SIM swapping
Fraud in which an attacker gets a mobile carrier to move a victim's phone number to a SIM the attacker controls, then receives the codes sent to it by text message or call.
In a SIM swap, the attacker contacts the victim’s mobile carrier, usually posing as the victim using personal details gathered in advance, and asks for the number to be moved to a new SIM card or eSIM. The victim’s phone then loses service and their calls and text messages go to the attacker. It is social engineering against the carrier’s customer processes rather than a technical break of the phone network.
The prize is usually the one-time passwords and account recovery codes delivered by text or voice. This exposure is one reason NIST SP 800-63B-4 treats authentication over the public switched telephone network as a restricted authenticator (sections 3.1.3.3 and 3.2.9), and advises verifiers to weigh signals such as a SIM change or number porting before sending a code. Codes from an authenticator app (TOTP) do not travel over the phone number, so a SIM swap alone does not capture them, though they can still be phished. Phishing-resistant authentication such as FIDO2 does not depend on the number, provided text messages are not kept as a recovery route.
Exam relevance: a scenario in which a user suddenly loses mobile service shortly before their accounts are taken over is likely to describe SIM swapping. Candidates are expected to identify text-message authentication as the weakness and to prefer app-based or phishing-resistant authenticators.