Manav.id
Vertical · 5 min read

The subscriber never signs: why SIM-swap rules harden the wrong side

The subscriber never signs: why SIM-swap rules harden the wrong side

Every control the industry has deployed asks the carrier to be better at recognising an impostor. None asks the subscriber to produce something an impostor cannot. As long as a line change can be completed by convincing a human at the carrier, it will be.

Why do SIM-swap rules harden the wrong side?

Because they impose duties on the carrier, and the one party who could end the attack is never asked for anything. FCC rules require secure authentication before a SIM change or port. eSIM provisioning compressed the attack to minutes, and the subscriber still signs nothing.

Key takeaways
  • FBI IC3 logged 982 SIM swap complaints and $25,983,946 in losses in 2024 — a figure that undercounts because downstream losses are reported under other categories.
  • eSIM QR provisioning removed the physical SIM and the in-store handoff. A rep or a bribed insider can complete a port in roughly two minutes.
  • The enrolment-recovery paradox is the real engineering problem: bootstrapping a subscriber credential without recreating the support-channel bypass the control exists to eliminate.

The numbers, with their denominators

Carrier side (regulated)Authenticate before changeNotify the subscriberRecord the requestAll defeated by a convincing callerSubscriber side (unregulated)Signs nothingLearns afterwardsCannot pre-authoriseCould end the attack in one gesturevs
The subscriber is the only party who can definitively answer the question, and is never asked.

The FBI's Internet Crime Complaint Center recorded 982 SIM swap complaints in 2024, with reported losses of $25,983,946 — down from 2,026 complaints the prior year. Read those figures carefully before drawing comfort from the decline.

Complaint counts measure reporting, not incidence, and SIM swap is systematically under-reported because victims experience it as a bank fraud or an exchange account theft. The reported loss attaches to whichever category the victim filed under. A $25.98M direct figure sits alongside downstream losses that are counted elsewhere and are, on every practitioner account, substantially larger.

The honest summary is: the direct complaint volume fell, the per-incident downstream consequence rose, and neither number tells you about the attempt rate, which carriers hold and do not publish.

What the FCC rules do

The Commission adopted rules addressing SIM swap and port-out fraud, revising its CPNI and local number portability rules. In substance: carriers must use secure methods of authenticating a customer before effecting a SIM change or a port-out, must notify customers immediately of such requests, and must maintain records of requests and responses.

Every one of those obligations sits on the carrier. That is the correct place to put a regulatory obligation — the carrier is the regulated entity — and it is also the reason the rules cannot solve the problem, because the attack works by persuading the carrier.

What eSIM changed

Physical SIM swap had friction: a card, a store, a handoff, sometimes a courier. Remote SIM provisioning replaced all of that with a QR code and an activation code.

The practical consequence, described by security practitioners and visible in the provisioning architecture itself, is that a profile can be moved to an attacker-controlled device in about two minutes, with no physical artefact and no in-store identity check. An insider at a retail or care desk can complete it inside a normal-looking transaction.

Where each control acts. Note that every row operates on the carrier side.
ControlActs onDefeated by
Account PINCarrier verificationSocial engineering; PIN reset through the same channel
Port freezeCarrier verificationRemoval through the same channel
In-store ID checkCarrier verificationNot invoked for eSIM remote provisioning
Delay windowCarrier verificationPatience
Fraud scoring on change requestsCarrier verificationA request that looks ordinary
Subscriber signatureSubscriberNothing the carrier can be persuaded to do

The last row, stated precisely

If a line change requires a fresh assertion from a credential held on the subscriber's enrolled device, then no amount of persuasion applied to carrier staff produces the change. The insider cannot complete it. The social engineer cannot complete it. The person who knows the subscriber's mother's maiden name, last four payments and account PIN cannot complete it.

That is a categorical difference from every other row, and it is the reason this is worth the engineering difficulty that follows.

The enrolment-recovery paradox

Here is the hard part, and any proposal that skips it is not serious. The subscriber's credential lives on a device. Devices are lost, broken, stolen and replaced. So there must be a recovery path — and a recovery path that carrier staff can execute is precisely the support-channel bypass the control was built to eliminate.

Three designs, honestly scored:

DesignInsider resistanceSocial engineering resistanceUsability on device loss
Carrier staff can re-enrol on verificationNoneNoneExcellent
Second enrolled authenticator required; staff cannot re-enrolStrongStrongPoor if the subscriber enrolled only one
Staff can initiate re-enrolment; completion requires a delay plus notification to all prior authenticatorsModerateModerateGood

The second row is correct and will strand subscribers. The third is a compromise and is where most deployments will land. The first is where most deployments will land if nobody makes the argument, and it is worth nothing.

Making the override a signed exception

If a human override path must exist — and for a consumer service at national scale it must — then make it an artefact rather than a capability.

An override is performed by a named supervisor, signs a canonical statement of what was overridden and on what basis, carries a delay, and notifies every enrolled authenticator. It becomes a rare, attributable, reviewable event rather than an unlogged discretion exercised thousands of times a day.

What to measure

  1. Line changes per month, split by channel: self-service, care, retail, dealer.
  2. Share of subscribers with any authenticator enrolled, and share with two.
  3. Override rate per thousand changes, by store and by agent.
  4. Time from change to subscriber notification, measured rather than specified.

The third of these will be the uncomfortable one, and it is the one that tells you whether the control is real.

What eSIM changed

Provisioning time and attacker economics
EraChange mechanicsAttack window
Physical SIMShip or collect in storeDays
Store activationIn personHours
eSIM remote provisioningDownload a profileMinutes

A control designed around a delay does not survive the delay disappearing. Notification after the fact is now notification after the accounts have been drained.

Objections and honest limits

“Carriers are doing what the rules require.” Largely, yes. The rules constrain the carrier and the attack targets the carrier's staff, so compliance and exposure move independently.

“A subscriber signature adds friction to a legitimate change.” Once, on a change most subscribers make every few years. Compare that to the friction of an account takeover.

What a carrier could offer

  1. Let subscribers enrol a credential. Optional, and the ones who opt in are the ones with the most to lose.
  2. Require a signature for SIM change and port-out. Rendering the change being made.
  3. Offer a pre-authorised delay. So even a signed change cannot take effect instantly.
  4. Expose a verifiable signal to relying parties. A bank should be able to check recency without calling the carrier.

Terms used here

SIM swap
Moving a subscriber's number to an attacker-controlled SIM, usually by deceiving carrier staff.
Port-out
Moving a number to a different carrier, which achieves the same result through a different process.
eSIM provisioning
Downloading a subscriber profile remotely, which removes the physical step and the delay that came with it.

Frequently asked questions

Do the FCC rules not already require strong authentication? They require secure authentication methods and prompt notification. Those are obligations on the carrier's verification process. The distinction drawn here is between verifying the requester and requiring an act only the subscriber can perform.

What about subscribers with no smartphone? They need a path that does not exclude them, which means the override exists by design. The goal is to make it rare and attributable, not to eliminate it.

Does this stop downstream account takeover? It removes the phone number as the compromise vector. It does nothing about relying parties who accept other weak recovery factors.

Would carriers adopt this voluntarily? The commercial case is remediation, churn and litigation cost, plus a differentiated position with high-value subscribers. Whether that outweighs implementation cost is a carrier-specific calculation.

Why don't carrier rules stop SIM swap? They constrain the carrier, and the attack works by deceiving carrier staff. Compliance and exposure move independently.

What did eSIM change? It removed the physical step. A change that used to take days now takes minutes, and notification after the fact arrives too late.

What would a subscriber signature add? The one thing no caller can produce. It is friction once every few years against a takeover that drains accounts.

Where this fits in Manav

Manav puts the subscriber or the authorising party back in the loop for the changes that matter, with a signature bound to the specific change and verifiable by a bank, a regulator or a counterparty without calling the carrier.

See change authorisation →

Sources and further reading