Bewary Get Bewary
Scam patternPublished Sep 17, 2026

Did a scammer SIM swap my phone number?

Bewary fraud research, published by Andrey Khayrullaev, founder. How we research scam patterns.

What the caller says

Caller ID: Wireless Support, (888) 555-0198. "Hi, this is the carrier fraud team. We are seeing a pending SIM change on your account from Miami. If this was not you, we need to stop it before your number is disconnected. I have your name, billing ZIP, and the last four on file. To verify you are the account owner, read me the six-digit security code we just sent. Do not hang up or the transfer will complete." Text during the call: "Your security code is 493118. We will never ask for this code." Second text: "A new SIM or eSIM was activated for your number. If this was not you, contact your carrier." Then your phone drops to SOS, No Service, or emergency calls only. Calls stop. Bank texts stop. The attacker has the line.

SCAM

Yes. Treat sudden no service as takeover. The giveaway is control of your phone number moving off your handset, so calls, texts, and reset codes land on the criminal's SIM or eSIM. The FBI's IC3 reported 1,075 SIM-swap complaints in 2023, with adjusted losses of more than $48.7 million.

How to spot this scam

  • Treat sudden no service as the alarm, not a bad tower.Why
  • Read any SIM, eSIM, or port-out notice as fraud if you did not request it.Why
  • Hang up when a caller asks for a one-time code.Why
  • Believe the code text over the voice on the phone.Why
  • Do not trust Caller ID just because it names your carrier.Why
  • Do not treat known facts as proof the caller is real.Why
  • Watch money accounts the minute your phone loses service.Why
  • Stop trying password resets while the attacker controls the number.Why
  • Treat a store visit you never made as identity theft.Why

What to do now

  1. Call your carrier from another phone and say SIM swap account takeover.Why
  2. Make the carrier kill the new SIM or eSIM before you reset accounts.Why
  3. Lock your email from a trusted device before you chase bank alerts.Why
  4. Freeze transfers and resets at banks, payment apps, and crypto exchanges.Why
  5. Replace SMS codes on money accounts after the line is back.Why
  6. Write the SIM-swap timeline while the carrier can still see it.Why
  7. Report the takeover to the FBI at ic3.gov.Why

What it looks like on your phone

Recreated example of the scam call: Caller ID: Wireless Support, (888) 555-0198.

"Hi, this is the carrier fraud team. We are seeing a pending SIM
A representative example based on common reports. Exact wording varies.

Got a message like this? Check yours free

Paste any text, link, or number you are unsure about. Bewary gives you a straight answer in seconds, and the exact reason why.

Private. Never sold, never tied to you.

The detail behind this

The reasoning behind each line above, for when the immediate question is settled.

Why each of those gives it away

Treat sudden no service as the alarm, not a bad tower.

In a SIM swap, the network now trusts another SIM or eSIM for your number. That is why voice calls, bank texts, and password reset codes stop arriving on your device at the same time.

Read any SIM, eSIM, or port-out notice as fraud if you did not request it.

The wording may say new SIM, eSIM activation, number transfer, port-out, device change, or line moved. Different carriers use different labels, but the action is the same, your number is being assigned to hardware you do not hold.

Hang up when a caller asks for a one-time code.

That code is the account check the caller cannot pass alone. Keeping you on the phone lets them trigger the code, hear it from you, and type it into the carrier portal before you can think through the warning text.

Believe the code text over the voice on the phone.

Many carrier and bank codes say some version of "we will never ask for this code" because the code is meant for the real customer only. A caller who says the warning does not apply is trying to turn the warning into background noise.

Do not trust Caller ID just because it names your carrier.

Spoofed Caller ID can show Wireless Support, Fraud Department, or a local-looking number while the call comes from anywhere. The test is the ask, and a caller who needs your PIN, password, or texted code is using you to pass the carrier's check.

Do not treat known facts as proof the caller is real.

SIM-swap crews may already have your billing ZIP, last four digits, device model, or old address from breach-dump markets or earlier phishing. Those details make the script sound like support, but they do not prove the caller controls the carrier account.

Watch money accounts the minute your phone loses service.

Once the number lands on the attacker's SIM, SMS recovery can deliver login codes and reset links to them. That gives them a path into bank, payment, email, and crypto accounts that still trust your phone number.

Stop trying password resets while the attacker controls the number.

If a reset sends a text code, you may be feeding fresh codes to the criminal's SIM. Use a different verification route, or wait until the carrier confirms your number is back on your device.

Treat a store visit you never made as identity theft.

Some attackers never call the victim. They persuade a carrier agent online, by phone, or in a retail store to move the line, and the tell is an account-owner action completed when you were not present and did not ask for it.

Working through the steps

Call your carrier from another phone and say SIM swap account takeover.

Use the carrier app, your bill, or paperwork you already had before the suspicious call, not a number from the caller or text. This gets the case routed to the team that can check SIM, eSIM, port-out, store, and agent actions on the line.

Make the carrier kill the new SIM or eSIM before you reset accounts.

Ask them to revoke the unauthorized SIM, restore the number to your device, end active sessions, and tell you when and how the change was made. Then add a stronger account PIN, port-out lock, number lock, or no-SIM-change note if your carrier offers it.

Lock your email from a trusted device before you chase bank alerts.

SIM attackers use the phone line to reset the mailbox that controls account recovery. Change the email password, sign out other sessions, remove unknown recovery phones, and check for forwarding rules that would copy reset emails to the attacker.

Freeze transfers and resets at banks, payment apps, and crypto exchanges.

Contact them through their apps or signed-in account pages and say your phone number was SIM swapped. Ask for holds on wires, withdrawals, new payees, card changes, password resets, and new-device approvals until the carrier restores the line.

Replace SMS codes on money accounts after the line is back.

SMS proves control of the phone number, and the scam was built to steal that control. Move high-value accounts to an authenticator app, passkey, or hardware security key where the account supports it.

Write the SIM-swap timeline while the carrier can still see it.

Record the exact time service dropped, the Caller ID name, what the caller asked for, which carrier texts arrived, and when bank or email alerts started. That timeline helps the carrier tie the unauthorized SIM event to account resets, withdrawals, or attempted transfers.

Report the takeover to the FBI at ic3.gov.

Include the words SIM swap, the carrier name, the phone number taken over, the time service died, the accounts hit, and any dollar amount lost or attempted. IC3 is the FBI's reporting route for internet crime, and the complaint number gives banks, exchanges, and investigators a clean incident reference.

Sources and reporting

Use official channels to confirm a suspicious request and report fraud.