TL;DR:

  • SIM swapping moves your mobile number to a SIM card the attacker controls, giving them access to any accounts protected by SMS verification codes
  • UK small businesses are targeted because their mobile numbers are often tied to banking, payment platforms, and domain registrars that fall back to SMS 2FA
  • The attack typically starts with social engineering your mobile network operator’s customer service team — or bribing/phishing an insider
  • The defences are: switch from SMS 2FA to authenticator apps or hardware keys, set a SIM lock/port freeze with your network, and separate your business-critical phone number from your personal one

Your business bank account has two-factor authentication turned on. You feel reasonably secure. What you might not have considered is that if that second factor is an SMS code sent to your mobile number, the security is only as strong as the process your mobile network uses to verify your identity before issuing a replacement SIM.

SIM swapping exploits that process. It’s not a software vulnerability — it’s a social engineering attack against the humans at your phone company’s customer service team, or occasionally an insider threat within the network itself.

How a SIM Swap Attack Works

The core mechanics are straightforward:

  1. The attacker researches you. Your name, phone number, email address, and sometimes your date of birth are often publicly accessible or easily obtained through data broker sites, LinkedIn, or prior data breaches.

  2. The attacker contacts your mobile network — by phone, chat, or in-store — posing as you. They claim they’ve lost or damaged their phone and need the number transferred to a new SIM card they’ve already obtained.

  3. Customer verification varies wildly. Some networks require account PINs or memorable passwords. Others rely on date of birth, the last four digits of a card on the account, or a recent call to verify identity. With enough personal information, an attacker can pass these checks — or find a customer service agent who’s willing to override them after a persuasive story.

  4. Once the swap completes, any SMS sent to your number arrives on the attacker’s SIM, not yours. Your phone shows “no service” or “SIM not registered.” The attacker immediately requests password resets on every account tied to that number, intercepts the SMS codes, and gains access.

The entire process from successful swap to account compromise can take under 20 minutes.

Why Small Businesses Are Particularly Exposed

For individuals, the most common SIM swap targets are cryptocurrency exchange accounts and social media. For small businesses, the exposure is broader:

Business banking: Most UK high street banks (Lloyds, Barclays, NatWest, HSBC) offer SMS codes as a 2FA option for business accounts. Many small businesses use this because it’s the default and requires no additional app.

Payment platforms: Stripe, PayPal, SumUp, and similar platforms use SMS verification for account changes, payouts, and banking detail updates. An attacker with access to your Stripe account can redirect payouts.

Domain registrar accounts: Your business domain’s registrar likely has SMS recovery as an option. Losing control of your domain — even temporarily — can be catastrophic: email goes down, your website can be pointed elsewhere, SSL certificates can be manipulated.

Google Workspace and Microsoft 365: Both fall back to SMS for account recovery if other MFA methods aren’t set. A compromised Microsoft 365 account is a foothold into your entire business — email, SharePoint, Teams, and any SaaS tools connected via SSO.

HMRC online services and Companies House: Government platforms used for tax filing, payroll, and company management increasingly use mobile numbers for verification. Compromised access here could be used for fraudulent filings.

What to Do: Defence in Layers

No single change makes you immune, but the combination of the following significantly reduces your risk.

1. Replace SMS 2FA with authenticator apps or hardware keys

On every account that supports it, disable SMS verification and enable TOTP (time-based one-time passwords) via an app like Google Authenticator, Authy, or Microsoft Authenticator — or a hardware key like a YubiKey. TOTP codes are generated on your device and are not tied to your phone number, so a SIM swap gives the attacker nothing useful.

Start with your business banking apps, payment platforms, email, and domain registrar. Most UK banks now support authenticator apps for business accounts; some require you to request this through their business support team rather than switching in the app yourself.

2. Set a SIM lock or port authorisation code

UK mobile networks allow you to set a PAC (Porting Authorisation Code) requirement or a SIM swap PIN that must be provided before any number transfer can proceed. Contact your network directly:

  • EE: Call business support and request a SIM swap freeze or enhanced verification requirement
  • Vodafone: Ask for a “customer freeze” on your account — prevents any SIM changes without in-store photo ID
  • O2: Request a port lock and account PIN requirement
  • Three: Call business support to add a security password to your account

The exact process varies by network and account type, but all major UK operators have some form of additional protection available if you ask. It’s rarely offered proactively.

3. Use a separate number for critical accounts

If feasible, use a dedicated SIM (a cheap PAYG SIM or a VoIP number) specifically for receiving business security codes, separate from your main business number. Keep this number private — not on your website, not on business cards, not on any public profile. An attacker who doesn’t know the number can’t target it.

4. Set up account activity alerts

For banking and payment accounts, configure email or in-app alerts for any login from a new device, password change, or payment detail change. This gives you a window — potentially minutes — to contact your bank’s fraud team before damage is done, even if you do get SIM-swapped.

5. Review data broker exposure

Services like DeleteMe (UK-compatible) or browser-based tools like Have I Been Pwned let you check how much of your personal information is publicly accessible. The more an attacker can find about you before calling your network, the easier the social engineering is. Reducing your public footprint doesn’t eliminate the risk but raises the difficulty.

If It Happens to You

If your phone suddenly shows no signal or “SIM not registered” — especially if it coincides with unexpected emails about password changes — act immediately:

  1. Call your mobile network from another phone to report the unauthorised SIM swap and request your number be recovered
  2. Contact your bank’s fraud line (the 24-hour number on the back of your card) to freeze your account
  3. Change passwords on critical accounts via email (if email isn’t compromised) or using saved recovery codes
  4. Report to Action Fraud (actionfraud.police.uk) — SIM swapping is fraud and reportable

Recovery is possible but stressful. The window between a SIM swap and an attacker accessing accounts can be measured in minutes, which is why the defensive steps above — particularly moving off SMS 2FA — are worth implementing before any incident occurs.