All Posts
Why SIM Cloning Isn't Used Anymore, And What Changed It

Why SIM Cloning Isn't Used Anymore, And What Changed It

Your phone number is more valuable to hackers than your password. Here's what they're actually doing to steal it.

Imagine waking up one morning, reaching for your phone, and noticing something odd, no signal. Not a spotty bar or two. Nothing. You restart the phone. Still nothing. You try calling from another device and hear your own voicemail pick up immediately. Somewhere out there, someone else is answering your calls, receiving your texts, and, most critically, intercepting the two-factor authentication codes protecting your bank account.

This is not something you see only in sci-fi movies. It is happening to real people, and it is getting more and more common. However, the attackers most likely didn't "clone" your SIM like the movies show, that's a trick that is almost forgotten now. What came after is much simpler, yet much more dangerous.


What SIM Cloning Actually Is

Each SIM card has two identifiers that make it recognizable:

  • IMSI (International Mobile Subscriber Identity), a unique number that identifies you to the network
  • Ki (Authentication Key), a secret cryptographic key that is used to confirm that your SIM is genuine

To clone a SIM, an attacker would need to physically get both of these from your SIM card and put them onto a blank programmable SIM. Technically, this would let their device act as your phone number on the network, taking your calls and texts as if they were you.

Technically. But the real question is: are they capable of doing it?


The Short Answer: It Depends on How Old Your SIM Is

During the 1990s, SIM cloning was a major concern. At that time, older SIM cards depended on an authentication algorithm called COMP128v1, which was gravely compromised. An attacker who manages to get hold of a SIM card can within hours, by using a SIM reader (a very cheap and widely available device) send thousands of carefully crafted challenge queries to the card and extract the Ki key. The rest of the cloning process becomes easy from then.

Eventually, carriers and manufacturers became aware of the problem. Nowadays, SIM cards employ far more powerful algorithms the most common being COMP128v3 and Milenage and the Ki is stored in a secure hardware element which is designed to be non-extractable by any means. Invading the key of a modern SIM by force is computationally impossible with the current state of technology, even if the attacker has physical access to your SIM.


What Attackers Actually Do Today

Since breaking modern SIM cryptography is very complicated, attackers decided to stop trying it. Instead, they discovered a much simpler door for getting in, by calling your mobile carrier's customer support.

SIM Swapping: The Social Engineering Attack

During a SIM swap, a hacker gets in touch with your mobile carrier and poses as you. They say their phone was lost or damaged and ask for the number to be moved to a new SIM card, the one they have.

They open a way to the customer's account by using personal data obtained from breaches, social networking sites, or phishing attacks: full name, home address, the last 4 digits of the Social Security number, the account PIN. With a great deal of this info, many customer support representatives at the carrier will do the transfer without a second thought.

When the hijacking is done, your phone will no longer work. Their phone will receive even the ones meant for you, including 2FA codes.

Some of the famous cases of victims have been crypto investors, journalists, and even Jack Dorsey, Twitter CEO, whose account was hacked with the SIM swap in 2019.

SS7 Attacks: The Telecom Backdoor

Actually, there's another way to do this one that doesn't even involve tricking anyone through social engineering. And that would be the SS7 protocol (Signaling System No. 7) that is the telecommunications backbone worldwide allowing call, text and roaming management between different networks.

It was so simple back then, only a handful of trusted actors had access to it. Most people today would not even dream of accessing the SS7. Its security model, however, did not change with time. Those who have access to the SS7 can listen to your calls and read your SMS messages without needing your physical SIM. You would hardly suspect.

In fact, this is one of the most solid reasons for not relying on SMS as a way of two-factor authentication. Your messages are far from being private.


How to Actually Protect Yourself

As the danger changes, your protective measures should change as well. Here is the list of things that really work:

1. Enable a SIM PIN or SIM lock

Usually, carriers give you an option of setting a PIN which has to be keyed in before your SIM can be used or transferred. Do that. It makes it harder for someone who tries to do a SIM swap.

2. Request a port freeze or account lock from your carrier

You can get in touch with your carrier and request them to put additional verification steps, sometimes these extra measures are known as "port freeze" or "account lock", that stop the transferring of your number unless you have personally authorized it by showing an ID at the store.

3. Don't rely on SMS for two-factor authentication

Go for an authenticator app (Google Authenticator, Authy, or Apple's integrated option) rather than getting SMS codes if you can. Authenticator codes generated locally on your device are not vulnerable to SIM swapping or SS7 interception.

4. A hardware security key is the best defense for high-value accounts

If you are very serious about the security of your email, bank accounts, and crypto wallets, using a physical hardware key such as YubiKey is considered the best method. It is not possible to intercept it remotely.

5. Keep your personal information private as much as possible

The most direct way that SIM swapers use to trick you is through your personal data. Keep track of what you are sharing openly, have strong and different passwords for your accounts, and turn on the service that tells you when your data has been leaked.


The Bigger Picture

SIM cloning is the kind of threat that makes great tech thriller plots but we don't really have to worry about it that much in real life. The real risk to your phone number, in 2024 is very ordinary: an experienced scammer chatting a customer service rep who's a bit bored and giving just enough of your personal info to be believable.

Don't get scared of your SIM card. Just realize that the most vulnerable part of mobile security is very rarely the technology itself it's the human element surrounding it.

Defense your account information the same way you safeguard your passwords. Besides, for what is really sensitive, don't rely on your phone number as the ultimate security layer.


Found this useful? Share it with someone who still uses SMS for two-factor authentication. It might save them a very bad morning. And don't forget to subscribe to my newsletter to get security content like this

Enjoyed this post?

Get notified when I publish next.

No spam — only new posts on networking, security, DevOps and infrastructure.

Comments

Leave a comment