SIM swapping sounds technical. It isn't.
Here's how it works: an attacker calls your mobile carrier, pretends to be you, and convinces a customer service rep to transfer your phone number to a SIM card they control. From that moment, every text message meant for you — including two-factor authentication codes — goes to them instead.
Your bank. Your email. Your crypto wallet. Your password reset flows. All of them route through your phone number.
This isn't a sophisticated hack. It's social engineering. The attacker needs your name, maybe the last four digits of your SSN, and a convincing story. That information is often available from past data breaches — which means the attack gets easier every year as more of your data leaks.
High-profile victims have lost millions of dollars this way. And it can happen to anyone.
What you can do:
— Call your carrier and add a SIM lock or account PIN that's required for any changes
— Move away from SMS-based 2FA where possible — use an authenticator app instead
— Use a Google Voice or similar number for account recovery rather than your real mobile number
— Consider a separate "throwaway" phone number for anything financial
The deeper point: your phone number is not a secure identifier. It feels like one because we've built so much on top of it. But it's a utility that can be redirected by a 5-minute phone call.
The more of your life runs through digital systems, the more valuable it is to understand which links in the chain are weakest.
Stay sharp. 📡
— Dispatch Team @ DotComCrowd
newsletter.dotcomcrowd.com