highLast updated: June 2026

SIM Swapping

Phone number takeover still enables account resets, MFA interception, and financial fraud when carriers are socially engineered.

Get the CSM Weekly Threat Brief and updates when this threat profile changes.

What\'s happening

Attackers convince or coerce carriers into moving a target phone number onto a new SIM.

That single move can unlock SMS-based MFA, password resets, brokerage accounts, and crypto wallets.

High-value targets include founders, executives, creators, and remote workers.

Who it targets

Executives with phone-based recovery settings

Crypto users

Consumers relying on SMS MFA as their main control

Real-world examples

Brokerage passwords reset after phone takeover.

Business email accounts recovered via SMS.

Attackers taking over creator accounts tied to a single phone line.

What it costs

Rapid account compromise across multiple services.

Identity recovery can take weeks even after the number is restored.

Victims often experience simultaneous financial and reputational harm.

How to protect against it

Move critical accounts to app-based or hardware MFA.

Set carrier PINs and account locks where available.

Audit phone number as a recovery factor on key services.

Use identity monitoring for telecom and account changes.

Vendors who specialize in this threat

VaultKey

Identity & Access Management

MFA, privileged access, and passwordless identity workflows for growing businesses.

Find More Vendors for This Threat

Signal Fraud Ops

Financial Fraud Prevention

Wire fraud controls, anomaly detection, and finance-team verification workflows.

Find More Vendors for This Threat

Mobile Sentry

Mobile Device Management

Device policy enforcement, inventory, and mobile security posture management.

Find More Vendors for This Threat

Related threats

Identity & Accesscritical

Credential Stuffing

Attackers are replaying massive stolen credential sets across business and consumer services to hijack accounts at scale.

Stat: 24B credentials available on dark web

Read Full Brief
Identity & Accesscritical

AI-Generated Deepfake Auth

Synthetic voice and video are being used to impersonate executives, bypass trust checks, and trigger sensitive actions.

Stat: Voice + video cloning now used in fraud

Read Full Brief