Why Are Travellers Especially Vulnerable to SIM-Swap Attacks?
Travellers face a uniquely elevated risk from SIM-swap and account-takeover fraud. When you're abroad, you're less likely to notice immediately that your home number has gone dead, and customer-service calls to your carrier can be difficult, slow, or impossible in a different time zone — giving attackers a wider window to drain accounts before you can react.
The FBI's Internet Crime Complaint Center (IC3) reported over 1,075 SIM-swapping incidents in one year, with losses topping $48 million — and those are only the cases that were formally reported. The real figure is almost certainly higher. Meanwhile, a 2023 GSMA report on mobile fraud found that account-takeover attacks exploiting phone-number portability remain one of the top three vectors for financial fraud globally.
Here's the core problem: your phone number has become a master key. Banks, email providers, cryptocurrency exchanges, and travel booking platforms all use SMS codes to "verify" your identity. Whoever controls your number, controls your accounts — even if they never know your passwords.
How Does a SIM-Swap Attack Actually Work?
A SIM-swap attack unfolds in a predictable sequence, and understanding each step is the first move toward stopping it.
Step 1 — Reconnaissance. The attacker gathers personal data about you: your full name, date of birth, home address, and the last four digits of your Social Security Number (or national ID equivalent). Much of this is available through data breaches, social media, or phishing emails. Sites like Have I Been Pwned let you check whether your email address has appeared in known breaches.
Step 2 — Social engineering the carrier. The attacker calls your carrier's customer service line (or visits a retail store) pretending to be you. They claim their phone was lost or damaged and request that your number be transferred to a new SIM they control. Many carriers still rely on knowledge-based authentication — "What's your mother's maiden name?" — which is trivially bypassed with stolen data.
Step 3 — Takeover. Once your number is ported, the attacker requests password resets on your email, bank, and investment accounts. The SMS verification codes land on their device. Within minutes, they can lock you out of every account tied to that number.
Step 4 — Monetisation. Funds are transferred, cryptocurrency wallets are drained, and loyalty points are redeemed — often before you even realise your phone has gone silent.
The entire process can take as little as 15 minutes. When you're jet-lagged in a hotel room in Bangkok or boarding a connecting flight, 15 minutes is an eternity.
What Makes Travellers a Preferred Target?
Criminals specifically time attacks to coincide with known travel periods for several reasons.
- Your phone may already be behaving oddly. Roaming issues, weak signal, and silent periods are normal when travelling, so you're less likely to flag a sudden loss of service as suspicious.
- Your carrier's fraud team can't reach you easily. If your carrier tries to call your number to verify a suspicious port request, you won't receive it — because your number is being ported away.
- You're more likely to use public Wi-Fi. Airports, hotels, and cafés are hotbeds for credential-harvesting attacks that feed the reconnaissance phase.
- Your accounts are often in a "travel mode" state. You may have temporarily disabled location-based alerts or paused fraud notifications to avoid false positives while abroad.
If you're planning an extended trip — whether it's studying abroad for a semester or working remotely across multiple countries — your exposure window is proportionally longer.
How Can You Lock Down Your Carrier Account Before You Travel?
The single most effective step you can take is adding a carrier-level PIN or passphrase to your account before you leave home. This is different from your account password; it's a secondary code that must be provided before any SIM change, number port, or account modification is authorised.
Set a Port-Out PIN or Passcode
Every major carrier offers this feature, though it goes by different names:
- AT&T: "Extra Security" passcode (6–15 digits)
- T-Mobile: "Account Takeover Protection" (a dedicated toggle in account settings)
- Verizon: "Number Lock" feature
- UK carriers: "Port Authorisation Code (PAC)" request — you can instruct your carrier not to release it without in-store ID verification
Call your carrier's customer service or log into your account portal and enable this before your departure date. Choose a PIN that isn't derived from your birthday, address, or any detail that could be found in a data breach.
Request In-Store-Only Verification
Some carriers allow you to flag your account so that SIM swaps and port requests can only be processed in person with a government-issued photo ID. This is the nuclear option — and it's highly effective. The trade-off is that if you genuinely lose your phone abroad, getting a replacement SIM is more complicated. Weigh that risk against your threat model.
Freeze Your Number Portability
In the United States, the FCC has rules requiring carriers to implement additional authentication for SIM swaps, including sending a notification to the account holder before a port is completed. Make sure your carrier has your current email address on file — not just your phone number — so these alerts reach you even if your number is compromised.
Why Should You Replace SMS Two-Factor Authentication Right Now?
SMS-based two-factor authentication (2FA) feels like security, but it's the weakest link in your account-protection chain. Once an attacker controls your number, every SMS code becomes theirs. Replacing SMS 2FA with an authenticator app is the single highest-impact security upgrade you can make — and it takes about 20 minutes to do for your most important accounts.
Authenticator Apps vs. SMS: A Direct Comparison
| Feature | SMS 2FA | Authenticator App (e.g., Google Authenticator, Authy) | Hardware Key (e.g., YubiKey) |
|---|---|---|---|
| Vulnerable to SIM-swap | ✅ Yes | ❌ No | ❌ No |
| Works without cell signal | ❌ No | ✅ Yes | ✅ Yes |
| Works offline (airplane mode) | ❌ No | ✅ Yes | ✅ Yes |
| Requires physical device | Phone | Phone | Physical key |
| Cost | Free | Free | ~$50–$70 |
| Ease of setup | Very easy | Easy | Moderate |
| Best for travellers | ❌ | ✅ | ✅ (for high-value accounts) |
Switch your email, banking, social media, and cryptocurrency accounts to authenticator-app-based 2FA as a priority. For accounts holding significant financial value — brokerage accounts, crypto wallets — consider a hardware security key like a YubiKey as an additional layer.
Use Passkeys Where Available
In 2025–2026, passkeys have become widely supported by Google, Apple, Microsoft, and major banks. A passkey is a cryptographic credential stored on your device that replaces both your password and your 2FA code. It cannot be phished, intercepted over SMS, or stolen via a SIM swap. If a service offers passkey login, enable it.
Does Using an eSIM Reduce Your SIM-Swap Risk?
This is one of the most important — and most underappreciated — security advantages of eSIM technology. Unlike a physical SIM card that can be cloned or swapped at a carrier store, an eSIM profile is cryptographically bound to your device's embedded hardware chip (the eUICC). A criminal cannot walk into a store and ask for your eSIM to be "transferred" to a new device in the same way they can with a physical SIM.
The GSMA's eSIM specification requires that eSIM profile downloads be authenticated through a Subscription Manager Data Preparation (SM-DP+) server, meaning a new eSIM profile can only be installed on a device that has been cryptographically authorised. This is a fundamentally different — and more secure — architecture than the physical SIM ecosystem.
Practical eSIM Security Benefits for Travellers
- No physical SIM to lose or have stolen. A pickpocket in a crowded market can't take your eSIM the way they can take a physical SIM card.
- Travel eSIMs are separate from your home number. When you use a travel eSIM for data abroad — for example, picking up a Thailand eSIM plan before a trip to Southeast Asia — your home number remains on your primary eSIM profile and is unaffected by anything that happens to the travel eSIM.
- Dual-SIM capability keeps your home number active. Modern iPhones and Android devices support dual eSIM, letting you keep your home number active for calls while routing data through a local travel eSIM. This means you'll still receive carrier fraud alerts on your home number even while using local data.
- Remote provisioning is authenticated. Adding or removing an eSIM profile requires authentication through the device's secure enclave — it can't be done by a carrier store employee without your device in hand.
That said, eSIM is not a silver bullet. Your carrier account can still be socially engineered to add or remove eSIM profiles if the carrier's authentication process is weak. The carrier-level PIN steps described above apply equally to eSIM accounts.
What Are the Other Account Takeover Vectors Travellers Should Know About?
SIM-swap is the most dramatic form of account takeover, but it's not the only one. Travellers face several additional threat vectors that feed into or bypass the phone-number attack entirely.
Phishing on Travel-Themed Pretexts
Attackers know that travellers are actively engaged with booking confirmations, itinerary changes, and payment receipts. A well-crafted phishing email that mimics an airline, hotel chain, or ride-share app is far more likely to succeed when you're in the middle of a trip and expecting exactly these kinds of messages.
What to do: Bookmark your airline and hotel's official apps. Never click email links to "verify your booking" — go directly to the app or website instead. Be especially cautious when you're tired or rushed (like during a connection).
Public Wi-Fi Credential Harvesting
Unsecured public Wi-Fi at airports, cafés, and hotel lobbies can be used to intercept unencrypted traffic or to serve a fake captive portal that harvests your credentials.
What to do: Use a reputable VPN on all public networks. A travel eSIM with a dedicated data plan — like a UK eSIM or a European regional plan — means you can stay on your own secure mobile data connection instead of relying on hotel Wi-Fi for sensitive tasks.
Malicious Charging Stations ("Juice Jacking")
Public USB charging ports in airports and hotels can be compromised to install malware or extract data from your phone. The FBI issued a public advisory about juice jacking as recently as 2023.
What to do: Carry your own wall charger and a USB data-blocker ("USB condom") if you must use public ports. Better yet, carry a portable battery pack.
Lost or Stolen Device
A stolen unlocked phone is an immediate account-takeover risk — the thief has access to your SMS codes, authenticator apps, and potentially saved passwords.
What to do: Enable a strong biometric lock (Face ID or fingerprint) plus a PIN. Enable remote wipe via Find My (iOS) or Find My Device (Android). Store a backup of your authenticator app's recovery codes in a secure, offline location before you travel.
What Should You Do If You Suspect a SIM-Swap Is Happening Right Now?
Speed is everything. The moment you notice your phone has lost service in a way that doesn't match your location or roaming settings, treat it as a potential SIM-swap until proven otherwise.
Immediate Response Checklist
- Try to make a call or send a text. If your number is dead but you have Wi-Fi, you can still use iMessage, WhatsApp, or Signal over Wi-Fi — use these to contact someone who can help.
- Log into your carrier account from a browser (using saved credentials or a password manager). Check whether a SIM change has been requested or processed.
- Call your carrier's fraud line — not the general customer service number. Have your account PIN ready. Ask them to immediately reverse any unauthorised SIM change.
- Lock your financial accounts. Log into your bank, investment, and cryptocurrency accounts from a trusted device (not your potentially compromised phone) and change passwords immediately. Enable a temporary freeze if available.
- Change your email password. Email is the master key to everything else. Change it from a device that doesn't rely on SMS 2FA.
- File a report. In the US, file with the FCC and the IC3 (ic3.gov). In the UK, report to Action Fraud. In Australia, report to the ACCC's Scamwatch. Documentation matters for both law enforcement and any subsequent insurance or bank dispute.
If you're abroad and dealing with a SIM registration requirement in a country like Saudi Arabia, make sure you understand the local carrier's process for reporting fraud — it varies significantly by country.
How Do You Manage Roaming Settings Safely Without Exposing Yourself?
There's an intersection between your roaming configuration and your security posture that most travellers never think about. Certain roaming settings can inadvertently reduce the friction for attackers — or leave you without fraud alerts at a critical moment.
For a deep dive on configuring your device correctly before departure, see our complete guide to eSIM roaming settings, which covers how to avoid unexpected charges while keeping security notifications active.
Key principles:
- Keep your home carrier's app installed and notifications enabled, even if you're using a travel eSIM for data. Fraud alerts from your home carrier will come through the app via Wi-Fi or your home eSIM profile.
- Don't disable SMS on your home number. Some travellers turn off their home SIM to avoid roaming charges. Instead, use a travel eSIM for data and keep your home SIM active in receive-only mode.
- Review which apps have SMS permissions. On Android in particular, some apps request SMS read access unnecessarily. Audit these before travel.
SIM-Swap Prevention: A Quick-Reference Checklist
Use this checklist before every international trip:
Before You Leave
- Add a carrier-level PIN or port-lock to your home account
- Enable "Number Lock" or equivalent at your carrier
- Switch email, banking, and social accounts from SMS 2FA to an authenticator app
- Enable passkeys on all services that support them
- Back up authenticator app recovery codes offline
- Enable remote wipe on your device
- Install and configure a VPN
- Check your email on Have I Been Pwned for recent breaches
- Set up a travel eSIM for your destination (keeps your home number separate from data usage)
During Your Trip
- Use mobile data (travel eSIM) rather than public Wi-Fi for sensitive tasks
- Don't click email links for bookings — use apps directly
- Use your own charger; avoid public USB ports
- Keep your phone locked with biometrics + PIN at all times
- Monitor your home carrier's app for unusual activity
If Something Goes Wrong
- Contact your carrier's fraud line immediately
- Change email and banking passwords from a trusted device
- File reports with the relevant national authority
- Notify your bank to freeze accounts if funds are at risk
FAQ
Can a SIM-swap happen to an eSIM?
A SIM-swap attack is significantly harder to execute against an eSIM than a physical SIM. Because eSIM profiles are cryptographically bound to your device's hardware, a criminal can't simply walk into a store and swap the profile to a new device. However, if your carrier's account authentication is weak — for example, relying only on a password and a security question — an attacker could still socially engineer a new eSIM profile download. Setting a carrier-level PIN or port-lock on your account closes this gap.
What's the difference between a SIM-swap and a port-out scam?
A SIM-swap transfers your number to a new SIM card on the same carrier. A port-out scam transfers your number to an entirely different carrier, as if you were switching providers. Both achieve the same result — the attacker gains control of your number — but they use different carrier processes. Port-out scams can be blocked by enabling "Number Lock" or a port-out PIN at your current carrier, which requires additional authentication before any number transfer is approved.
Is SMS two-factor authentication better than nothing?
Yes — SMS 2FA is still better than no 2FA at all, because it stops most opportunistic attackers who only have your password. However, it provides no protection against a targeted SIM-swap attack. For any account holding financial value or sensitive personal data, you should upgrade to an authenticator app (like Google Authenticator or Authy) or a hardware security key as soon as possible.
How long does a SIM-swap attack take?
The actual swap itself can be completed in as little as 15 minutes if the attacker has enough personal information to satisfy your carrier's identity verification. The subsequent account takeovers — email, banking, crypto — can happen within the same hour. This is why immediate detection and a fast response are critical. Monitoring your carrier's app for activity alerts and keeping your home number active (even while using a travel eSIM for data) helps you catch the attack as early as possible.
Will my bank refund money lost to a SIM-swap attack?
This depends on your country and bank. In the UK, banks are required under the Payment Services Regulations to reimburse unauthorised transactions unless they can prove you were grossly negligent. In the US, the Electronic Fund Transfer Act (EFTA) provides some protection for unauthorised electronic transfers, but coverage varies significantly for cryptocurrency losses. Filing a police report and reporting to the FCC or IC3 immediately strengthens any refund claim. Contact your bank's fraud department within hours of discovering the attack.
Should I turn off my home SIM when travelling to avoid roaming charges?
Turning off your home SIM entirely is not recommended from a security standpoint. A better approach is to use a travel eSIM for all data usage — which keeps costs low — while keeping your home SIM active in a receive-only or minimal-roaming state. This ensures you continue to receive fraud alerts, carrier notifications, and authentication calls on your home number. Most modern dual-SIM phones let you configure exactly which SIM handles data vs. calls.
What personal information do SIM-swap attackers typically use?
Attackers typically need your full name, phone number, carrier name, account PIN (if they can find it), date of birth, and the last four digits of your Social Security Number or national ID. Much of this data is available from previous data breaches, public social media profiles, or phishing attacks. Minimising your public digital footprint — especially on social media — and using unique, complex passwords for your carrier account reduces the attacker's ability to gather what they need.
Are travellers in certain regions at higher risk?
The risk of SIM-swap fraud is global, but the sophistication of carrier authentication varies by country. Regions with less stringent carrier identity verification processes can be higher-risk environments for port-out scams. Regardless of destination — whether you're heading to Australia, Japan, or anywhere in between — the same preventive steps apply: lock your home carrier account and move away from SMS 2FA before you travel.
The Bottom Line: Protect Your Number Like a Second Passport
Your phone number has become as valuable as your passport — in some ways, more so, because it's the key to your financial life. SIM-swap fraud exploits the gap between how carriers authenticate identity and how much trust we've placed in phone numbers as a verification method.
The good news is that the defences are straightforward and mostly free. Locking your carrier account, switching to an authenticator app, and using an eSIM for travel data are three steps you can complete in an afternoon. They won't just protect you on your next trip — they'll protect you year-round.
Travel should be about the experience, not about managing the fallout from identity theft. Take the 20 minutes before your next departure to work through the checklist above. Your future self — the one who doesn't have to spend three days on hold with a fraud department from a hotel in a different time zone — will thank you.






