Phone Number Suddenly Stopped Working? What to Do During a SIM-Swap Attack

Phone Number Suddenly Stopped Working? What to Do During a SIM-Swap Attack

Your phone can lose service for ordinary reasons: a local outage, an unpaid bill, a damaged SIM, or a device that needs to reconnect to the network. But when the loss of service is sudden and is followed by password-reset emails, unexpected login alerts, or a message saying your SIM was changed, treat the situation as a possible account takeover.

A SIM-swap attack does not require a thief to possess your handset. The attacker persuades or tricks a mobile carrier into moving your phone number to a SIM or eSIM under the attacker’s control. Calls and text messages intended for you can then arrive on that other device. If any important account uses SMS codes for sign-in or password recovery, the stolen number can become a bridge into your email, banking, social media, or payment accounts.

The response is not simply “call the carrier and wait.” Two recoveries are happening at once: you need to recover the phone number, and you need to stop the number from being used as a trusted key elsewhere. This guide puts those tasks in a practical order.

First, decide whether this looks like fraud or a normal outage

One bar of signal, slow data, or a brief “SOS only” message is not proof of a SIM swap. Check the simple explanations without losing too much time. Restart the phone once, turn airplane mode on and off, and see whether another phone on the same carrier has service in the same place. If you have Wi-Fi, open the carrier’s official app or type its address yourself to look for an outage or billing notice.

Move from troubleshooting to incident response if any of these appear together:

  • Your phone changes from normal service to no service and stays that way while nearby customers still have coverage.
  • The carrier sends an email or app notice about a SIM, eSIM, device, account PIN, or number-transfer change you did not request.
  • You receive password-reset messages, one-time codes, or sign-in alerts from unrelated accounts.
  • Your carrier password no longer works, your account profile has changed, or you cannot reach the account through the usual recovery route.
  • Friends receive strange messages that appear to come from your number or one of your messaging accounts.

You do not need certainty before taking protective action. A short carrier outage is inconvenient; allowing an active takeover to continue can be much more costly. Use a different trusted device and a known-safe connection if possible, especially if the affected phone is behaving strangely in other ways.

The first 15 minutes: contain both sides of the attack

Start a simple incident note. Record the time service stopped, the last legitimate call or text, every alert you received, and the actions you take. Save screenshots of carrier emails and security notifications. This record helps you explain the sequence to the carrier and financial institutions, and it reduces the chance that you will repeat or skip a step while stressed.

1. Contact your carrier through a route you know is genuine

Use the number printed on a bill, the carrier’s official website or app, or an in-person store. Do not call a number supplied in an unexpected text, email, social-media reply, or search advertisement. An attacker may follow the first fraud with a fake “support” contact that asks for more information.

Tell the carrier that your service stopped unexpectedly and that you suspect an unauthorized SIM change or number port. Ask the representative to:

  • check whether a physical SIM, eSIM, device, or port-out change was completed or requested;
  • freeze further SIM and porting changes while the case is investigated;
  • return the number to a SIM or eSIM that you control;
  • invalidate the unauthorized SIM or eSIM;
  • review and remove unknown authorized users, contact details, or recovery methods;
  • reset the carrier account password and account PIN through a verified process; and
  • give you a case or ticket number.

The exact controls and names vary by carrier and country. Ask whether your provider offers a number lock, port freeze, transfer PIN, or extra verification for future SIM changes. Do not assume that changing only the website password cancels a fraudulent transfer already in progress.

2. Protect your primary email account immediately

Your main email inbox is often more valuable than the phone number because it can reset many other accounts. If you can still sign in, change its password from a trusted device, review recent sessions, sign out unfamiliar devices, and check whether the recovery phone, recovery email, forwarding rules, or filters were changed. Replace SMS as the second factor if the service supports a passkey, security key, or authenticator app and you can set it up safely.

If you are locked out, use the provider’s official account-recovery page. Type the address yourself or use a saved bookmark. Avoid “account recovery experts” offering help through private messages; legitimate providers do not need you to reveal a one-time code to a stranger.

For a deeper recovery sequence, use NerveFilter’s guide to what to secure first when an email account is hacked.

3. Contact financial providers if there is any sign of access

Check banks, cards, payment apps, cryptocurrency services, and shopping accounts that store payment methods. Look beyond completed transactions. A changed phone number, new payee, linked device, password reset, or attempted transfer can matter even when no money has left yet.

Use a trusted number on a statement, card, or official app. Tell the fraud team that your mobile number may have been taken over and ask what temporary restrictions are appropriate. Do not rely on SMS alerts reaching you while the number is outside your control. If unauthorized activity occurred, follow the institution’s dispute process and preserve its reference number.

Work outward from accounts that can unlock other accounts

After email and financial services, prioritize accounts by the power they give an intruder—not by how often you use them. A cloud account may hold saved passwords, device backups, documents, and remote-management controls. A mobile-wallet account may expose payment cards. A social account may let someone impersonate you and scam contacts. A workplace account may expose other people’s information as well as yours.

For each high-value account:

  1. Use the official app or a freshly typed address.
  2. Change a reused or exposed password to a unique one.
  3. Review recent sign-ins, active sessions, and trusted devices.
  4. Remove unfamiliar recovery methods, passkeys, app passwords, and connected apps.
  5. Sign out other sessions where the service offers that control.
  6. Save new recovery codes somewhere the attacker cannot reach.

A password change does not always close existing sessions. That is why the session and device review is a separate step. Likewise, removing your phone number as an authentication method does not automatically reverse changes an attacker already made.

What the attacker may be able to see—and what they may not

A successful SIM swap redirects service associated with the number. It does not automatically copy the photos, files, app data, or locally stored messages from your physical phone. The attacker may receive new calls and SMS messages after the transfer, including verification codes, but the exact behavior depends on the carrier, service, device, and messaging platform.

This distinction matters. Do not waste the first hour factory-resetting a phone that remains physically in your possession solely because its mobile service disappeared. A reset does not recover the number from the carrier and can erase useful evidence or access to authenticated apps. On the other hand, if the handset itself is also missing, combine this plan with the lost or stolen phone response.

An eSIM is not a magic shield against account-level social engineering. It removes a small card that can be physically moved, but a fraudulent carrier-side activation or number transfer can still target the subscription. Focus on the carrier account, transfer controls, and authentication methods rather than assuming the SIM’s format solves the risk.

Do not let the attacker direct the recovery

SIM-swap incidents create a perfect setting for secondary scams. You are expecting messages, you are in a hurry, and you may be willing to share details to get service back. Pause when someone contacts you first.

A carrier representative should not need a one-time code that unexpectedly arrives after an unsolicited call. A bank will not need you to move money to a “safe account.” A cryptocurrency exchange will not send an agent to recover funds through a messaging app. If a caller appears to know your name, carrier, or recent problem, that knowledge is not proof of identity.

End the contact and start a new one through a verified channel. This single habit also protects against phishing messages that imitate the carrier notice that began the incident.

Once the number is restored, the work is not finished

Test incoming calls and text messages, but treat restored service as the end of containment—not proof that every account is safe. Ask the carrier to confirm that the unauthorized SIM is inactive and that no pending port request remains. Review the carrier account again for unknown devices, email addresses, authorized users, and billing changes.

Then repeat the security review for your most important accounts. Look at the full incident window, beginning before the phone lost service. Attackers sometimes change recovery details or create a persistent session first and trigger the visible SIM transfer later.

Notify people if an account sent messages while it was compromised. A short factual warning is enough: tell contacts not to trust recent requests for money, codes, or links and identify the period involved. Do not forward the malicious link as an example.

If personal identity or financial information was used, follow the identity-theft and fraud-reporting process for your country. In the United States, the Federal Trade Commission directs victims to IdentityTheft.gov for a tailored recovery plan. Other countries have their own consumer-protection, police, or cybercrime reporting channels.

Build a safer setup before the next emergency

The most useful prevention measures reduce the authority of the phone number and make carrier changes harder.

Harden the mobile-carrier account

Use a unique carrier password and a PIN that is not based on a birthday, address, or the last digits of an identity number. Enable any available port lock or number lock. Keep the account email secure and remove people who no longer need authorization. Ask what verification the carrier uses for remote SIM and eSIM changes; features differ, so a control you remember from another provider may not exist on yours.

Move important accounts away from SMS when practical

SMS verification is better than relying on a password alone, but it depends on continued control of the number. The FTC specifically notes that text-message verification may not stop a SIM swap and recommends considering an authenticator app or security key for sensitive accounts. Current NIST guidance treats authentication over the public telephone network as restricted and says services should consider signals such as a SIM change or number port before sending a code.

Prefer a passkey or hardware security key where the service supports it. An authenticator app can also reduce dependence on the phone number, although the app and its backups still need protection. Keep recovery codes offline or in a secure password manager rather than in an inbox that the same account can unlock. NerveFilter’s comparison of passwords, SMS codes, authenticator apps, and passkeys can help you choose the right option for each account.

Prepare an offline recovery card

Write down the carrier’s genuine fraud number, your account number, the names of your most important providers, and where your recovery codes are stored. Do not include passwords or PINs on a card kept with the phone. The goal is to preserve the route to help when mobile data, calls, and SMS all fail at once.

A short decision rule

If your phone alone loses service and there are no security alerts, check the network and your account status. If service disappears while account changes or login alerts appear, contact the carrier and secure your email in parallel. If money, identity information, or workplace data may be involved, add the relevant fraud or security team immediately.

The strongest response is calm and ordered: verify through trusted channels, recover the number, close the attacker’s paths into other accounts, preserve evidence, and reduce future dependence on SMS. You do not have to know exactly how the transfer happened before you begin protecting what the number could unlock.

Official sources

Hasnain

Hasnain is the writer and editor behind NerveFilter, where he explains suspicious messages, account access, phone privacy, app permissions, and digital-safety recovery. His work is documentation-based: guidance is checked against current provider instructions and primary public sources, with limitations stated when devices, regions, or software versions differ. He is not presented as a certified cybersecurity professional. To report an error or ask an editorial question, email contact@nervefilter.info; never send passwords, codes, or banking details.