SIM Swap Attack Guide 2026 β€” Full Walkthrough: Recon, Social Engineering, Port-Out & Account Takeover

Blacksec

Administrator
Staff member
πŸ“± SIM SWAP ATTACK GUIDE 2026 πŸ“±

Full Walkthrough: Recon β†’ Social Engineering β†’ Port-Out β†’ Account Takeover



⚑ AUTHOR'S NOTE:

SIM swapping is the single most effective attack vector for account takeover in 2026. It bypasses 2FA, resets passwords, and gives you access to email, crypto, bank accounts, and social media β€” all from one phone number.

The reason it works is simple: telecom security is a joke. Customer support reps at T-Mobile, Verizon, AT&T are paid $15/hour and trained to be helpful, not suspicious. One convincing phone call and they'll port a number to a SIM you control.

I've personally used SIM swaps to access over $40k in crypto accounts, numerous bank accounts, and countless social media profiles. This guide covers everything I've learned.



πŸ“Œ TABLE OF CONTENTS

  • 1.0 β€” What is a SIM Swap? (The Mechanics)
  • 2.0 β€” Reconnaissance: Gathering Intel on the Target
  • 3.0 β€” Pretexts: What to Say When You Call
  • 4.0 β€” The Call: Scripts for T-Mobile, Verizon, AT&T
  • 5.0 β€” Bypassing Security Questions (The Most Important Part)
  • 6.0 β€” Post-Swap: Account Takeover Speedrun
  • 7.0 β€” Crypto Wallet Recovery (The Golden Target)
  • 8.0 β€” OpSec for SIM Swapping
  • 9.0 β€” Automation: SIM Swapping at Scale
  • 10.0 β€” Protecting Yourself from SIM Swaps



1.0 β€” WHAT IS A SIM SWAP?

The Mechanics:

A SIM swap (also called SIM splitting, SIM hijacking, or port-out fraud) exploits the way mobile carriers handle SIM card changes.

Code:
Normal Process:
  1. You lose your phone / SIM card
  2. You go to carrier store or call support
  3. You verify your identity (PIN, SSN, or account details)
  4. Carrier issues a new SIM linked to your number
  5. Old SIM stops working. New SIM works.
  6. You keep your number, texts, calls

SIM Swap Attack:
  1. Attacker gathers your personal information (OSINT)
  2. Attacker calls your carrier pretending to be you
  3. Attacker provides enough verification to pass
  4. Carrier issues new SIM β€” ships to attacker OR activates eSIM
  5. Your phone loses service. Attacker's phone gets your texts.
  6. Attacker uses SMS-based "Forgot Password" to reset your accounts
  7. Attacker drains your crypto, bank, or social media

⚠️ If your phone suddenly loses signal (full bars β†’ no service) for more than 5 minutes, you're likely being SIM swapped. Call your carrier immediately.

Why It Works in 2026:

  • Carrier support reps are underpaid and overworked β€” they want to end the call
  • Most carriers still use SMS as "secure" 2FA (it's not)
  • SSN, DOB, and address are easy to find (data breaches, OSINT)
  • Account PINs are often the default or a simple number
  • eSIM makes it even easier β€” no physical SIM needed, instant activation



2.0 β€” RECONNAISSANCE

Before you call, you need information. The more you have, the easier the swap.

Information Needed for a Successful SIM Swap:

InfoWhy NeededWhere to Get It
Full NamePrimary ID checkSocial media, data breaches
Phone NumberThe number being portedTheir Telegram, Twitter, IG, forum bio
Current CarrierWhich company to callNumber portability lookup (free online tools)
SSN / Last 4 SSNPrimary verification for US carriersFullz database, data breaches (free: haveibeenpwned)
DOBSecondary verificationFullz, social media, data breaches
Account PINGold standard for verificationDefault PINs (last 4 of SSN, 0000, 1234), SIM swap forums
Recent calls/textsAdvanced verification (some carriers)Difficult β€” skip targets that require this
Billing ZIPAddress verificationFullz, OSINT

OSINT Toolkit for Recon:

Code:
1. Find the target's phone number
   - Telegram: look at their profile (many display phone numbers)
   - Twitter/IG: bio, tweets, linked accounts
   - Forum profiles: many display Telegram handles
   - WHOIS: if they own a domain, check WHOIS for phone
   - Data breach dumps: use dehashed.com or leaked.zone

2. Identify the carrier
   - Use https://freecarrierlookup.com
   - Or: https://www.numberportabilitylookup.com
   - Enter the number β†’ get carrier name

3. Gather PII (Personally Identifiable Information)
   - Dehashed.com (search by email, username, phone, IP)
   - BeenVerified / Spokeo (paid but comprehensive)
   - Pipl.com (deep web search)
   - Data breach CSV dumps (search for their email/username)

4. Find security question answers
   - Check social media for: pet names, mother's maiden name, 
     where they went to school, favorite movie
   - Facebook memories, birthday posts, old MySpace data
   - LinkedIn (education, hometown, past jobs)

5. Build the profile
   - Create a text file with everything
   - Practice the information until you can answer naturally
   - Confidence is everything on the call



3.0 β€” PRETEXTS

Your pretext (cover story) determines whether the rep helps you or flags you.

The Four Most Effective Pretexts:

PretextBest ForDifficultySuccess Rate
"I lost my phone"All carriersEasy60-70%
"My phone was stolen"All carriersMedium50-65%
"My SIM stopped working"T-Mobile, AT&TEasy70-80%
"I want to switch to eSIM"Verizon, T-MobileMedium-Hard40-50%

Pretext Deep-Dives:

Code:
Why it works: Losing a phone is common. Carriers handle this daily.
The rep's script already covers lost phone scenarios.

Call flow:
  1. Call carrier support
  2. "Hi, I lost my phone and I need to transfer my number to a new SIM."
  3. Rep will ask for verification (PIN, SSN, or account details)
  4. Provide what you have with confidence
  5. If they ask "Are you sure you lost it?" β€” "Yes, I've been looking everywhere."
  6. They'll deactivate the old SIM and issue a new one

Code:
Why it works: Urgency = less scrutiny. Reps want to help a "victim."

Call flow:
  1. Call carrier support
  2. "Hi, my phone was just stolen. I need to lock my account and transfer my number."
  3. Sound worried but not hysterical (too much emotion = suspicious)
  4. "I'm worried they'll access my bank accounts."
  5. Most carriers have a "stolen phone" procedure β€” it's fast.
  6. They'll prioritize security and issue the new SIM quickly.

⚠️ Risk: Some carriers flag "stolen" reports and may ask for police report.
   Have a response ready: "I just filed one at the precinct on [street]."

Code:
Why it works: No implied urgency, no victim narrative β€” just a technical issue.
Reps handle this without extra security flags.

Call flow:
  1. Call carrier support
  2. "Hi, my SIM card isn't working. I've tried restarting my phone."
  3. "Can you check on your end if there's an issue with my line?"
  4. Rep will usually say "Let me try reactivating your SIM"
  5. "Is there an eSIM option? I've heard that's more reliable."
  6. If they suggest sending a new physical SIM β€” agree
  7. If they offer eSIM β€” even better, instant activation

⚠️ Risk: Some reps will try troubleshooting first (restart, settings check).
   Be patient. Let them try. Then say "Still not working." Move to eSIM.



4.0 β€” THE CALL: CARRIER SCRIPTS

T-Mobile Script (Easiest Carrier):

Code:
You:  "Hi, I need help with my line. My SIM card stopped working."
Rep:  "I can help with that. Can I have your phone number?"
You:  "[Target's number]"
Rep:  "And can you verify the account? What's your PIN or last 4 of SSN?"
You:  "I don't remember setting a PIN. Is the last 4 of SSN okay? It's [xxxx]."
Rep:  "Thank you. And your date of birth?"
You:  "[DOB. Use date from recon]"
Rep:  "And what's the billing ZIP code on the account?"
You:  "[ZIP from recon]"
Rep:  "Alright, verified. Let me check your line... I see your SIM is registered. Let me try refreshβ€”"
You:  "Actually, I've been having issues for a few days. Can we just switch to eSIM? I hear it's more reliable."
Rep:  "Sure, I can set that up. I'll send you an email with the QR code."
You:  "Great. Please send it to [email address]. I can't access my phone obviously."
Rep:  "Done. Your old SIM is deactivated. Check your email for the eSIM QR code. Once you scan it, your number will be active."
You:  "Thank you so much. That was really helpful."

βœ… SIM SWAPPED. You now control the number.

Verizon Script (Harder β€” They Have Better Security):

Code:
You:  "Hi, I need to transfer my line to a new phone. My old phone broke."
Rep:  "I'm sorry to hear that. Can I get your mobile number?"
You:  "[Target's number]"
Rep:  "To access the account, I need your account PIN or the billing password."
You:  "I think my PIN is [last 4 SSN or 0000]..."
Rep:  "That's not matching our records. Do you have the account owner's SSN?"
You:  "Is there another way to verify? This is my account, I just haven't called in a while."
Rep:  "I can send a one-time passcode to the account's backup email."
You:  "What email do you have on file?"
Rep:  "It ends in @[masked domain]. Does that seem right?"
You:  "That's correct. Can you resend the code? I'll check my email."
Rep:  [Sends code via email]
You:  [Give them the code β€” you have access to the email from recon]
Rep:  "Verified. Now, are you looking for a new SIM or eSIM?"
You:  "eSIM please. I'll use the QR code."
Rep:  "I'm sending it to your email. Check inbox."

βœ… This approach works when you have email access from recon.
   If you don't have email access, skip Verizon targets or find another vector.

AT&T Script (Medium Difficulty):

Code:
You:  "Hey, my SIM isn't working. I'm traveling and really need my line back."
Rep:  "I can help. What's your wireless number?"
You:  "[Target's number]"
Rep:  "What's your passcode or account PIN?"
You:  "I'm not sure. Is it the last 4 of SSN?"
Rep:  "That's not it. Let me try something... I can send a code via SMS."
You:  "That's the problem β€” my phone isn't getting texts. The SIM is dead."
Rep:  "I can send to your email on file. What email did you register with?"
You:  "[Email from recon]"
Rep:  "I've sent it. Please confirm the code."
You:  [If you have email access] "It's [code]. Got it."
      [If no email access] "I'm not seeing it in my inbox or spam. Can we try another option?"
Rep:  "I can verify with your recent calls. Who did you call last?"
You:  [Best guess based on recon β€” spouse, mother, or "I mostly text"]
Rep:  "What's your billing address?"
You:  "[Address from recon]"
Rep:  "Okay, I'll approve the eSIM transfer. Check your email for the QR code."

⚠️ AT&T sometimes asks about recent calls/texts β€” this is the hardest question.
   If they do, your best bet is: "I don't remember specifically. I mostly use WhatsApp."



5.0 β€” BYPASSING SECURITY QUESTIONS

This is the difference between a successful SIM swap and a failed one.

Common Security Questions & How to Find Answers:

QuestionWhere to Find AnswerSuccess Rate
Mother's Maiden NameFullz packages, obituaries, Ancestry, public records80%
Pet's NameInstagram, Facebook (pet photos often tagged with names)70%
High School NameLinkedIn education section, Facebook alumni groups90%
Street You Grew Up OnWhite pages, old addresses from data breaches60%
First Car Make/ModelOld Facebook posts ("Just got my first car!"), Instagram50%
Favorite MovieLetterboxd, Twitter movie posts, Facebook likes40%

What to Do When You Don't Know the Answer:

Code:
DO NOT GUESS. One wrong answer and some carriers lock the account.

Instead:
  1. "I think I set it to [common answer]... but let me check."
  2. "I changed it recently and can't remember. Is there another way to verify?"
  3. "Can you read me the hint? I might recognize it."
  4. "That's embarrassing β€” I set that years ago. What about using my SSN instead?"
  
Key principle: Sound frustrated with YOURSELF, not with the rep.
             "Ugh, I can't believe I don't remember this. I'm sorry."

Most reps will offer alternative verification if you're polite.



6.0 β€” POST-SWAP: ACCOUNT TAKEOVER SPEEDRUN

Once the SIM is swapped, you have a limited window β€” anywhere from 30 minutes to 24 hours before the target realizes and fights back.

The Priority Order:

Code:
T+0:00 β€” SIM activated on your device
T+0:01 β€” Check for SMS messages already received (accounts that sent codes)
T+0:02 β€” Go to target's email provider. Click "Forgot Password"
           β†’ "Send code via SMS" β†’ Enter the code you received
           β†’ Set new password β†’ Lock out the target
T+0:05 β€” Search email for "crypto", "coinbase", "binance", "blockchain"
           β†’ Reset password via email/SMS
           β†’ Withdraw all funds to your wallet immediately
T+0:10 β€” Search email for "bank", "chase", "boa", "wells fargo"
           β†’ Reset password. If SMS verification, you have it.
           β†’ Transfer funds via Zelle or wire to drop account
           β†’ If they have 2FA app, you may be blocked
T+0:20 β€” Search email for "paypal", "venmo", "cashapp"
           β†’ Reset β†’ Transfer to your account
T+0:30 β€” Social media (if the target is high-value)
           β†’ Twitter/IG: Reset, change handle, post crypto scam
           β†’ Discord: Access servers, DM members
T+0:45 β€” Delete all "Your password was changed" and "Login from new device" emails
T+1:00 β€” Check if target has SIM PIN enabled (some phones)
           β†’ If yes, you might still have access but need to move fast
T+2:00 β€” Re-check all accounts for any you missed
T+2:30 β€” Log out of everything, wipe browser, destroy SIM
           β†’ Total time: ideally under 3 hours from first code

⚠️ TIME IS YOUR ENEMY. Most targets notice within 2-4 hours when their phone stops working. Crypto accounts are the priority β€” bank accounts take longer to drain but have more fraud protection. Hit crypto first, bank transfers second.

Account Takeover Automation:

Code:
# takeover_bot.py β€” Automate account access after SIM swap
import time
import requests
from typing import Dict, List

class TakeoverBot:
    """Automated account takeover using SIM swap access."""
    
    def __init__(self, target_email: str, sms_api_key: str):
        self.email = target_email
        self.sms_api_key = sms_api_key
        self.session = requests.Session()
        self.recovered_accounts = []
    
    def read_sms(self) -> List[Dict]:
        """Read SMS messages from the swapped SIM via API."""
        resp = self.session.get(
            f"https://sms-api.io/v1/messages",
            params={"api_key": self.sms_api_key, "new": "true"}
        )
        return resp.json() if resp.status_code == 200 else []
    
    def check_email(self, email_pass: str) -> List[Dict]:
        """Search target's email for financial keywords."""
        # This connects to the email's IMAP
        # Returns list of accounts found
        keywords = ["coinbase", "binance", "kraken", "blockchain",
                    "chase", "bank of america", "wells fargo",
                    "paypal", "venmo", "cashapp", "robinhood"]
        return [{"source": kw} for kw in keywords]
    
    def reset_crypto_exchange(self, exchange: str) -> bool:
        """Reset password on a crypto exchange via SMS."""
        payloads = {
            "coinbase": {"email": self.email, "method": "sms"},
            "binance": {"account": self.email, "verify": "phone"},
            "kraken": {"username": self.email, "reset_method": "sms"}
        }
        if exchange not in payloads:
            return False
        
        resp = self.session.post(
            f"https://api.{exchange}.com/v1/password/reset",
            json=payloads[exchange]
        )
        return resp.status_code in [200, 202]
    
    def execute_swap(self, target_info: Dict):
        """Execute full account takeover."""
        print(f"[*] Starting takeover for {target_info['name']}")
        
        # Step 1: Read any pending SMS
        sms = self.read_sms()
        print(f"[*] Found {len(sms)} pending SMS messages")
        
        # Step 2: Reset email
        print(f"[*] Resetting email: {self.email}")
        # Email reset logic here (varies by provider)
        
        # Step 3: Find all financial accounts
        accounts = self.check_email("temp_pass_123")
        print(f"[*] Found {len(accounts)} financial accounts")
        
        # Step 4: Reset each financial account
        for acct in accounts:
            exchange = acct["source"]
            if self.reset_crypto_exchange(exchange):
                print(f"  βœ“ Reset {exchange}")
                self.recovered_accounts.append(exchange)
                time.sleep(30)  # Wait for SMS code
        
        return self.recovered_accounts



7.0 β€” CRYPTO WALLET RECOVERY

Crypto is the highest-value target for SIM swaps. Non-custodial wallets (MetaMask, Trust Wallet) can't be recovered through SIM swap alone β€” you need the seed phrase. But custodial accounts (exchanges) are vulnerable.

Crypto Accounts Vulnerable to SIM Swap:

PlatformSMS Reset?Withdrawal LimitTime to Drain
CoinbaseYes (if no 2FA app)$50k/day15 min
BinanceYes (if no 2FA)2 BTC/day15 min
KrakenYes (phone call option)$100k/day30 min
GeminiYes (SMS)$25k/day15 min
RobinhoodYes (SMS reset)$50k/day20 min
CashAppYes (SMS + email)$7,500/week10 min

Withdrawal Best Practices:

Code:
1. Reset exchange password via SMS
2. Wait for SMS, enter code
3. Set NEW password (don't reuse)
4. Login with new password
5. Disable any 2FA (if they have authenticator app, you may be stuck)
6. Withdraw all assets to YOUR wallet:
   - Coinbase β†’ Send to your wallet (always use bech32 address)
   - Binance β†’ Send to your wallet (ERC20 for USDC/ETH)
   - Use a fresh wallet for EACH exchange
7. Convert to Monero via ChangeNow (no KYC)
8. Monero wallet hold (24h)
9. Convert back to BTC and sell via Bisq
10. Total time: ~2-3 hours active



8.0 β€” OPSEC FOR SIM SWAPPING

What Carriers Log:

  • Every call to customer support is recorded
  • Account changes are logged (who made them, when)
  • SIM changes are logged (new IMEI, new ICCID)
  • IP addresses accessing online accounts are logged

How to Protect Yourself:

  1. Use a burner phone to call the carrier β€” never your real phone
  2. Use a VOIP number that's not linked to you (Google Voice, TextNow)
  3. Call from a different state/region than where you live
  4. Don't use any personal mannerisms or phrases
  5. Don't SIM swap targets in your own country if possible
  6. Never swap a number and then immediately access accounts from home IP
  7. Use VPN + VM for all account access after the swap
  8. Don't brag about swaps on Telegram/forums (this is how people get caught)
  9. If the target is high-profile (crypto whale, executive), expect more scrutiny

⚠️ The FBI has prosecuted numerous SIM swappers under the Computer Fraud and Abuse Act (CFAA) and wire fraud statutes. Sentences range from 2-10 years depending on amount stolen. Only target accounts where you understand the full risk picture.



9.0 β€” SIM SWAPPING AT SCALE

How Organized Groups Operate:

Code:
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚                      SIM SWAP GROUP                            β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚                                                                 β”‚
β”‚  Role 1: OSINT Researcher                                      β”‚
β”‚    - Gathers targets from: crypto Twitter, ICO participants,   β”‚
β”‚      Telegram groups, fullz databases, breach dumps            β”‚
β”‚    - Output: Target profiles with phone, carrier, SSN, DOB     β”‚
β”‚                                                                 β”‚
β”‚  Role 2: Caller (the "phoner")                                 β”‚
β”‚    - Makes the carrier call (best voice, most convincing)       β”‚
β”‚    - Uses burner phone + voice changer if needed                β”‚
β”‚    - Output: SIM swapped / eSIM QR code                         β”‚
β”‚                                                                 β”‚
β”‚  Role 3: Account Taker                                         β”‚
β”‚    - Receives the SMS codes from the swapped number             β”‚
β”‚    - Resets passwords, drains accounts                          β”‚
β”‚    - Output: Crypto in central wallet                          β”‚
β”‚                                                                 β”‚
β”‚  Role 4: Liquidator                                            β”‚
β”‚    - Handles the crypto off-ramp (Monero β†’ cash)               β”‚
β”‚    - Has existing pipelines to BTC ATMs, P2P exchanges         β”‚
β”‚    - Output: Clean cash distributed among team                 β”‚
β”‚                                                                 β”‚
β”‚  Split: Researcher 15%, Caller 25%, Taker 35%, Liquidator 25%  β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜



10.0 β€” PROTECTING YOURSELF

Since you now know how the attack works, here's how to make sure it doesn't happen to you.

Anti-SIM Swap Checklist:

Code:
β–‘ Set a unique account PIN with your carrier (NOT your SSN, DOB, or 1234)
β–‘ Enable "Port-Out Protection" or "Number Lock" (T-Mobile calls it "Account Takeover Protection")
β–‘ Remove SMS-based 2FA from ALL important accounts
β–‘ Use authenticator app (Google Authenticator, Authy) instead of SMS
β–‘ Use hardware security key (YubiKey) for crypto exchanges
β–‘ Don't display your phone number publicly (Telegram, Twitter, forums)
β–‘ Use a Google Voice number for public-facing accounts (can't be SIM swapped)
β–‘ Check haveibeenpwned.com regularly for your email
β–‘ Use a separate phone number for crypto that's not linked to your identity
β–‘ If your phone suddenly loses signal: call carrier immediately, then change all passwords



END OF SIM SWAP GUIDE

Remember: every security measure you learn also teaches you how it can be broken. Use that knowledge wisely.
 
Top