Your phone shows "No Service" at lunch. Annoying, but the coffee shop Wi-Fi works, so you keep answering email and get back to work. By dinner, someone across the country has used your phone number to reset your email password, approve a wire from your business checking account, and lock you out of the payroll portal. Nothing was hacked in the Hollywood sense — no malware, no breached password. Your mobile carrier handed your number to a stranger who asked nicely, and every text-message security code your bank sent went straight to them.
This is SIM swapping, and it is one of the highest-loss frauds aimed at small business owners precisely because it bypasses the security most owners trust. The FBI's Internet Crime Complaint Center logged 982 SIM-swap complaints with nearly $26 million in reported losses in 2024 — an average of more than $26,000 per victim — after a $72.6 million peak in 2022. Reported numbers understate the damage, because much of the theft gets classified under other fraud categories and many victims never report at all.
The good news: this attack has a short list of known countermeasures, most of them free and most of them taking under ten minutes. This guide walks through how the scam works, why business accounts are especially exposed, and the four locks that shut it down: carrier-level port protection, moving off SMS-based verification, callback verification for wires, and alerts that catch a takeover in progress.
How a SIM Swap Works in Four Steps
Understanding the mechanics matters because every defense below maps to one of these steps.
Step 1: The attacker collects your personal details. Fraudsters harvest the answers to carrier security questions — date of birth, address, account details — from data breaches, your social media profiles, phishing messages, and information brokers. Business owners leak more than most: your name, business address, and phone number sit on your website, your invoices, and state business-entity filings.
Step 2: The attacker impersonates you to your carrier. Armed with those details, the criminal calls your mobile carrier (or visits a store, or bribes an insider) and claims to be you, asking to move your number to a new SIM card they control. A close cousin called port-out fraud moves your number to a different carrier entirely. Either way, the result is identical: your number now rings on the attacker's phone.
Step 3: The attacker resets your passwords. With your number receiving your texts, the criminal triggers "forgot password" flows on your email, bank, payroll, and payment accounts. The one-time codes arrive on the attacker's device. Email usually falls first, and email is the skeleton key — most account-recovery flows run through it.
Step 4: The money moves. Business email, banking, and payment apps in hand, the attacker wires funds, adds new payees, changes payroll direct-deposit routing, or buys cryptocurrency. Business accounts are the prize: higher balances, higher wire limits, and — critically — weaker legal protections than consumer accounts.
The whole sequence can run in hours. Victims often notice only the first symptom: their own phone going dark.
Why Business Owners Are Prime Targets
Three facts combine to make a small business owner the ideal SIM-swap victim.
Your number is public and your balances are high. A fraudster choosing between an anonymous consumer and a business owner whose cell number is on the company contact page, whose revenue can be estimated from public filings, and whose operating account holds payroll money will pick the business owner every time.
Business bank accounts have weaker fraud protections. Consumer accounts fall under Regulation E, which caps your liability for unauthorized electronic transfers and forces the bank to investigate. Business accounts generally do not — commercial wire and ACH disputes fall under state commercial law (UCC Article 4A) and whatever your account agreement says, which usually means the bank is liable only if its security procedures were not "commercially reasonable." In practice, recovering a fraudulent business wire is far harder than reversing a consumer Zelle scam. The money that leaves is usually gone.
One number guards many doors. Think about everything tied to your cell number: business banking login codes, email recovery, payroll provider access, payment processors, and often the authenticator backup itself. A SIM swap does not pick one lock — it copies the master key.
Recognize the Warning Signs
The American Bankers Association lists four red flags that should trigger immediate action:
- Sudden loss of cell service. You cannot make calls or send texts, especially in a location where coverage is normally fine. This is the hallmark symptom — your number is already ringing elsewhere.
- Apps on your phone stop working for account access, while everything else seems normal.
- Security alerts about settings changes you did not authorize — password resets, new-device logins, or recovery-email changes.
- Unusual login activity on email, financial, or phone-carrier accounts.
If the first symptom appears, do not wait to see whether service comes back. Treat it as an active attack until proven otherwise and work the response checklist near the end of this article.
Lock 1: Harden Your Carrier Account
Your carrier is the front door of this attack, and all three major US carriers now offer free locks specifically built for it. The FCC's rules effective July 2024 require carriers to authenticate customers securely before SIM changes or ports and to notify you immediately when such a request is made — but the optional account-level locks go further by refusing the transfer in the first place.
Verizon: Number Lock plus SIM Protection. Number Lock blocks your number from being ported to another carrier until you turn the lock off. A separate SIM Protection toggle guards against SIM changes on your existing line. Enable both in the My Verizon app under account security — one without the other leaves a gap.
T-Mobile: Account Takeover Protection plus SIM Protection. Account Takeover Protection blocks unauthorized transfers of your lines, with separate Port Out Protection and SIM Protection settings alongside it. Manage them in the T-Life app under your account. T-Mobile's SIM Protection generally requires in-store ID verification to bypass, which is exactly the friction you want against a phone-based impersonator.
AT&T: Wireless Account Lock. AT&T folds both jobs into a single Wireless Account Lock that blocks number transfers and SIM changes, managed in the myAT&T app. Also set the separate account passcode AT&T requires before making account changes by phone.
Three carrier rules that apply everywhere:
- Set a carrier PIN or passcode that is not your birthday, address, or the last four of your Social Security number. Attackers arrive knowing all of those. This code is different from your phone's unlock code — it is the password your carrier demands before touching your account.
- Generate a number-transfer PIN only when you are actually switching carriers. The transfer PIN is a single-use credential, not a standing defense. The standing defense is the account lock.
- Ask about an in-person-only note. Several carriers let you flag the account to require store-visit verification with photo ID for SIM or port changes. Phone support is where impersonation happens; routing changes through a human who checks ID removes the attacker's channel.
If your business lines sit on a carrier account managed by someone else — an office manager, an IT contractor — confirm these locks are enabled there too. The number that receives your bank's verification texts is the one to protect, whoever pays the bill.
Lock 2: Move Off SMS Verification
Text-message codes are the single point of failure SIM swapping exploits. Take your phone number out of the authentication path and the attack loses its payoff even if it succeeds.
Use an authenticator app everywhere it is offered. Apps such as Google Authenticator, Authy, Microsoft Authenticator, or 1Password generate codes on your device that never travel over the cellular network. The FTC's guidance is explicit: if you are concerned about SIM swapping, use an authentication app or a security key, because text-message verification will not stop a SIM swap. Enable app-based verification on email first — it is the recovery path for everything else — then banking, payroll, payment processors, and your carrier account itself.
Upgrade to a hardware security key for the crown jewels. The FBI recommends physical security keys as the strongest option: a USB or NFC key that must be physically present to log in. A key cannot be phished, forwarded, or SIM-swapped. At minimum, put one on your primary business email and your bank login.
Handle the banks that only offer SMS. Some smaller banks and older business-banking platforms still verify by text alone. For those accounts, the carrier locks from the previous section are your only technical defense — which is all the more reason to enable them — plus the transaction alerts covered below. When choosing a bank or payroll provider, ask whether they support authenticator apps or hardware keys, and weigh a "no" as a real security gap.
Back up your authenticator properly. Moving off SMS creates a new risk: losing the device that holds your codes. Most authenticator apps offer encrypted cloud backup or multi-device sync — turn it on. Store printed recovery codes for critical accounts somewhere a burglar cannot find but your successor can, such as a safe-deposit box.
Lock 3: Verify Every Wire With a Callback
SIM-swap attackers love wires because wires are fast, hard to reverse, and — for business accounts — weakly protected. Even if your own number is never swapped, your vendors' and clients' numbers can be, which is how a convincingly worded "we changed banks, please wire here" message arrives from a familiar address. One procedural control defeats nearly all of it.
Call back on a known number before every first-time or changed-destination payment. When anyone — vendor, client, partner, even your own employee — asks you to send money to new account details, stop and call them at a phone number you already had on file, not one printed in the message. Confirm the routing and account numbers verbally. This single habit, applied without exceptions, neutralizes both SIM-swap-driven payment fraud and ordinary business-email compromise.
Make the habit structural rather than heroic:
- Require dual approval for wires and new payees. Most business-banking platforms support dual control: one person enters the payment, a second approves it. A lone attacker with your credentials cannot complete the theft.
- Set daily wire and ACH limits that match your real needs. A $250,000 daily wire limit on an account that wires $8,000 a month is not convenience — it is an attacker's budget. Lower the ceiling to slightly above your largest legitimate payment.
- Separate duties on payroll changes. Direct-deposit redirections are a favorite SIM-swap monetization. Require any bank-detail change to be confirmed verbally with the employee, and have someone other than the requester enter it.
Document the callback rule in writing and tell your vendors you follow it. When a scammer pressuring "urgent, wire today" meets an employee whose written procedure says "we always call back," the procedure wins.
Lock 4: Set Alerts That Catch a Takeover Early
If the first three locks fail, speed is everything. Fraud caught in minutes can sometimes be reversed; fraud found at month-end reconciliation is gone. Build a tripwire layer:
- Bank transaction alerts on every business account. Enable push or email alerts for wires, new payees, password changes, new-device logins, and any transaction above a threshold you set low — even $1 for wires. Route these alerts to an email address protected by app-based verification, not SMS.
- Email login alerts. Your email provider can notify you of sign-ins from new devices or locations. Since email is the skeleton key, treat an unfamiliar-login alert as a five-alarm fire.
- Carrier account alerts. Install your carrier's app and enable security notifications so SIM-change or port-out notices reach you through a channel the attacker does not control.
- Credit freeze, not just monitoring. A SIM swap often precedes new-account fraud in your name. Freezing your credit with all three bureaus costs nothing, takes minutes, and does more than any paid monitoring service. Business owners should also consider freezing their business credit profiles where the bureau allows it.
- Daily balance review. A two-minute morning glance at operating-account activity catches what automated alerts miss. Reconcile weekly at minimum — fraud discovered during reconciliation is late, but it still beats discovery by overdraft notice.
If It Happens: The First-Hour Checklist
If your phone goes dark unexpectedly or you receive alerts about changes you did not make, work this list in order, from a device and connection the attacker does not control:
- Call your carrier immediately — from another phone — and report a suspected SIM swap. Ask them to freeze the line, reverse the swap, and restore your number to your SIM.
- Log into email first from a trusted device and change the password, then review recovery addresses, forwarding rules, and active sessions. Attackers add hidden forwarding to keep reading your mail after you recover.
- Change banking, payroll, and payment passwords, and review every transaction, payee, and scheduled payment since the swap began.
- Call your bank's fraud department — not the branch — and report suspected unauthorized access. Ask about reversing recent wires; speed matters enormously.
- Place a fraud alert with Equifax, Experian, and TransUnion, and freeze your credit if you have not already.
- File reports with the FTC at IdentityTheft.gov and the FBI's Internet Crime Complaint Center at ic3.gov. Bring the report numbers to your bank and carrier — they accelerate disputes.
- Document everything with timestamps in a single log: when service dropped, what you found, whom you called. If recovery becomes a legal fight, this log is evidence.
Then schedule the post-mortem within a week: which lock was missing, and what changes before the next attempt? Attackers share lists of soft targets. A business that was easy once will be tried again.
Keep Your Financial Records Ready for the Worst Day
Fraud response runs on records. When the bank's dispute team asks which transfers were unauthorized, when the insurer asks for proof of loss, and when your accountant needs to book the theft correctly at year end, scattered logins and approximate memories cost you real money. Clean books — every account reconciled on schedule, every payee change logged, every wire matched to an invoice — turn a chaotic week into a documented claim.
As you tighten security around your accounts, maintaining clear financial records is what lets you prove what happened and recover faster. Beancount.io provides plain-text accounting that gives you complete transparency and control over your financial data — no black boxes, no vendor lock-in. Get started for free and see why developers and finance professionals are switching to plain-text accounting.





