Two quite different attacks get discussed as if they were one thing. One of them is a paperwork problem at your carrier, and it can be hardened. The other lives in the network between carriers, and no SIM you can buy will touch it. Knowing which is which decides what is worth paying for.
The attack people usually mean
SIM jacking, or SIM swapping, does not involve your phone at all. An attacker persuades your carrier to move your phone number onto a SIM they control. Your handset quietly drops to no service, and from that moment every call and text intended for you arrives on theirs. Then they start working through password resets, because your number is the recovery factor for almost everything you own.
They get there two ways. The first is social engineering, and the fuel for it is bought rather than hacked — your date of birth, previous addresses and relatives are all purchasable from data brokers, which is exactly the problem we covered in the Cloaked write-up. The second is simpler and better documented than most people expect: a retail or call-center employee is paid to make the change. No amount of customer-side caution fixes an insider.
Port-out fraud is the same attack with a different destination. Rather than moving your number to a new SIM on the same carrier, the number is ported away to a different carrier entirely, which is often harder to unwind because your original provider no longer has the account.
What the numbers actually say
This is where most vendor writing on the subject stops being useful, so here are the figures.
The FBI's Internet Crime Complaint Center logged 2,026 SIM swap complaints and roughly $72.7 million in reported losses in 2022. In 2023 that fell to 1,075 complaints and $48.8 million. In 2024 it fell again, to 982 complaints and $26.0 million.
That is a real, sustained decline, and there is a plausible reason for it. In November 2023 the FCC adopted rules on SIM swap and port-out fraud, with compliance required from July 8, 2024. Carriers must authenticate a requester before moving a number, handle failed authentication attempts, notify the customer of any SIM change or port-out request, train staff, keep records, and — the part worth acting on today — offer customers an account lock. Those rules apply to resellers as well as to the big networks.
So the honest shape of the risk is a shrinking and highly targeted one, not a growing indiscriminate one. But averages hide the thing that matters here. The average reported loss in 2024 works out to roughly $26,500, and that number is an average of a distribution with a very long tail. Nobody gets SIM swapped at random. You get selected, usually because something recoverable by SMS is worth taking, and if your number is the recovery factor on a crypto position or an account with wire authority, you are not the average.
The other thing entirely: SS7
Signaling System 7 is the family of protocols carriers use to talk to each other — to set up calls, route texts, and hand your phone between networks as you roam. It was designed in the 1970s for a small club of state-owned monopolies who had no particular reason to distrust one another, and it shows. There is essentially no authentication of who is asking.
Someone with signaling access can ask the network where a subscriber is and get a location back, redirect calls, or intercept SMS messages, including one-time passcodes. This is neither theoretical nor purely historical. Criminals drained German bank accounts back in 2017 by using signaling access to intercept the one-time codes, and in April 2026 the Citizen Lab published an analysis of two surveillance campaigns that, for the first time, tied real-world attack traffic to mobile operator signaling infrastructure, with activity traced from late 2022 into 2025. Diameter, the 4G successor, inherited a good deal of the same trust model, and while 5G standalone improves matters, roaming and interworking keep the old paths alive at the edges.
Carriers do deploy signaling firewalls, and a well-configured one filters most external attempts. Coverage is uneven, the rule sets are complicated, and misconfiguration leaves gaps.
Here is the part that matters for a purchasing decision. SS7 is a problem in the network between carriers, not in your account. No PIN, no cooling-off period, no verification protocol and no particular SIM changes whether a signaling request from a distant network gets honored. It is worth saying plainly because a good deal of marketing in this category lets the two blur together.
Secure providers, and a spotlight on Efani
A small category of mobile providers now sells hardened account security as the product rather than as a feature. They are resellers on the major networks, they charge a large multiple of an ordinary plan, and what you are buying is a deliberately slow, human, suspicious process wrapped around your number. Efani is the best-known, and Cape is a newer entrant with a similar pitch. We are using Efani here as the worked example, because its published detail is the most specific, and because the way it draws its own boundaries is instructive for judging any provider in the category.
Efani runs $99 a month, or $999 a year, with unlimited calls, texts and data in the US, Canada and Mexico, and a $5 million insurance policy that applies from day one. It puts you on your choice of two of the major US networks — it excludes T-Mobile and does not name the other two on its public pages.
What it genuinely does is make the paperwork attack very hard. Efani says its process imposes a multi-week cooling-off period on port-outs and SIM changes, requires manual review by more than one staff member, asks for notarized statements, and blocks SIM swap requests by default rather than treating them as routine. Those are the company's own descriptions of its internal process, which no customer can independently audit — but they describe a categorically different posture from a four-digit PIN and a retail employee under pressure to be helpful. Against the attack described at the top of this article, it is a serious control.
Two caveats, in fairness rather than as a knock.
The marketing says eleven layers. Their own page describes roughly five concrete controls, and the rest is not enumerated. The controls that are described are real and meaningful, but the number is a number.
And Efani makes no SS7 claim. We checked the homepage, the how-it-works page and the business page, and none of them mention signaling. That is to their credit, and it is the single most useful thing about them for the purposes of this article, because it tells you where the honest boundary of the category sits. You are buying a much better account-security process on the same underlying networks as everyone else, which is precisely what a reseller can deliver and precisely what it cannot. If you find a provider in this category that does claim signaling-layer immunity, that claim is the thing to interrogate.
On the insurance: $5 million is real, and it is recovery rather than prevention. Efani does not publish its underwriter or the specific payout triggers, so read the policy before you count it as a control.
Do these first, because they are free
Anyone selling you mobile security should tell you this part, and most do not.
- Turn on the account locks with your current carrier. Plural, because there are two: one that blocks SIM changes and one that blocks port-outs. The FCC order requires every provider, resellers included, to offer them to all customers at no cost, and it encourages carriers to let you switch both on in a single step. Verizon calls its version Number Lock; T-Mobile calls it Account Takeover Protection. This takes a few minutes, costs nothing, and is the single largest reduction in risk available to you.
- Get your number out of your authentication wherever you are allowed to. Move to an authenticator app, a passkey, or a hardware key. This is the only item on this list that defeats SS7 as well as SIM swapping, because it removes the SMS from the equation entirely rather than trying to protect it.
- Stop handing out the real number. A masked number for vendors and forms keeps your actual line out of the broker files that make social engineering work.
- Separate your recovery factor. The number that protects your bank and any crypto holdings should not be the number printed on your business cards.
The bottom line
If you are an executive with wire authority, hold material crypto, or your phone number is the recovery path for accounts worth many multiples of the premium, then roughly $1,200 a year for a carrier whose entire operating process is designed to refuse a swap is defensible, and the insurance is a reasonable backstop behind it.
For most staff, most of the time, the free account lock plus removing SMS from your authentication gets you the large majority of the benefit for none of the money. That is not a reason to dismiss the product. It is a reason to do the free things first and then decide whether the remaining exposure justifies the subscription.
And nobody should buy any of these, or anything else sold as a SIM, expecting protection at the signaling layer. That problem is being worked on several levels above your account, and the only defense available to you personally is to stop trusting SMS with anything that matters.
If you want help working out which of your accounts still fall back to a text message, or how to set this up across a team, call 281-407-1619 or contact us. It is the kind of thing that belongs in a broader security posture review rather than a one-off purchase.
Sources
- How Efani's SIM swap protection works
- Efani plans and pricing
- 2024 Internet Crime Report — FBI Internet Crime Complaint Center
- Criminals increasing SIM swap schemes, public service announcement — FBI IC3
- Protecting Consumers from SIM Swap and Port-Out Fraud, Report and Order FCC 23-95 — FCC
- Effective compliance date for the SIM swapping rules — FCC
- Real-world SS7 attack: criminals drain German bank accounts, 2017 — The Hacker News
- Uncovering global telecom exploitation by covert surveillance actors — The Citizen Lab