AT &T has launched its new Wireless Lock, designed to prevent SIM swapping — one of the most common cybercrime scenarios targeting mobile users.

The feature, which was available to a limited number of users for nearly a year, is now available to all AT&T subscribers. When enabled, it prevents critical account changes, such as porting your phone number to another SIM or carrier, providing an extra layer of protection against fraud attempts.
See also: Cybercriminals target T-Mobile and Verizon employees for SIM-swapping attacks
SIM swapping attacks occur when cybercriminals manage to transfer a phone number to their own device, thereby gaining access to calls, SMS, and two-factor authentication codes. In many cases, attackers go so far as to trick or bribe telecom company to complete the breach.
With AT &T 's Wireless Lock , users can use the company's app or website to "lock" their number. This means that no SIM changes , number porting, or billing changes can be made, even by an AT&T employee (unless the feature is manually disabled).
For business accounts, additional options are provided, such as excluding specific lines from the lock or limiting the ability to make changes when the feature is active.
See also: SIM swapping attacks: eSIMs are also entering the “game”
With the growing threat of SIM swapping attacks, AT&T's initiative marks a significant step towards strengthening digital security in the telecom space. However, the move comes rather late, as competitors like Verizon have been offering similar services for nearly five years.
SIM swapping attacks have caused serious security incidents in recent years. In 2020, Joseph James O'Connor, known as "PlugwalkJoke," was found guilty of attacks that resulted in the theft of nearly $800,000 worth of cryptocurrency. A year later, T-Mobile warned its customers about SIM swapping attacks aimed at compromising their accounts, while in 2023, hackers exploited a Google Fi data breach to carry out similar attacks.

Additionally, threat actors such as Scattered Spiderhave been accused in the US of using SIM swapping to infiltrate corporate networks. More recently, eSIM hijacking, where criminals activate electronic SIM cards in the name of victims, gaining control of their numbers.
Responding to growing threats, the US Federal Communications Commission (FCC) strengthened regulations in 2023, imposing stricter identity verification measures in cases of SIM changes and number portability, trying to better shield the telecommunications landscape.
See also: Google plans SIM backup
Successful attacks can lead to unauthorized access to personal accounts and sensitive information, theft , financial losses, and stress for victims.
Providers are required to implement secure authentication processes before transferring customer phone numbers to different devices or providers. They must increase the security of customers' accounts by implementing additional levels of verification for account access, such as requiring personal contact or sending a special code via email.
Additionally, users can protect themselves from SIM swapping attacks by remaining cautious about sharing personal information and contacting their provider immediately if they receive suspicious messages.
Finally, telecommunications companies should educate their staff about the dangers of SIM-swapping and create policies that prohibit changing the SIM card without the account holder's immediate approval.
Source: www.bleepingcomputer.com
