Criminals rarely jump straight to a full SIM‑swap takeover. They often test the waters first with a “dry‑run” to see what they can access, whether you notice, and how your carrier responds. Two early red flags are unexpected store‑visit notifications and brief, unexplained service interruptions or suspensions. Acting quickly at these early signals can stop a full account takeover, prevent loss of your phone number, and protect your financial and identity accounts linked to SMS verification.
What Is a SIM‑Swap Dry‑Run?
A SIM‑swap dry‑run is a preliminary step attackers use to probe your mobile account before committing to a full port or SIM change. The goal is to confirm your personal details, test carrier procedures, and gauge whether they can redirect your calls and texts without immediate detection. If the test goes unnoticed, they may proceed to seize your number, intercept one‑time passcodes, reset passwords, and drain your accounts.
Why criminals do dry‑runs
- Validation: Ensure your number is active and tied to valuable services (banks, crypto, email).
- Process mapping: Learn what your carrier requires for a SIM change or port‑out.
- Timing: Identify the best time to execute a takeover when you’re less likely to respond (late night, travel, weekends).
- Noise testing: See which alerts you receive and whether you take action.
Early Signals: Store‑Visit Notifications
Many carriers send texts or emails saying a representative or store has updated your account, viewed your profile, or initiated a device or SIM change request. If you did not visit a store or contact support, treat this as a potential dry‑run or social‑engineering attempt.
Common store‑visit or account‑change messages
- “Your account was accessed in store.” Indicates an employee looked up your account. Attackers may be using stolen details to feign ownership.
- “A SIM change was requested.” Someone tried to associate your number with a new SIM card.
- “Device upgrade in progress.” Suggests an attempt to tie your line to a new device or financing, sometimes a precursor to SIM swapping.
- “Port‑out request submitted.” Signals an attempt to move your number to a different carrier.
What to do immediately
- Do not reply to the alert directly. Go to your carrier’s website and call the number listed there or use the official app. Attackers sometimes spoof messages with malicious callback numbers.
- Ask for a security review. Request the representative check recent access logs, notes, and pending orders on your account. Ask them to cancel any request you did not authorize.
- Enable or strengthen a port‑out/SIM‑change lock. Add or update an account PIN/passcode and request the strictest in‑person and phone verification your carrier offers.
- Document the incident. Save screenshots of the message, the date/time you called, and the representative’s confirmation that the request was removed.
Early Signals: Temporary Line Suspensions and Brief Service Loss
Short, unexplained interruptions—no bars, “SOS only,” missed calls that go straight to voicemail, or sudden inability to send/receive texts—can indicate a SIM change attempt or provisioning test on your line. Some criminals trigger a brief suspension to verify control steps without fully porting your number.
What it can look like
- Intermittent outage for minutes to an hour: Your phone regains service without explanation.
- “Welcome to your new device” or activation texts: Appearing when you have not changed phones.
- Unusual voicemail behavior: Voicemail password prompts reset or greeting changes.
- Carrier app logout: You’re unexpectedly logged out of your carrier account, or the password no longer works.
Immediate response steps
- Use Wi‑Fi to secure accounts right away. If cellular is unstable, connect to Wi‑Fi and change your email and carrier account passwords from a trusted device.
- Contact the carrier via official channels. Ask whether there was a SIM change, eSIM transfer, line suspension, or port‑out request. Have them cancel anything pending and re‑provision your original SIM or eSIM if needed.
- Rotate recovery options. If you rely on SMS codes, switch critical accounts to app‑based authenticators and add secure backup codes.
- Monitor for password‑reset emails. Attackers often reset bank, email, or social passwords immediately after gaining control of your number.
How Attackers Orchestrate Dry‑Runs
Dry‑runs typically pair social engineering with leaked personal data. Attackers may:
- Use breached data: Names, addresses, and last four of SSN to pass basic checks.
- Pose as you in store: Attempt a SIM replacement claiming a lost or damaged phone.
- Call support with persuasion: Pressure reps using urgency or spoofed call IDs to bypass security.
- Test multiple channels: Start a small request online, call in, then show up in store to find the weakest link.
Lock Down Your Carrier Account
Proactively hardening your mobile account reduces the chance that dry‑runs succeed. Each carrier offers slightly different tools—ask for the strongest available.
Baseline protections to request
- Unique account PIN/passcode: Not your birthday or address. Store it securely.
- Port‑out protection: Require in‑person verification with government ID and the account PIN before any port or SIM change.
- Account notes and flags: Ask the carrier to add a “do not change without PIN and photo ID” note visible to all reps.
- Text/email alerts for every change: Turn on notifications for logins, SIM swaps, and port requests.
- Limit authorized users: Remove old lines, former employees, or unused authorized contacts.
On‑device defenses
- Enable a SIM PIN: Requires a code when the SIM is moved to another phone. Keep the PUK code in a safe place and never share it.
- Strong phone lock: Use a long passcode or biometrics; disable lock‑screen previews of texts to reduce information leakage.
- Secure eSIM transfers: Keep device firmware updated and require device unlock to add or transfer eSIM profiles.
Reduce Your Reliance on SMS for Account Security
Because SMS can be intercepted after a SIM swap, prioritize phishing‑resistant or app‑based methods for your most valuable accounts.
- Use app authenticators: Move 2FA to apps like Microsoft Authenticator, Google Authenticator, or password‑manager‑based authenticators.
- Prefer security keys where supported: Hardware keys (FIDO2/WebAuthn) offer strong protection from SIM‑based attacks.
- Store backup codes offline: Keep printed or encrypted copies in separate secure locations.
- Update recovery email and phone: Use a separate email for account recovery and avoid using the same phone number for all services.
What To Do If You Suspect a Dry‑Run
If a store‑visit alert or temporary suspension raises your suspicion, act as if a takeover is imminent. Speed matters.
- Lock down the carrier account: Call from a trusted number via the official website/app, set a new account PIN, enable port‑out protection, and cancel any pending changes.
- Secure your email first: Email is often the master key. Change the password, enable 2FA with an app or hardware key, and review recent login activity.
- Harden financial and crypto accounts: Remove SMS 2FA, add app/hardware 2FA, and review linked devices and sessions.
- Check your password manager: Rotate passwords for high‑risk accounts (banking, brokerage, major retailers, social, cloud storage).
- Review devices and sessions: Log out of unknown sessions in email, social media, and financial apps; revoke suspicious OAuth connections.
- Watch for new lines or financing: Attackers sometimes attempt device financing in your name. Contact your carrier’s fraud department if you see unfamiliar orders.
Signals That a Full Takeover May Be Underway
- Persistent no‑service on your phone while friends say your line rings or goes to voicemail.
- Bank or email password‑reset notifications you didn’t request.
- Carrier confirms a completed SIM swap or port‑out that you did not authorize.
- Multiple failed 2FA attempts or login alerts across accounts.
If any of these occur, escalate immediately: ask the carrier to freeze the line, revert the SIM, and require in‑person verification; contact banks to place holds; and change credentials from a known‑safe device.
How to Talk to Your Carrier’s Fraud Team
Being precise speeds up resolution. Use clear requests and log every step.
- State the issue: “I received an unauthorized store‑visit alert and had a service interruption. Please review logs for my line and cancel any pending SIM, device, or port‑out activity.”
- Request protections: “Add a port‑out lock, require my account PIN and government ID in person for any SIM change, and note no changes by phone unless the secure passcode is verified.”
- Ask for confirmation: Get a case number, the rep’s name or ID, and a confirmation email summarizing changes.
Strengthen Identity and Financial Monitoring
SIM‑swap attempts often coincide with broader identity risks, including new‑account fraud and unauthorized credit activity. Ongoing monitoring can help you catch fallout quickly if attackers proceed after a failed dry‑run.
- Set fraud alerts or credit freezes with the major credit bureaus if you suspect identity misuse.
- Monitor for new accounts and hard inquiries that you don’t recognize.
- Track password‑reset and security alerts from your email, banks, and brokerages.
If you want a single place to keep an eye on credit changes and identity‑linked activity while you harden your accounts, consider a dedicated monitoring solution such as SmartCredit for privacy, credit monitoring, and identity protection.
Reduce Exposure That Fuels Social Engineering
Attackers lean on publicly available data to answer carrier verification questions. Limiting what’s exposed makes dry‑runs harder.
- Minimize public contact details: Remove or obfuscate phone numbers and addresses from social profiles and business listings where feasible.
- Opt out of data brokers: Suppress listings that publish your home address, age, and relatives—common verification clues.
- Separate numbers: Consider a dedicated number for 2FA that you never share publicly, or use app/hardware methods instead.
Create a Personal SIM‑Swap Response Plan
Write down the exact steps you’ll take if you receive a suspicious alert, so you aren’t scrambling under pressure.
- Who to call: Carrier fraud number from the official site, banks’ fraud lines, and your email provider’s security help page.
- What to change first: Email and carrier credentials, then financial logins, then other services.
- How to verify: Use a separate, trusted device and a secure network when changing passwords and 2FA.
- Evidence capture: Save messages, call logs, and any case numbers in a secure note.
Frequently Asked Questions
Are store‑visit notifications always malicious?
No. Sometimes a legitimate system audit or minor account check triggers an alert. But if you didn’t request help, treat it as suspicious until your carrier confirms details and removes any unauthorized activity.
Can a SIM PIN stop a carrier‑level swap?
A SIM PIN protects your physical SIM if moved to another device, but it doesn’t stop a carrier from reassigning your number to a different SIM. That’s why port‑out locks and strong account PINs with the carrier are essential.
Is eSIM safer than a physical SIM?
eSIMs remove the risk of someone physically stealing your SIM, but account‑level swaps and eSIM transfers can still be abused if your carrier account is not locked down. Use strong authentication and port‑out protections either way.
What if I’m traveling and lose service?
Roaming can cause intermittent service, but unexpected “activation” texts or carrier account changes are not normal. Contact your carrier using Wi‑Fi calling or their app to confirm no unauthorized actions occurred.
Conclusion
SIM‑swap dry‑runs thrive on small warning signs: a store‑visit alert you didn’t expect, a brief service loss, or a stray “new device” message. Treat these as urgent. Verify changes directly with your carrier using official contact channels, enable the strongest port‑out and SIM‑change protections they offer, and remove SMS from your most important logins. By acting quickly at the first hint of trouble—and by monitoring for identity and credit misuse—you can shut down a dry‑run before it escalates into a full takeover.
Good to Know
A sudden “Welcome to your new device” text, even when your phone hasn’t changed, can be an early warning sign of a SIM‑swap attempt. Treat it as urgent and contact your carrier using a trusted number from their official site.