SIM-swap defense for business owners: a founder’s playbook
A cloned phone number can drain your bank and your store admin before you notice. This is the founder’s playbook: carrier locks, non-SMS MFA, and recovery, in the order that matters.
If you run a business, the single most effective way to protect yourself from a SIM swap is to move your important accounts off SMS-based two-factor and lock your number against transfer at your carrier, before anything happens, not after. I say this from experience: RankShield exists in part because my own phone number was cloned in the same window that my business was hit with click fraud, and living through how fast a hijacked number becomes a hijacked life is what made device and identity security personal for me. A SIM swap is when an attacker convinces your carrier to move your phone number to a device they control, and because so much of your business, your bank, your email, your store admin, uses that number to verify you, taking the number can mean taking all of it. It is common enough to be a real risk: the FBI’s Internet Crime Complaint Center logged 982 SIM-swapping complaints with nearly 26 million dollars in reported losses in its 2024 report, and SIM swapping ranked among the top reported cyber threats in 2025 (FBI IC3 20241). What most SIM-swap advice leaves out is a business-owner order of operations, which accounts to harden first when your number is the key to your livelihood. That is what this playbook gives you. One honest note: no step makes you swap-proof, but this order closes the doors that matter most, fastest.
How does a SIM swap actually happen?
A SIM swap happens when an attacker persuades your mobile carrier to transfer your phone number to a SIM card or device they control, usually by impersonating you with personal details they gathered beforehand. They call or visit the carrier, claim to be you with a lost or upgraded phone, and answer the verification questions using information from data breaches, phishing, or your own public footprint. Once the carrier moves the number, your phone loses service and theirs starts receiving your calls and texts, including your two-factor codes.
The reason it works is that carriers built number transfers to be easy for legitimate customers who genuinely switch phones, and that convenience is the vulnerability. The attacker does not need to hack anything technical; they need to social-engineer a support representative, which is often easier than breaking a password. This is why the defense is partly at the carrier, locking the number so a transfer requires a step the attacker cannot fake, and partly at your accounts, so that even a hijacked number does not unlock them.
For a business owner, the danger is the concentration of trust on one number. Your bank texts a code to it, your email recovery runs through it, your payment processor and store admin verify with it, so the number is a master key you did not realize you minted. That concentration is exactly what makes a swap so damaging and why hardening has to be deliberate. The FBI logged 982 SIM-swap complaints and nearly 26 million dollars in losses in 2024 (FBI IC3 20241), and behind many of those numbers is a person who did not know their phone number had become their weakest link.
What accounts does a SIM swap target first?
A SIM swap targets your email and your money first, because email is the recovery path to everything else and money is the payoff. The attacker uses your hijacked number to reset your email password, since email accounts often allow SMS-based recovery, and once they control your email they can reset almost every other account that emails a reset link. From there they go for the accounts that hold or move money: your bank, your payment processor, your business accounts, and any wallet or exchange, draining what they can before you regain control.
For a business owner, the target list is longer and more valuable than for an individual, which is why the order of hardening matters. Beyond personal email and banking, an attacker who takes your number can reach your business email, your Shopify or store admin, your ad accounts, and your payment gateways, each of which can be used to steal money, place fraudulent orders, or run up spend. The same week my number was cloned, my business was being hit with click fraud, and the lesson that stuck was that attacks on the person and the business are not separate problems; the phone number connects them.
This is why the playbook is ordered by value, not convenience. Harden the accounts that hold money and grant access first, email, banking, payment processing, store admin, before the low-stakes ones, because those are what an attacker reaches for in the first minutes. Protecting the person behind the business is inseparable from protecting the business, which is exactly the principle RankShield’s device protection is built around: the founder’s device and identity are part of the business’s attack surface.
How do you lock your number at the carrier?
Lock your number by enabling your carrier’s port-out protection, a transfer PIN or number-lock feature that requires a code or an explicit setting change before your number can be moved to another carrier or SIM. Every major US carrier offers some version of this, and it is the single control that directly addresses the swap itself rather than its consequences. Set a PIN that is not derived from anything an attacker could look up, and confirm the lock is active rather than assuming it is on by default, because it usually is not.
Add the carrier account itself to your defenses, not just the number. Put a strong, unique password on your carrier online account, enable non-SMS two-factor on it if the carrier supports it, and ask whether they offer additional protections like a required in-person verification or a note on the account for high-risk customers. The goal is to make an unauthorized transfer require something the attacker cannot obtain by charming a support representative, which is the exact weakness a swap exploits.
Treat the carrier lock as necessary but not sufficient, because determined attackers sometimes defeat carrier controls through insider help or persistence. That is why the lock is step one and the account hardening in the next sections is steps two and three: even if a swap succeeds, accounts protected by app-based or hardware two-factor do not fall just because the number moved. Layering the carrier lock with non-SMS authentication is what turns a catastrophic swap into a contained inconvenience.
What should you use instead of SMS two-factor?
Replace SMS two-factor with an authenticator app or, better, a hardware security key on every account that offers the option, because those methods do not travel with your phone number. An authenticator app generates codes on your device itself, so moving your number to an attacker’s SIM does not move your codes. A hardware security key is stronger still: it is a physical device that must be present to log in, which defeats both SIM swaps and most phishing, and it is the gold standard for your highest-value accounts.
Prioritize the switch by account value, matching the order-of-operations principle. Move your email, banking, payment processing, and store admin off SMS first, since those are what an attacker targets first, then work through the rest. Where an account only offers SMS, see whether you can add an authenticator app as the primary method and remove SMS as a fallback, because leaving SMS as a backup recovery option quietly reopens the door you just closed. The weakest enabled method is the one that defines your real security.
Keep backup codes for the accounts you harden, stored offline, so that removing SMS does not lock you out if you lose your device. The point is not to make your accounts fragile but to make them independent of your phone number, so a swap that once would have handed an attacker everything now hands them a dead number and nothing else. That independence is the core of SIM-swap defense: the number stops being a master key the moment your important accounts no longer trust it alone.
What do you do if your number is already swapped?
If your number is suddenly dead, no service, no calls or texts, when it should work, act immediately in a fixed order: contact your carrier from another phone to report the swap and reclaim the number, then secure your email, then your money. Speed matters because the attacker is racing to reset accounts while they hold the number, so the first minutes decide how much damage they do. Do not wait to see if service comes back on its own; a sudden loss of service with no explanation is the signature of a swap in progress.
Work the sequence deliberately. Call your carrier and tell them your number has been ported without authorization and you need it locked and returned. In parallel, from a secure device, change your email password and revoke active sessions, because email is the attacker’s path to everything else. Then check and secure your bank and payment accounts, watching for and reversing unauthorized transactions, and alert your bank’s fraud line that you have been SIM-swapped so they scrutinize activity. Finally, secure your business accounts, store admin, ad accounts, and processors, since those can be used to steal money or run fraud even after you regain the number.
Document everything as you go, because you will likely need it. Note the time you lost service, the transactions and password changes you did not make, and every account touched, and report the crime to the FBI’s Internet Crime Complaint Center, which tracked these cases and is where losses get recorded (FBI IC3 20252). That record supports fraud claims with your bank and processors and helps any investigation, and it is far easier to compile in the moment than to reconstruct later.
How do you build lasting device and identity resilience?
Build lasting resilience by treating your phone number as untrusted infrastructure and your identity as something that must be independently verifiable, not just something a text message confirms. The durable lesson from a SIM swap is that any security that depends on possessing a phone number is only as strong as your carrier’s support desk, so the goal is to remove the number from your critical trust decisions entirely. Once your important accounts authenticate with keys and apps rather than texts, a swap becomes an inconvenience instead of a catastrophe.
Extend the same principle to your business. The founder’s device and identity are part of the company’s attack surface, so protecting the person is protecting the business, and the two should be secured together rather than as separate concerns. Keep your carrier lock active, review your two-factor methods periodically to catch any SMS fallback that crept back in, and make sure recovery paths for critical business accounts do not route through your phone number. Resilience is not a one-time setup; it is a posture you maintain as accounts and apps change their defaults.
This is exactly why I ended up building in this space: living through a cloned number while my business was under a separate attack made it clear that device integrity and business security are one problem, not two. If you want continuous protection for the device and identity that sit at the center of your business, so a compromise is caught and contained rather than discovered after the damage, see how RankShield protects the person behind the business. The number stops being your weakest link the day you stop letting it be your master key.
How do you make your number stop being your weakest link?
A SIM swap turns your phone number into a master key an attacker can copy, and for a business owner that key opens the email, the bank, and the store admin all at once. The defense is an order of operations you can do this week: lock your number against transfer at your carrier, then move your highest-value accounts, email, banking, payment processing, and store admin, off SMS two-factor and onto an authenticator app or a hardware key. Keep offline backup codes so you are not locked out, and remove SMS as a fallback where you can, because the weakest enabled method is the one that defines your security.
I built in this space because I lived the other version of this story, a cloned number and a business under attack in the same week, and the lesson was that your device and your business are one attack surface. Harden the person and you harden the company. If your number goes dead, act in the fixed sequence, carrier first, then email, then money, and report it to the FBI’s IC3. And if you want continuous protection for the device and identity at the center of your business, see how RankShield protects the person behind the business, so a compromise is contained, not discovered too late.
Questions, answered.
How do I protect my business from a SIM swap?
Do two things before anything happens: lock your phone number against transfer at your carrier with a port-out PIN or number-lock feature, and move your most important accounts off SMS-based two-factor onto an authenticator app or a hardware security key. For a business owner, the order matters because a SIM swap targets your email and money first, so harden email, banking, payment processing, and store admin before lower-stakes accounts. Add a strong password and non-SMS two-factor to your carrier account itself, keep offline backup codes so removing SMS does not lock you out, and remove SMS as a fallback recovery method where you can. The goal is to make your phone number stop being a master key, so that even a successful swap hands an attacker a dead number rather than your business.
How does a SIM swap attack actually happen?
An attacker convinces your mobile carrier to transfer your phone number to a SIM card or device they control, usually by impersonating you using personal details gathered from data breaches, phishing, or your public footprint. They contact the carrier claiming to be you with a lost or upgraded phone and answer the verification questions, and once the carrier moves the number, your phone loses service while theirs starts receiving your calls and texts, including two-factor codes. It works because carriers designed number transfers to be easy for legitimate customers, so the attacker does not need to hack anything technical; they social-engineer a support representative. That is why defense is partly at the carrier, locking the number, and partly at your accounts, so a hijacked number cannot unlock them.
What carrier locks stop a SIM swap?
Every major US carrier offers a port-out protection feature, sometimes called a transfer PIN, number lock, or SIM-protection setting, that requires a code or an explicit change before your number can be moved to another SIM or carrier. Enable it, set a PIN that is not derived from anything an attacker could look up, and confirm the lock is actually active rather than assuming it is on by default, because it usually is not. Also secure the carrier account itself with a strong unique password and non-SMS two-factor, and ask whether the carrier offers extra protections like required in-person verification. Treat the lock as necessary but not sufficient, since determined attackers sometimes defeat carrier controls, which is why you also move your important accounts off SMS so a swap that succeeds still does not unlock them.
What should I use instead of SMS two-factor?
Use an authenticator app or, for your highest-value accounts, a hardware security key, because neither travels with your phone number. An authenticator app generates codes on your device itself, so moving your number to an attacker’s SIM does not move your codes, and a hardware key is a physical device that must be present to log in, which defeats both SIM swaps and most phishing. Prioritize the switch by account value: move email, banking, payment processing, and store admin off SMS first, then work through the rest. Where an account keeps SMS as a backup recovery option, remove it if you can, because the weakest enabled method defines your real security. Keep offline backup codes so losing your device does not lock you out of a hardened account.
What do I do if my number was already swapped?
Act immediately in a fixed order. If your phone suddenly loses service when it should work, that is the signature of a swap, so from another phone contact your carrier, report that your number was ported without authorization, and have them lock and return it. In parallel, from a secure device, change your email password and revoke active sessions, since email is the attacker’s path to your other accounts. Then secure your bank and payment accounts, watch for and reverse unauthorized transactions, and alert their fraud lines that you were SIM-swapped. Finally secure your business accounts, store admin, ad accounts, and processors. Document the timeline and everything touched, and report it to the FBI’s Internet Crime Complaint Center, which supports fraud claims and any investigation. Speed matters because the attacker is racing to reset accounts while they hold the number.
How common are SIM swaps for business owners?
Common enough to be a real risk rather than a rare edge case. The FBI’s Internet Crime Complaint Center logged 982 SIM-swapping complaints with nearly 26 million dollars in reported losses in its 2024 report, an average of roughly 26,000 dollars per victim, and SIM swapping ranked among the top reported cyber threats in 2025. Reported figures also understate the problem, because many victims do not report or attribute the loss to a SIM swap specifically. Business owners are attractive targets because their phone number often unlocks not just personal email and banking but business email, store admin, ad accounts, and payment processors, so a single swap can reach far more value than for an individual. That concentration of access is exactly why the hardening order in this playbook, money and access accounts first, matters for anyone running a business.
References
Jamie Kloncz
Founder & CEO, RankShield
Jamie Kloncz is the founder and CEO of RankShield, the verifiable AI and quantum security platform. He started the company after two attacks landed in a single week: his phone was cloned, and his business was hit by a click-fraud campaign. One targeted him as a person, the other his livelihood, and no single tool defended both. That experience, together with surviving an AI voice-clone scam, shaped RankShield’s core belief: the threats of the AI age are personal first, and trust should be something you can check, not just extend.
Make every AI action provable.
RankShield is the verifiable, quantum-safe AI security platform — protection you can check, not just trust.