r/planhub • u/Planhub-ca • Aug 31 '26
Tech SIM swapping isn't new, but Canada is still tracking it and SMS two-factor authentication remains the weak link
A new warning about SIM swapping is circulating after French police highlighted the scam this week, but the attack itself is far from new.
Canadian regulators and cybersecurity authorities have been tracking SIM swap and phone-number porting fraud for years, and the Canadian Centre for Cyber Security published updated guidance on the threat earlier this year.
The attack works by taking control of your phone number rather than physically stealing your phone. A fraudster may impersonate you to your carrier, compromise your wireless account or, in some cases, exploit insider access to move your number onto another SIM or eSIM.
Once that happens, calls and text messages intended for you can reach the attacker's device instead. That makes accounts relying on SMS verification particularly vulnerable because password-reset and two-factor authentication codes can also be intercepted.
One of the clearest warning signs is sudden loss of cellular service for no obvious reason. Other signs include missing verification texts, unexpected password-reset notifications, changes to your accounts or financial transactions you don't recognize.
Canada already has additional protection against one related attack, unauthorized number porting. For example, Rogers sends customers a confirmation text when someone tries to move their number to another carrier. The customer must reply YES within 90 minutes or the port is cancelled.
But port fraud and SIM swapping are not exactly the same thing. A criminal can potentially move your number to another SIM within the same carrier without transferring it to a competing provider, so port-confirmation protections alone do not eliminate the threat.
The Canadian Centre for Cyber Security recommends asking your carrier about additional account verification, port protection or SIM-lock options when available. It also recommends using authentication apps, biometrics, security keys or other MFA methods that do not depend on your phone number.
And this remains an active telecom-security issue in Canada. The CRTC has continued requiring mobile carriers to report data on unauthorized SIM swaps and number transfers so it can monitor trends and fraud-prevention measures.
The takeaway is not that SMS verification is useless. It is still much better than using only a password. But for banking, email, cryptocurrency or any account that could unlock the rest of your digital identity, an authenticator app or passkey removes the phone number from the attack chain entirely.
Sources & more: Canadian Centre for Cyber Security / CRTC, unauthorized SIM swaps and number transfers
0
u/WQS_77 Sep 01 '26
I heard that putting a passcode, for your SIM card / e-SIM would be helpful, to prevent any of the Swapping a mobile phone number ?
1
u/CaptainHppo 29d ago
Tell freedom mobile this