Your Phone Doesn't Block SIM Swapping Attacks by Default: Turn on Carrier Settings Now
What Happened — SIM‑swap fraud has surged, allowing attackers to hijack a victim’s phone number, intercept SMS‑based two‑factor authentication (2FA) codes, and gain access to personal and corporate accounts. Major U.S. carriers (AT&T, T‑Mobile, Verizon) now offer optional “SIM Protection” or “Number Lock” settings that are off by default.
Why It Matters for Compliance & Audit Readiness
- The scenario maps directly to SOC 2 CC6.1 (Logical Access) and CC6.2 (User Authentication) – controls designed to prevent unauthorized credential use.
- Demonstrating that you’ve enforced carrier‑level SIM safeguards provides concrete, continuous evidence of due‑diligence for audit reviewers.
- Incorporating these settings into your organization’s access‑control policy closes a common “out‑of‑band” attack vector that many compliance programs overlook.
Who Is Affected – Financial services, healthcare, SaaS providers, and any enterprise that relies on SMS‑based MFA for employee or customer authentication.
Recommended Actions
- Enable carrier‑provided SIM protection (e.g., Verizon’s “SIM Protection” and “Number Lock”, AT&T’s “Account PIN”, T‑Mobile’s “SIM Card Lock”).
- Update your access‑control policy to require carrier‑level SIM safeguards for all privileged accounts that use SMS 2FA.
- Add SIM‑swap awareness to your security‑awareness training curriculum and test it in phishing simulations.
Source: ZDNet Security
Technical Notes – Attack vector: social engineering / stolen credentials; attackers convince carriers to re‑port numbers or bribe carrier staff. No CVE; the risk is procedural. Data at risk includes MFA tokens, personal identifiers, and any downstream systems that trust SMS 2FA. Source: same article