a bank reset

Suppose your phone loses service at 8 p.m., and the carrier later confirms an unauthorized SIM change. You recover the number, enable the carrier’s account-lock feature, and then find a bank password-reset email from 8:20 p.m. You immediately contact the bank, change the email and bank passwords, remove unknown sessions, and review transfers.

You replace SMS verification with an authenticator app on the primary email and bank account, save the carrier case documentation, and report any broader identity theft. The response order matters because restoring the phone number first cuts off a major verification channel the thief was actively using.

Primary sources used

Check the official source before you submit sensitive information.