security

SIM Swap Attacks Can Drain Your Cloud Storage

Your cloud account password is strong. But if you use SMS two-factor authentication, a SIM swap attack can bypass it in minutes.

Your Google Photos library. Your iCloud drive. Your backup of every important document you’ve accumulated over years. You protected all of it with a strong password and two-factor authentication.

Now imagine losing access to all of it in fifteen minutes — without your password ever being guessed, without your device ever being touched.

That’s what a SIM swap attack does.


What Is a SIM Swap Attack

A SIM swap — also called SIM hijacking or SIM porting — is a type of account takeover that exploits the way mobile carriers operate, not the way your apps or passwords work.

The sequence: an attacker contacts your mobile carrier’s customer support, claims to be you, and convinces a representative to transfer your phone number to a SIM card they control. This is often easier than it sounds. Attackers prepare using personal information harvested from data breaches, social media profiles, and sometimes direct social engineering of people close to you.

Once the transfer is complete, your phone loses service. Every call and SMS message sent to your number arrives on the attacker’s device instead — including any one-time passcodes your accounts send for authentication.

Reported SIM swap incidents have risen dramatically in recent years. UK data showed cases jumping from under 300 to nearly 3,000 incidents within a single year. The FBI has tracked hundreds of millions of dollars in losses from SIM swap fraud, and the frequency of attacks is increasing as organized criminal groups run these operations at scale.


How a SIM Swap Drains Your Cloud Files

Most cloud storage and photo services still support SMS-based two-factor authentication. Many users have it enabled because it’s the option presented during setup and it feels like enough.

The problem is structural. When an attacker controls your phone number, they can initiate a password reset on your email account. The reset code arrives on their device. They set a new password. They own your email.

From email, the cascade begins:

  • Reset the password for your Google account, which controls Google Photos, Google Drive, and Google One storage
  • Reset your Apple ID via account recovery, gaining access to iCloud Photos and iCloud Drive
  • Access Dropbox, OneDrive, or any other cloud service tied to that email address as a recovery option

Every layer of protection you built — the strong password, the 2FA habit, the careful account hygiene — collapses because your phone number became the weakest link in the chain.

What attackers do with cloud access

Once inside a cloud storage account, attackers move quickly for several reasons. Common motivations include:

Ransomware tactics. Personal photos and documents are deleted or moved to attacker-controlled storage, then held for a ransom payment to “restore” them. Irreplaceable memories make powerful leverage.

Identity document harvesting. Passports, driving licences, bank statements, tax documents, and medical records stored in cloud drives fetch high prices on identity fraud markets. Most people store scanned copies of these without thinking about who else might access them.

Financial fraud enablement. Screenshots of bank apps, brokerage statements, or payment confirmation emails can provide enough information to facilitate further fraud.

Further account compromise. Cloud email archives often contain password reset links, account confirmation emails, and other information useful for gaining access to additional accounts.

The attacker’s goal is to extract value and lock you out before you notice your phone has gone dark.


Why Your Carrier Isn’t Your Safety Net

SIM swapping depends on human error inside carrier call centres — and that’s difficult to eliminate entirely.

Carriers have introduced improvements: PIN codes required for account changes, in-store verification, account lock features. These measures raise the bar. None make SIM swapping impossible.

Social engineering specifically targets the human layer. An attacker who has researched your public profiles and prior data breaches can construct a plausible story for a customer service representative under pressure to resolve calls quickly. Verification controls vary by carrier and by individual representative.

Port freeze programs — available at most major carriers under names like “port lock,” “number lock,” or “account protection” — prevent number transfers from being initiated without in-person verification. They’re worth enabling. But they’re opt-in, meaning most users don’t have them.


The Fix: Move Away from SMS 2FA

The most effective protection against SIM swap attacks is to stop using your phone number as an authentication factor for accounts where it matters.

Authenticator apps

Apps like Google Authenticator, Authy, or Apple’s built-in authenticator generate time-based codes on your device. These codes are not delivered over your phone number — they’re generated locally using a shared secret established during setup. A SIM swap doesn’t affect this mechanism at all.

Switch your primary email, your Google account, your Apple ID, and your main cloud storage accounts to authenticator-based 2FA. Then disable SMS as a fallback option where the service allows it.

The limitation: if you lose your device without backup codes stored somewhere, account recovery becomes harder. Keep your backup codes in a physical location or a password manager.

Hardware security keys

Physical security keys (like YubiKey) and passkeys provide the strongest protection because authentication requires physical possession of the key. There’s no phone number involved, no code to intercept, and no SMS channel to attack.

Both Google and Apple support hardware keys for account authentication. For anyone with a high-value archive of personal files, a hardware key is the single highest-impact security investment available for under $50.

Disable SMS as a recovery method

Many services list your phone number not just for 2FA but as an account recovery option. An attacker who controls your number can use account recovery flows even if you’ve switched to an authenticator app for regular login.

Review each of your important accounts and remove your phone number from recovery options if the service allows it. This is different from removing SMS 2FA — recovery methods deserve a separate audit.


Carrier-Level Protections: What to Actually Do

Contact your mobile carrier and ask specifically about:

Account PIN. Most carriers allow you to set a separate PIN required for any account changes, including SIM transfers. This is distinct from your device unlock PIN. If you haven’t set one, set one now.

Port freeze or number lock. This prevents your number from being transferred without in-person verification at a store. The exact name varies by carrier. Ask directly: “How do I prevent my number from being ported without me going into a store?”

Disabling phone-based account management. Some carriers let you restrict all account changes to happening in-store or online only, removing the phone-support vector entirely.

These are free to enable and take a single phone call or store visit.


A Practical Audit Checklist

Start with what matters most:

Primary email account

  • Switch to authenticator-app 2FA
  • Remove your phone number as a 2FA method
  • Remove your phone number as an account recovery option
  • Enable a hardware security key if available

Cloud storage accounts

  • Google Photos / Drive: secured through your Google account; the above covers it
  • iCloud: go to Apple ID settings, remove phone number from trusted phone numbers if a hardware key or separate authenticator is configured
  • Dropbox, OneDrive: switch to app-based 2FA in account security settings

Phone number protection

  • Call your carrier, set an account PIN
  • Request a port freeze or number lock
  • Review what personal information is visible on your social media — birthdates, carrier mentions, family member names — that an attacker could use to impersonate you

Backup codes

  • Download backup codes for every account where they’re available
  • Store them offline: printed, or in a password manager that doesn’t use SMS recovery

What Happens If a Swap Occurs

The warning sign is unmistakable: your phone loses service unexpectedly. Calls fail, SMS stops arriving, data goes dead.

When this happens, call your carrier immediately from a different phone or go to a store. Report the unauthorized transfer. Request the number be restored.

The window between the swap and the attacker completing their takeover is narrow — they move quickly precisely because they know the phone going dark is noticeable. Priority order: restore your phone number, then change the password for your email account before the attacker can lock you out permanently.

Google, Apple, and Microsoft all have account recovery processes that require more than SMS verification alone. Initiating these before the attacker modifies recovery options is the race you’re trying to win.


How daftei Approaches This

daftei doesn’t use your phone number as an authentication factor. There’s no SMS-based 2FA path that a SIM swap can exploit to bypass account access.

Additionally, daftei has a 30-day account grace period before permanent deletion. If an attacker who has gained access to an account attempts to delete it — a common step in account takeovers to prevent recovery or destroy evidence — that action isn’t immediate and irreversible. The 30-day window exists so you have time to notice and reverse the action before data is permanently erased.

Account security is only as strong as the weakest factor in the chain. If a SIM swap can get into your email, and your email can reset your cloud storage password, a strong password on the storage account itself provides limited protection. The chain matters, and phone numbers shouldn’t be links in it.


The Core Lesson

SIM swapping exploits trust in phone numbers as identity. That trust was built into authentication systems during an era when physical possession of a phone number felt like a reasonable security signal. It no longer is.

Authenticator apps and hardware keys don’t have this weakness. Neither does a port freeze at your carrier. The mitigations exist, they’re free or cheap, and they take an afternoon to implement.

The question is whether you make those changes before something happens, or after.

Your memories deserve better than an ad platform.

Try daftei free →
← All posts