An attacker who has social-engineered a carrier into porting your customer’s number now receives every SMS code you send. The password may be phished or reset, the OTP is delivered, and from your backend the login looks perfectly authenticated.
SIM-swap fraud works because it attacks the phone number, not the person and not the device. That gap is exactly where device intelligence earns its place: the attacker controls the number, but they are sitting at a completely different device than your real customer.
Why the OTP is the wrong thing to trust
SMS one-time passwords assume the number is a proxy for the human. A port-out breaks that assumption instantly. Once the number lives on the attacker’s SIM, the code you generate is a code you are handing to the fraudster. No amount of OTP hardening fixes an authentication factor that has been physically relocated.
The signal that does not move with the number is the device. Your genuine customer keeps logging in from the same phone, the same browser, the same hardware. The attacker cannot clone that. When an SMS-verified login suddenly originates from a device you have never seen, the correct code is a red flag, not a green light.
Signals that expose the post-port login
The takeover almost always shows the same fingerprint pattern:
- A brand-new visitorId with zero prior successful logins on the account
- A network change into a different ASN, often a residential proxy or datacenter range
- A geography jump inconsistent with the account’s normal login region
- A fresh browser or app install with default, low-entropy configuration
- Reset-then-login timing, where a password reset and first login happen minutes apart
Individually these are noisy. Together, arriving on an OTP-verified session, they describe a SIM swap far more reliably than any single carrier signal you could buy.
Prynt assigns each browser and device a stable visitorId that survives cookie clearing, private mode, and app reinstalls. When the OTP succeeds but the visitorId is new to the account, you have caught the exact moment a swapped attacker walks through the door.
Building a step-up that the attacker can’t satisfy
The point of detection is to force a challenge the number holder cannot pass. A SIM-swapper has the code but not the device history, so route high-risk logins to factors that are device-bound rather than number-bound:
- On a new-device, OTP-verified login, do not treat the session as fully trusted. Mark it provisionally authenticated.
- Require a second, non-SMS factor: a passkey tied to the original device, an authenticator app enrolled before the swap, or a hardware key.
- Hold sensitive actions — payout details, email change, adding a new payee — behind a cool-down when the device is unrecognized.
- Fire a push and email to the enrolled original device, which the attacker does not control.
Because Prynt resolves the visitorId server-side, you make this decision in your own backend at login, not in client code the attacker can tamper with. The Smart Signals payload arrives alongside your auth check, so the step-up fires before the session token is issued.
Watching the recovery flow, not just login
SIM-swap chains rarely stop at one login. Once inside, the attacker changes the recovery email, disables the original authenticator, and adds their own number. Each of those events deserves the same new-device scrutiny you applied at login.
Score the whole sequence. A new device that logs in, immediately changes recovery settings, and moves money within a single session is not a customer who bought a new phone — it is the textbook SIM-swap kill chain. Reason codes that name the specific signals (new device, network mismatch, reset-to-login velocity) let your fraud team explain the block instead of guessing.
Start scoring device risk at login
You cannot stop a carrier from porting a number, but you can make the stolen number worthless without the device. Layering a stable device identifier over your existing OTP flow turns a silent SIM-swap login into a loud, blockable event.
Prynt is free to start, and you can watch a fresh visitorId appear the moment you switch devices in the playground. Wire it into your login and recovery paths, and the code the attacker holds stops being enough on its own.
Try it free
Prynt is device intelligence with a free tier — visitor IDs, bot & fraud Smart Signals, and behavioral biometrics, powered by a cross-site network. Start free.