US Carriers Offer SIM Swap Protections, But Users Must Opt In
Verizon, T-Mobile, and AT&T provide tools to block unauthorized number transfers, yet these critical security features remain disabled by default.
Mobile phone numbers have become a primary vulnerability in digital security, leaving millions of users exposed to SIM swapping attacks. While the largest US wireless carriers provide technical safeguards to prevent these hijacks, these protections are not enabled by default, requiring users to manually secure their accounts.
SIM swapping is a fraud technique where attackers transfer a victim's phone number to a SIM card under the attacker's control. Once the number is hijacked, criminals can intercept two-factor authentication (2FA) codes sent via SMS, providing a gateway to hijack personal email and financial accounts. The process often involves social engineering to trick carrier representatives or, in some instances, bribing carrier employees at companies like Verizon and T-Mobile to perform the swap.
Carrier-Specific Safeguards
To combat this threat, the three major US carriers have implemented specific locking mechanisms. Verizon offers two distinct layers of security: "SIM Protection," which prevents unauthorized changes to the SIM or device, and "Number Lock," designed specifically to block unauthorized swaps of the mobile phone number.
T-Mobile provides a similar "SIM Protection" feature, which users can activate through the profile settings within the My T-Mobile account to thwart unauthorized transfers. AT&T utilizes a "Wireless Account Lock," which serves a broader purpose by preventing unauthorized wireless number transfers as well as unauthorized billing updates and general account changes.
The SMS Security Gap
This vulnerability persists because of a systemic reliance on SMS-based two-factor authentication. When a mobile number serves as the primary verification method for banking and identity services, it becomes a single point of failure. If an attacker controls the number, they effectively control the identity associated with it.
The fact that these carrier protections are opt-in rather than default means that the vast majority of users remain vulnerable. Despite the existence of technical safeguards, the burden of security is placed on the consumer, who may be unaware that these settings exist or how to navigate carrier menus to enable them.
What to Watch
As SIM swapping becomes more sophisticated, the industry is seeing a push toward more secure 2FA methods, such as authenticator apps and hardware security keys, which do not rely on the telephony network. Users should verify their current carrier settings immediately and consider migrating away from SMS-based recovery options where possible. It remains to be seen if regulatory pressure will eventually force carriers to make account locks the default standard for all subscribers.