The Phone Number You Trust Is a Liability
Here's the uncomfortable truth: your phone number is not yours. Not really. It belongs to your carrier, and it can be transferred to someone else's device with a phone call and enough social engineering. That single fact unravels the entire edifice of SMS-based two-factor authentication, and it's why SIM swap attacks have become one of the most effective account takeover vectors in circulation today.
The mechanics are almost embarrassingly simple. A threat actor gathers enough personal information about you — your name, address, date of birth, maybe even your account number from a data breach — and calls your mobile carrier pretending to be you. They claim they've lost their phone, want a replacement SIM, and need their number ported to the new device. If the carrier's verification process is weak — and most of them still rely on little more than a name and a PIN — the swap goes through. Just like that, your number lives on someone else's SIM card.
Once the swap is complete, every SMS one-time password sent to your number lands in the attacker's hands. Password resets for your email, your bank, your cryptocurrency exchange — all of it routes through a channel the attacker now controls. Torsten George, chief cybersecurity evangelist at ID Dataweb, experienced this firsthand when a threat actor conducted a SIM swap against his AT&T account two weeks before the attack came to light. By the time George noticed, the attacker already had his OTPs and was calling him pretending to be AT&T customer service, asking for the second layer of his account's passcode.
George played along, bought time, and eventually performed a parallel login on his own device. The attacker had already collected enough information to kick George out of his account, but George was fast enough to reset his password and lock the intruder out before any real damage occurred. Still, the near-miss exposed something systemic: "He no longer had access, but in that short period of time, he had lowered passcode from extra security to standard security," George told Dark Reading. That sentence alone should keep every security professional up at night.
In June 2026, Polish authorities dismantled an international SIM swap gang that exemplified this threat. The operation, led by the Polish Cybercrime Bureau (CBZC) with support from the FBI and Homeland Security Investigations (HSI), arrested four suspects accused of breaching telecom partner infrastructure and employee email accounts to facilitate large-scale SIM swaps. According to CBZC, the group operated as a "regular source of income," using specialized software and social engineering to hijack victims' phone numbers, intercept SMS messages and email communications, and ultimately control cryptocurrency exchange accounts. Authorities estimate tens of millions of Polish złoty (over $5 million USD) were stolen and laundered via a distributed financial network.
ZachXBT, a blockchain crime investigator, identified one of the suspects as Wojtek Kulisz, alias "Merry," based on images released from the police raid. All four arrested individuals have been placed in pre-trial detention and face charges of participating in an organized criminal group, hacking into IT systems to commit theft, and money laundering—offenses carrying up to 25 years in prison.
What Carriers Got Wrong
George's experience with AT&T reveals a pattern that repeats across the industry. When he reported the fraud, he was disappointed with the lack of responsibility from the carrier. His phone number had been cancelled without his knowledge — a level of access that suggested the threat actor had penetrated beyond his individual account into AT&T's broader systems. "The threat actors were able to impersonate me in front of AT&T, that means that AT&T didn't do a geolocation check and didn't send an OTP," George said. "So they just relied on someone telling them it had to be changed. They need a multi-layer approach for such a high-risk transaction."
AT&T responded to Dark Reading by pointing to Wireless Account Lock, a free feature launched in 2025 that disables several types of account changes including SIM swaps and port-outs. The feature works, but it's not enabled by default. Users must manually opt-in, and historically adoption has been low because carriers don't highlight the risk or drive awareness. Meanwhile, the verification process for a number port — one of the highest-risk actions in telecommunications — still often comes down to a name, a date of birth, and whoever happens to be manning the support line that day.
The joint government advisory issued last year by cybersecurity authorities in the U.S., UK, Australia, and Canada specifically warned about Scattered Spider, a threat group that conducted SIM swaps during their campaigns to steal OTPs, credentials, and security answers. MITRE confirmed the group used SIM swapping to maintain persistence on mobile carrier networks. These are not amateur operators. They're well-resourced, methodical, and they've mapped the verification gaps in telecom infrastructure down to the specific questions that trigger a successful port.
Shinyhunters, the ransomware gang, operates from the same playbook. Impersonation is its primary attack methodology, according to George. And attackers rely on people being desensitized to OTPs popping up on their screens — it's become a habit to automatically respond, which makes social engineering attacks against users far more effective.