
A mobile number is not a credential you control. It is a service another company administers, transferable by a person in a shop or a call centre who has been given a convincing story. Where that number receives your one-time codes or acts as a recovery route, the security of your account depends on a mobile operator’s process, and Ofcom has pressed the industry to tighten those processes precisely because the fraud keeps happening.
How the swap happens
The attacker gathers enough personal detail to pass a verification check, then requests a port to a new provider or a replacement SIM. Details come from social media, breach data and sometimes a phishing call to the victim in advance. Once the number moves, calls and messages arrive on the attacker’s device and the victim’s phone loses service, which is usually the first sign anything is wrong. From there the attacker requests password resets on the accounts that use the number, and each success gives them more. Email is usually first, because it unlocks everything else.
Why business accounts are affected
People reuse the same personal number for work services, and administrators often register a mobile as a fallback method when setting up multi-factor authentication. That fallback undoes the stronger method, because an attacker will always choose the weakest option offered at sign-in. Finance staff and system administrators are the obvious targets, and the attacker rarely needs your corporate systems to be badly configured, only to accept a code sent to a number they now control.
“Look at the registered authentication methods for your privileged accounts rather than the policy that governs them. In most tenants a handful of administrators still have a phone number listed as a backup from the day the account was created. Remove it, replace it with a second hardware key, and the attack path closes entirely.”
William Fieldhouse, Director, Aardwolf Security Ltd

What to change first
Remove SMS as an available method for privileged accounts and replace it with an authenticator application or, better, a hardware key or passkey. Check the account recovery options as well, since removing SMS from sign-in while leaving it as a reset route achieves very little. Alert on changes to authentication methods, because adding a phone number to an account is a common persistence step after a compromise. For personal protection, staff can ask their mobile provider to add a port-out authorisation code, which is free and takes one phone call.
Where testing helps
The technical half of this is configuration you can verify. Microsoft 365 penetration testing checks which authentication methods are genuinely enforced, whether a weaker method can be selected at sign-in, and whether recovery flows bypass your policy. The human half belongs in social engineering exercises, which are worth running against your own service desk, since the same story that persuades a mobile operator often works on an internal helpdesk. Penetration testing specialists in the UK will usually offer both as part of a wider identity assessment.
Frequently asked questions about SIM swap
These questions come up whenever multi-factor authentication methods are reviewed.
Is SMS worse than no second factor?
No. It stops password reuse attacks and bulk credential stuffing, which is most of what your ordinary users face. It is simply the weakest of the available methods, so keep it for low risk accounts and remove it where the account matters.
How would you know a swap had happened?
The victim’s phone loses signal without explanation, which staff should be told to report immediately rather than assuming a network fault. On your side, alerts on authentication method changes and unusual sign-ins provide the technical signal.
