SIM-swap fraud and bank accounts: warning signs and what to do
A SIM swap lets a criminal take control of a mobile number. That can make SMS codes and account-recovery messages part of a wider attempt to compromise banking, email or other services.
If your phone suddenly loses service without explanation, contact your mobile network immediately using another device and ask whether a SIM or eSIM change was made. At the same time, secure your email and banking accounts through official channels, change compromised passwords and tell the bank that your phone number may have been hijacked.
What a SIM swap changes
Your mobile number is controlled by the network, not permanently tied to one physical SIM. During a legitimate replacement, the network moves that number to a new SIM or eSIM. In a fraudulent SIM swap, a criminal tricks or compromises the provider into making that change without your permission, leaving your original phone disconnected.
The criminal may then receive calls and SMS messages intended for you. That does not automatically give them access to a bank account, but it can become one piece of a larger attack involving stolen passwords, email access, personal data and account-recovery processes.
Sudden loss of service is an important warning
A phone can lose signal for ordinary technical reasons, so one brief outage is not proof of fraud. Concern rises when the device unexpectedly shows no service for an extended period while other phones on the same network are working, especially if you also receive emails about password resets, new devices or changes you did not request.
Use another phone or Wi-Fi connection to contact the mobile provider through an official route. Ask whether a new SIM or eSIM was activated, when it happened and how to reverse an unauthorised change. Do not rely on a number supplied in an unexpected message about the incident.
Protect email as well as banking
Email is often the recovery channel behind banking, shopping and social accounts. If an attacker controls both your mobile number and email password, changing a bank password can become much easier for them. Use a unique email password and a strong form of two-step verification that does not depend solely on SMS where a service supports alternatives.
Check the email account for unfamiliar forwarding rules, recovery addresses and logged-in devices. A criminal who has entered the mailbox may create a rule that hides bank alerts even after you regain control of the phone number.
Tell the bank exactly what happened
Contact the bank through its app, official website or trusted phone number and say that you suspect an unauthorised SIM swap. Ask it to review recent logins, device registrations, new payees and transactions. If money has moved, report the payments as fraud immediately rather than waiting for the mobile network to finish its investigation.
Change banking credentials from a trusted device if the provider instructs you to do so. Never read one-time codes to a caller who says they are helping recover the account. During a real incident, criminals can call the victim and pose as the bank while they are actively trying to complete another authentication step.
Reduce the risk before an incident
Use unique passwords, enable strong authentication on email, and ask your mobile network what account-security options it offers for SIM changes. Keep the bank and network’s official contact routes somewhere accessible even when your own phone is unavailable. A second device or trusted household phone can be invaluable during recovery.
Be cautious about how much identity information you publish publicly. Date of birth, address history and answers to common security questions can help criminals impersonate customers. No single control prevents every SIM-swap attempt, but layers make it harder for control of a phone number to become control of your finances.
Recovery should include your other important accounts
Once the mobile number is secured, review other accounts that used SMS recovery: email, cloud storage, social media, payment apps and shopping services. Change passwords where compromise is plausible and sign out unfamiliar sessions. A SIM swap can be part of an identity takeover rather than an attack aimed only at one bank.
Check credit reports and important account notifications over the following weeks for unexpected applications or profile changes. If identity information was stolen, the consequences can appear later. Keep the mobile network's incident reference and the bank's fraud reference in case another provider asks when the takeover occurred.
Tell close contacts if the attacker may have used your number to impersonate you. A hijacked phone number can be used to request emergency transfers from family or colleagues while the victim appears unreachable. A short warning can prevent the identity takeover from spreading into a second person's bank account.
Sources and verification
Victoria Hughes — Consumer Rights Specialist
I treat a mobile number as an identity credential, not just a way to receive calls. A SIM-swap attack becomes dangerous when that credential is combined with an email password or other stolen personal information. If service disappears unexpectedly, I would not spend hours rebooting the phone before checking with the network. Use another device, confirm whether a SIM change occurred, then secure email and banking in parallel. Email gets special priority because it often controls password recovery for everything else. I also prefer authentication methods that do not rely solely on SMS when a service offers a stronger alternative. During recovery, be suspicious of anyone who calls 'to help' and asks for codes. A real incident creates perfect cover for a second scammer to sound believable. Finally, keep a small offline list of official emergency contact routes. Security plans that exist only inside the phone are least useful at the exact moment the phone number has been taken away from you. My recovery checklist extends beyond the bank because the number may have been the reset key for many services. Regaining signal is the start of cleanup, not proof that every account the attacker touched has automatically become secure again.
MyBankAnswers uses official provider and UK regulatory sources wherever practical. Information is general and does not constitute financial advice.