Across East Africa, a phone number is far more than a contact detail. It is a wallet, a bank login, a password reset channel and a proof of identity. That concentration makes SIM swap a uniquely high-value attack here.
How the attack runs
The attacker gathers enough personal information to impersonate the victim — much of it available from social media, data breaches or simple pretexting. They then persuade the mobile operator to port the number to a SIM they control, through a retail agent, a call centre, or an insider.
From the moment the swap completes, every SMS code goes to them. Mobile money, bank accounts, email password resets, social accounts. The victim's phone simply loses service — which is often the only warning, and it is easily mistaken for a network problem.
Why SMS as a second factor fails here
SMS-based verification assumes control of the number proves identity. SIM swap breaks that assumption completely, and it does so without touching any password. It is worth being direct: SMS is better than nothing, and materially worse than the alternatives.
- Authenticator apps generate codes on the device itself, with nothing to intercept.
- Hardware security keys are the strongest option and resist phishing as well.
- In-app approval tied to a registered device avoids the SMS channel entirely.
For individuals
- Set a PIN or passphrase with your mobile operator, required before any SIM change.
- Move critical accounts off SMS verification to an authenticator app.
- Treat sudden, unexplained loss of mobile service as a security event — call your operator from another phone immediately.
- Reduce what is publicly available about you: date of birth, mother's maiden name and the other staples of identity verification are often on social media.
For organisations
If you authenticate customers or staff by SMS, you have inherited this risk.
- Offer and encourage app-based authentication; reserve SMS as a fallback rather than the default.
- Detect recent SIM changes where your operator relationships allow it, and apply additional verification to high-value transactions when a number has changed recently.
- Do not permit password reset by SMS alone for privileged accounts.
- Monitor for the pattern: a SIM change followed quickly by a password reset and a transaction is a strong signal.
The broader lesson
Any control that depends on a third party's identity verification process inherits the weakest point of that process — in this case, a retail agent under pressure to be helpful. Design on the assumption that the phone number can be taken, and decide what should still be impossible when it is.
