SIM Swapping and Phone Number Hijacking in 2026: How Your Line Gets Stolen (and How to Lock It Down)
L'équipe Texto SMS Gratuit

L'équipe Texto SMS Gratuit

10 September 2026 · 12 min read

Introduction: when the signal disappears, it's sometimes already too late

One Tuesday afternoon, in the middle of the city, your phone displays "No Service." No outage has been announced, and colleagues around you have a normal signal. You restart the device, pull out the SIM card, blow on it out of superstition. Nothing. Two hours later, arriving home, you log in to your bank: three transfers you never made.

This scenario has a name: SIM swapping, or phone number hijacking. The fraudster didn't hack your phone. They didn't crack your password. They simply convinced someone — a customer service agent, a verification algorithm, sometimes a complicit employee — that your number belonged to them. From that point on, every validation SMS your banks, your messaging apps and your online accounts send to that number lands in their hands.

Blue SIM cards in various formats and an ejection tool laid out on a white background

In France, the phenomenon was long seen as marginal. It isn't anymore. The widespread adoption of the eSIM, which allows a line to be activated remotely in a matter of minutes without shipping a plastic card, has mechanically shortened the delay between the fraudulent request and the effective takeover. What used to take two business days now takes ten minutes.

This guide explains how the attack actually works, the concrete protections to enable both with your carrier and on your accounts, and the exact procedure to follow if your line has already been hijacked.

How a SIM swap really works

The attack almost always unfolds in three stages. Understanding this sequence is the best way to spot where you can interrupt it.

Phase 1 — Gathering information

The fraudster needs a base of data to impersonate you with a carrier: first and last name, date of birth, address, phone number, sometimes the last four digits of a bank card or a customer number.

These details come from three main sources:

  • Massive data breaches. The major breaches that have hit French carriers and retailers in recent years have put files containing identities, addresses and phone numbers into circulation. The CNIL has issued formal warnings on the subject on several occasions, and the government service Cybermalveillance.gouv.fr treats it as a recurring entry point in its alerts.
  • Targeted phishing. A fake delivery SMS, a fake "your carrier account is about to be suspended" message, a fake bank advisor on the phone. The goal isn't always to steal a password: sometimes it's just to get you to confirm a date of birth or an address.
  • Social media. A birthday photo, a publicly announced move, the dog's name used as a security question. What you freely publish feeds social engineering scenarios directly.

Phase 2 — The fraudulent request

There are two routes, and they aren't countered in the same way.

Route A: SIM replacement with your own carrier. The fraudster calls customer service or goes through the online account area posing as you, and declares that they've lost their phone. They request a new SIM be sent or, much faster, the activation of an eSIM on a device they control. Your SIM card is deactivated within a second: that's the moment your phone loses signal.

Route B: fraudulent number portability. The fraudster obtains your RIO code (the 12-character number identifying your line, obtained by dialling 3179), then signs up for a plan with a competing carrier while asking to keep your number. Porting takes one to three business days, sometimes less. Your original line is then automatically terminated.

Key takeaway: in both cases, a sudden and unexplained loss of mobile signal is not a technical glitch. It's the number one symptom of line hijacking.

Phase 3 — Exploitation

Once the number is captured, the fraudster triggers "forgot password" procedures on your accounts. Email first — because it controls everything else — then bank, payment platforms, crypto accounts, social media, and sometimes the carrier account area, to lock you out of regaining control.

The validation SMS, long presented as the gold standard of two-factor authentication, becomes at that moment the main way in. That's the whole paradox of SMS-based authentication: it relies on a channel that your carrier can administratively reassign.

Why 2026 is a pivotal year

Three developments have changed the equation.

The eSIM has become the norm. Virtually every smartphone sold in France since 2023 supports it, and most carriers allow a profile to be activated online, with no human involvement and no postal shipment. Excellent news for the legitimate user who switches carriers in three minutes. Excellent news, too, for the fraudster.

The market has consolidated and is in motion. Capital movements in French telecoms, customer base migrations from one carrier to another, and the arrival of new MVNOs — including ones backed by large retail chains — are multiplying the legitimate emails announcing contract changes. Against that background noise, a fraudulent message blends in far more easily.

Procedures have been streamlined for commercial reasons. ARCEP has long pushed to smooth out number portability in order to boost competition, and that's a good thing for consumers' wallets. But the friction removed from an honest customer's journey is also removed from an impostor's.

Hand holding a smartphone and two one-dollar bills, screen showing apps

The five locks to put in place right now

None of these measures takes more than ten minutes. Taken together, they make the attack far less profitable.

Lock 1 — The carrier-side confidential code

All French carriers offer, under various names, a customer service password or secret code distinct from your online account password. It's requested during sensitive operations: SIM change, cancellation, address modification.

In practice:

  • Call your customer service or go through your subscriber area and explicitly request the activation of a security code for any SIM or eSIM replacement request.
  • Choose a code that is neither your date of birth, nor your postcode, nor the end of your phone number.
  • Write it down somewhere other than a "passwords.txt" file. A small password notebook tucked away in a drawer remains, paradoxically, a robust solution against remote hacking.

Lock 2 — The SIM card PIN, genuinely enabled

Many users have disabled their SIM's PIN code to avoid entering it at every restart. That's a mistake: if the phone is physically stolen, the SIM can be extracted and inserted into another device to receive your validation SMS messages.

Re-enable it in the settings (Settings → Cellular → SIM PIN on iOS, Security → SIM card lock on Android) and change the default code, often 0000 or 1234.

Lock 3 — Move away from SMS for critical two-factor authentication

This is the most effective measure, and the most neglected. For your sensitive accounts — primary email, bank, payment platforms, carrier account area — replace SMS validation with:

  • an authenticator app (six-digit TOTP codes refreshed every 30 seconds), independent of the mobile network;
  • or, for the most exposed accounts, a physical USB-C security key that you plug in or tap against the phone. It's currently the only method a SIM swap can't bypass, since it has no connection to your number.

ANSSI has long recommended favouring these methods over SMS wherever they're available. Many French banks still require their own mobile validation app: that's already better than SMS, provided the app is tied to the device and not solely to the number.

Lock 4 — Clean up your recovery numbers

Take an inventory of the accounts where your number appears as a "recovery method." People often discover around fifteen of them. For each one, two questions: is this number essential here? Can I replace it with a secondary email address protected by TOTP?

A little-known tip: on several services, deleting the recovery number after enabling an authenticator app also removes the SMS bypass route. Check this explicitly in the security settings, because simply having an app in place doesn't always disable the SMS option.

Lock 5 — Monitor your RIO code and carrier emails

The RIO code is obtained by dialling 3179 from your line. It's sensitive information: never share it with someone who calls you, even if they present themselves as an advisor from a competing carrier. A carrier will never ask you for your RIO in an incoming call or by SMS.

Also set up alerts on your mailbox: any message containing "portability," "new SIM," "change of account holder" or "cancellation" deserves immediate attention. These notifications are often the only signal before the line is cut off.

The warning signs to know

SignalSeverityResponse
Sudden loss of signal, with no known outageCriticalCheck immediately using another device
Unsolicited "your porting request has been registered" SMSCriticalCall the carrier from another line
Confirmation email for an eSIM order you don't recogniseCriticalDispute it without delay
A wave of login attempts on your accountsHighChange passwords, check active sessions
Call from an "advisor" asking for a code received by SMSHighHang up, never pass on a code
Inability to log in to your carrier account areaHighContact the fraud department

One point deserves particular vigilance: a loss of signal can also have mundane causes (an oxidised SIM, a local outage, a configuration bug after an update). The distinguishing test is simple: do other devices around you on the same carrier have a normal signal? If so, and the SIM works again in another phone, it's a hardware problem. If the line doesn't work anywhere, consider fraud.

You're a victim: the hour-by-hour procedure

Close-up of a smartphone screen showing app icons

In the first 30 minutes

  1. Find another channel. A friend's phone, a landline, or a Wi-Fi connection to reach customer service via the chat in your subscriber area.
  2. Call your carrier's customer service and explicitly say the words "my line has been hijacked" or "SIM swap." Request the immediate blocking of the line and of any porting request in progress.
  3. Secure your primary email before anything else: change the password, log out of all sessions, remove the number as a recovery method.
  4. Call your bank and block your cards. The interbank emergency number, 0 892 705 705, allows cards to be blocked 24/7.

Within 24 hours

  • File a complaint. You can file it at a police station or gendarmerie, and an online pre-filing option exists. Keep the receipt: everything that follows depends on it.
  • Report the banking fraud. In the case of an unauthorised transaction, Article L133-18 of the French Monetary and Financial Code requires the bank to immediately refund the debited amounts, unless it can prove gross negligence by the customer. Having been the victim of a line hijacking carried out without your knowledge works in your favour.
  • Report it on Cybermalveillance.gouv.fr, which directs you to the appropriate resources, and on Perceval (the official online service) for bank card fraud.
  • Ask the carrier for a written record of the fraudulent request: date, channel, identifying details used. This document is decisive if the bank disputes its liability.

Within the week

  • Review all accounts linked to the number: social media, e-commerce platforms, storage services, government accounts (impôts, Ameli, CAF, France Connect).
  • Check that no call forwarding or SMS forwarding has been set up on your restored line.
  • Consider registering with the Banque de France incident file if credit applications may have been attempted, and keep an eye on your post.
  • If you hold sensitive credentials, a password manager will let you renew all your logins without reusing the same combinations.

What the law and carriers must — or needn't — do

The framework remains imperfect. No French legislation spells out precisely which checks a carrier must perform before reassigning a line. The French Postal and Electronic Communications Code governs portability and its deadlines, but leaves authentication procedures to carriers' discretion.

In practice, remedies do exist:

  • A written complaint to the carrier, by registered post with acknowledgement of receipt, invoking a breach of the obligation to secure the processing of personal data (Article 32 of the GDPR).
  • Referral to the electronic communications ombudsman (médiateur des communications électroniques) if the response is unsatisfactory after two months.
  • A complaint to the CNIL if your data has been used or disclosed wrongfully.

One useful remark: always keep proof of the steps you've taken. A simple portable document scanner or an archiving app is enough to build a clean file, often decisive when dealing with a legal department.

In summary

SIM swapping is not a sophisticated technical attack. It's a procedural flaw exploited through social engineering, made faster by the dematerialisation of the SIM. The effective protections are procedural too:

  • enable a confidential carrier code for any SIM or eSIM request;
  • re-enable and personalise your SIM card PIN;
  • take SMS out of the authentication loop on critical accounts;
  • never share your RIO code or a code received by SMS;
  • react within the hour to any unexplained loss of signal.

In the space of a decade, your mobile number has become the master key to your digital identity. It deserves to be treated as such: with the same seriousness as a keyring, not as a piece of data you hand out on every form.

#Sécurité#Arnaque#eSIM#Opérateurs#SMS#Vie privée#Mobile

Related articles

Send your SMS for free

100% free service, no sign-up and no ads. Send unlimited SMS to France.

Send an SMS
bg wave