If your phone just went dark and you did not request a new SIM, treat it as a SIM-swap scam. The FTC says a thief can call your carrier, claim the phone was lost or damaged, and move your number onto their device. They then get texts, calls, and SMS login codes, and can drain a bank or take email and social accounts. Do not reply to requests for personal details. Contact the carrier on a number or site you already know, take the number back, then change passwords. SMS two-factor will not stop this; switch to an authenticator app or a security key. Check cards and banks for unauthorized charges. If a Social Security number or account numbers were stolen, go to IdentityTheft.gov. This is number hijack, not a missing handset.

If your phone just went dark, call the carrier first

A sudden loss of cellular service, plus a SIM you did not request, is how the FTC describes a SIM-swap attack in progress. Your job in the first hour is to get the number back from the carrier, not to install antivirus and not to follow a lost-phone lock checklist written for a device you cannot find.

  1. Call the carrier from a number or website you already know — the back of a bill, the carrier app on Wi-Fi, or the official site you type yourself. Do not call a number from a text, email, or pop-up. Do not reply if someone asks for a PIN, last four of the Social Security number, or account password.
  2. Tell them you did not request a SIM change and that the number must come back to your SIM or eSIM. Ask them to cancel the unauthorized transfer and restore service to your device.
  3. Set a PIN or password on the cellular account before you hang up, if one is not already in place, so a second call cannot move the number again.
  4. Change account passwords after the number is yours again, starting with email, then banks and social logins. Assume SMS codes that arrived while the phone was dark went to the thief.
  5. Check credit cards and bank accounts for unauthorized charges. If a Social Security number, card, or bank numbers were stolen, go to IdentityTheft.gov for recovery steps.

Texts that ask you to “verify” the outage are often phishing. Walk through how to spot a phishing email before anyone “confirms” the number. Limit posting your full name, home address, and phone number together online; that mix is what a caller uses to sound like you at the carrier.

SIM swap vs a lost phone

A missing handset is a device problem; a SIM swap is a number problem, and the first phone call is different.

QuestionLost phone (device missing)SIM hijack (number stolen)
Who has the numberThe number usually still sits on your SIM. You may see no bars because the phone is off, dead, or out of reach.The scammer has the number on a new SIM they activated. Your phone goes dark even though it is in your hand.
What texts doSMS and MFA codes may still land on the missing device. Lock Apple ID and Google so those codes cannot be read.Texts, calls, and SMS MFA codes go to the thief. They can reset email, social, and bank logins that still use SMS.
First callLock the accounts on the device: follow lost phone: lock Apple ID and Google. Then tell the carrier the hardware is gone.Call the carrier first and take the number back. Then change passwords. Do not treat this as a lost-phone article.

If the plastic phone is in your pocket and service vanished after an unexpected SIM activation, stay on this page. If you cannot find the phone at all, use the lost-phone guide and still ask the carrier whether anyone requested a SIM change.

Lock down accounts after you have the number back

Once the carrier restores your number, change every password that SMS codes could have unlocked, starting with email. The FTC’s order is number first, then passwords, then a money check. Multifactor authentication is something you know, something you have, or something you are; when you are worried about number takeover, prefer an authenticator app or a security key over SMS.

  1. Email first. Change the password on the inbox that receives bank resets. Sign out other sessions. Turn on an authenticator app or security key. Remove the stolen number as the only recovery method if the account lets you.
  2. Banks, cards, and payment apps next. Change those passwords from a device you trust. Review recent transfers. Call the number on the card if you see charges you did not make.
  3. Switch SMS 2FA off wherever an authenticator app or security key is offered. SMS codes are what a SIM swap is designed to steal.
  4. Social, shopping, and cloud logins that still text codes to this number. Unique passwords; no reuse from email.
  5. Consider a credit freeze if a Social Security number, card, or bank numbers were stolen. Compare freeze vs monitoring in credit freeze vs identity monitoring, then go to IdentityTheft.gov for the FTC’s recovery plan.

If you already typed a password or SSN into a fake carrier page, treat it as phishing: change that password, use IdentityTheft.gov if the scammer has the info, and report the message to reportphishing@apwg.org, 7726 from a mobile phone, or ReportFraud.ftc.gov.

FAQ

What should I do if someone stole my phone number?

Call the carrier from a number or site you already know, take the number back onto your SIM, then change email and bank passwords. Check cards for unauthorized charges. If a Social Security number or account numbers were stolen, go to IdentityTheft.gov.

How do I know it is a SIM swap and not a lost phone?

If the handset is in your hand and service died after a SIM you did not request, it is a hijack. If you cannot find the device, lock Apple ID and Google first using the lost-phone checklist, and still ask the carrier whether anyone moved the number.

Does SMS two-factor authentication stop a SIM swap?

No. The FTC notes that SMS-based multifactor authentication may not stop this scam, because the thief receives the text codes. Use an authenticator app or a security key instead.

Can a SIM swap drain my bank account?

Yes. Once the thief has the number, they can intercept SMS codes and try to reset bank, email, or social logins. That is why the FTC says to take the number back, change passwords, and check cards and banks.

Do I need to buy antivirus because my number was stolen?

No. A SIM swap is an account-takeover problem at the carrier. Microsoft Defender on a home PC is still a valid buy-nothing choice for malware. Do not run a second real-time scanner alongside Defender.

A SIM swap is an account-takeover problem; Microsoft Defender on a home PC remains a valid buy-nothing choice for malware. Habits that actually help are a carrier PIN, unique passwords, and an authenticator app or security key instead of SMS. If the household later wants a multi-device paid suite, use only these on-site paid links: TotalAV, Norton, Bitdefender, McAfee, Avast.