Editorial scope: This is an account-control and home-security response checklist, not a claim that every carrier, alarm company, lock, or camera uses the same sign-in or recovery process. Product menus, recovery methods, monitoring rules, and carrier protections change. Verify the current process in the official app, carrier account, and service agreement before an incident.
A SIM-swap attack can turn a phone number into a route for password resets, one-time codes, support impersonation, and account recovery. That does not automatically give an attacker control of an alarm, camera, or smart lock. The risk depends on how each account verifies identity, whether the number is a recovery method, which sessions are already signed in, and whether another owner can remove users or rotate credentials.
The right response is not “reset everything.” It is to contain the phone-number takeover, protect the email and password-manager accounts that sit above the security system, preserve local alarm and entry functions, remove untrusted sessions, rotate the credentials that matter, and test the finished system from clean devices.
What a SIM swap is—and what it is not
The U.S. Federal Trade Commission describes SIM swapping as an attacker convincing a mobile carrier to move a victim’s number to a SIM card or device the attacker controls. Calls and texts intended for the victim may then reach the attacker. The FTC recommends contacting the carrier immediately, changing account passwords, checking financial accounts, and considering authentication methods that do not depend on text messages. Read the current FTC SIM-swap guidance before building your response sheet.
Keep three incidents separate:
| Incident | What changed | Home-security concern | First control |
|---|---|---|---|
| Lost or stolen phone | The physical device is missing | Existing app sessions, saved passwords, notifications, wallet keys, and local device access | Lock or mark the device lost through the platform’s official recovery route |
| SIM swap or number port-out | The phone number moved without authorization | SMS codes, voice calls, password recovery, monitoring callbacks, and support verification | Contact the carrier through a known official channel and recover the number |
| Security-account compromise | An alarm, camera, lock, email, or password-manager account has an untrusted session or changed credential | Direct control, video access, resident access, alert suppression, or evidence deletion | Use a clean device to remove sessions, change credentials, and verify settings |
One event may include all three, but do not assume it does. Record the evidence for each. A phone that suddenly shows no service could be a carrier outage, damaged eSIM, billing problem, device fault, or unauthorized transfer. Confirm with the carrier instead of treating the symptom as proof.
Warning signs that justify an immediate check
- Your phone loses cellular service while nearby phones on the same carrier still work.
- The carrier sends a notice about a SIM, eSIM, device, account PIN, or number-port change you did not request.
- Password-reset, sign-in, or one-time-code messages appear for accounts you were not using.
- A carrier-account password, email address, PIN, or authorized user changes unexpectedly.
- Alarm, camera, lock, email, or password-manager sessions disappear or show unknown devices.
- A monitoring center cannot reach the expected phone, or the account’s contact order has changed.
- A household member receives a message asking for a verification code, recovery code, or remote-support session.
Do not click a link in the warning message to investigate. Open the saved carrier app, type the known carrier address, use the number printed on a bill, or visit a carrier store. The home-security support scam checklist explains why an incoming caller, caller ID, text, or search ad is not proof of identity.
Build the dependency map before an incident
A useful response plan starts with dependencies, not brands. Write one row for every account that can alter security, access, evidence, monitoring, or recovery.
| Account or service | Can the phone number reset it? | Current MFA route | Other signed-in owner | Recovery held offline | Local fallback |
|---|---|---|---|---|---|
| Primary email | Yes / no / unknown | SMS, authenticator, passkey, security key, other | Name or none | Recovery codes and date tested | Not applicable |
| Password manager | Yes / no / unknown | Exact method | Name or none | Emergency kit or recovery code | Not applicable |
| Carrier account | Yes / no / unknown | Exact method | Authorized-account owner | Account number, PIN, port controls | Store or alternate line |
| Alarm vendor | Yes / no / unknown | Exact method | Second admin | Recovery method and support record | Keypad, siren, local code |
| Camera vendor | Yes / no / unknown | Exact method | Second admin | Recovery method | Local recorder or card, if installed |
| Smart-lock vendor | Yes / no / unknown | Exact method | Second admin | Recovery method | Key, keypad, inside thumb-turn |
| Smart-home platform | Yes / no / unknown | Exact method | Second owner | Recovery method | Direct app, keypad, key, local controls |
| Professional monitoring | Callback and support rules | Verbal passcode or documented alternative | Second contact | Account and permit records | Local alarm operation |
Store the map with the system record described in the home-security documentation checklist. Do not put live passwords, complete recovery codes, or unencrypted account secrets in a shared household note.
First 15 minutes: contain the takeover without disabling the house
- Move to a clean communications path. Use a trusted second phone, computer, landline, or in-person carrier location. Do not use a device or browser session that shows signs of compromise.
- Contact the carrier through a known official route. Ask whether the number, SIM, eSIM, device, account PIN, or port status changed. Record the time, case number, agent channel, and promised next step.
- Protect primary email and the password manager. These accounts can reset many downstream services. Review active sessions, recovery methods, forwarding rules, authorized apps, and recent security events before working through individual devices.
- Tell the other security owner. A second trusted administrator should preserve alarm operation, watch alerts, and check whether users, codes, cameras, or monitoring contacts changed.
- Keep physical controls available. Confirm that keys, keypad codes, inside releases, local sirens, and manual garage controls work. Do not factory-reset a hub or lock while account recovery is uncertain.
- Start a written incident log. Capture facts, not guesses: service loss time, messages received, account changes, unfamiliar sessions, carrier response, security alerts, and actions taken.
If there is an active break-in, threat, fire, or medical emergency, use the appropriate emergency service. Account recovery is secondary to immediate safety.
Protect the accounts above the security system
Work from the top of the dependency chain. A common safe order is primary email, password manager, carrier, smart-home platform, alarm account, camera account, lock account, monitoring profile, and secondary household accounts. Your actual order may differ if a vendor account owns the entire system.
For each account:
- Use a clean device and navigate directly to the official site or app.
- Review active sessions, trusted devices, recent sign-ins, connected apps, recovery email, recovery phone, and MFA methods.
- Remove sessions or devices you cannot identify. Record what was removed.
- Change the password to a unique value if compromise is suspected or confirmed.
- Replace an exposed SMS route where the service supports a stronger method.
- Generate new recovery codes if old codes may have been visible or copied, then invalidate the old set.
- Check mail-forwarding, notification, and support-delegate settings; an attacker may seek persistence instead of immediate device control.
- Do not remove the last working owner, trusted device, security key, or recovery route until the replacement is tested.
If the incident includes unknown sessions or changed settings, follow the broader home-security account-compromise response as well.
Move high-value accounts away from SMS where supported
SMS can be better than no second factor, but a phone-number takeover targets that route. Prefer the strongest current method the account supports and that the household can recover safely. Options can include passkeys, physical security keys, authenticator apps, trusted-device approvals, or vendor-specific methods.
Apple documents how physical security keys work as an additional protection for Apple Account sign-in in its current Security Keys for Apple Account guide. Google documents physical keys in its security-key sign-in guide. Those pages apply to their respective accounts, not automatically to every alarm, camera, or lock vendor.
Do not switch methods during a crisis without a recovery plan. A physical key can improve resistance to phishing and phone-number takeover, but losing every enrolled key or removing the last usable recovery route can create a different lockout. Enroll, label, store, and test backup keys according to the platform’s current rules.
Alarm system: preserve detection while checking authority
- Confirm the alarm remains armed or disarmed in the expected state using a local keypad or another trusted owner.
- Check the owner, administrators, household users, emergency contacts, monitoring contacts, verbal passcodes, and permitted support delegates.
- Review recent arm/disarm events, user changes, device removals, bypasses, and automation changes.
- Rotate codes tied to the compromised person or phone if the system’s records show exposure. Do not rotate every code blindly if that would remove a caregiver, responder, or household member during the incident.
- Confirm sensors, sirens, keypads, cellular backup, and local alarm behavior are separate from the stolen phone number. Test through the approved mode; do not trigger an avoidable dispatch.
- If professional monitoring is active, ask the provider to verify the contact order and identity process. Document any temporary contact change and its expiration.
The monitoring test checklist covers signals, zones, callbacks, contacts, and records. Tell the monitoring provider before running any test that could create a real alarm event.
Smart locks, garage doors, and access credentials
A phone-number takeover is not the same as a valid physical key or door code. Still, an attacker who enters the lock, home-platform, email, or vendor account may be able to view or change access. Check each access layer separately:
- Mechanical key, cylinder, key safe, and emergency-entry plan.
- Lock-vendor owners, guests, access codes, schedules, and access history.
- Smart-home residents, shared users, scenes, geofences, and auto-unlock rules.
- Garage-app owners, guest access, vehicle integrations, remotes, keypads, and manual release.
- Alarm codes and lock codes that happen to use the same digits. Replace reused values with separate credentials.
Use the smart-lock access-code audit to review named people, schedules, contractors, former residents, emergency access, and removal tests. Keep one tested non-phone entry method available before removing digital credentials.
Cameras and evidence: preserve before you change
Camera evidence can show when an account changed, whether someone approached the home, and whether a device went offline. It can also be destroyed by a rushed reset or retention expiry.
- Check camera owners, viewers, shared links, integrations, active sessions, notification rules, privacy modes, recording plans, and local-recorder users.
- Export relevant account-change, door, driveway, entry, and device-offline clips before resetting cameras or closing accounts.
- Preserve original timestamps, file names, export method, and a simple custody note. Do not edit the only copy.
- Confirm whether local recording continued during phone-number or internet disruption. Do not assume cloud history proves local recorder health.
- After access is secured, remove unknown viewers and links, rotate shared credentials, and test a new event from capture through export.
Do not publish identifying footage while seeking help. Share only with people or authorities who need it, following applicable privacy and evidence rules.
Monitoring callbacks and emergency contacts
A recovered security account is not enough if the monitoring center still calls a hijacked number. Review:
- Primary and secondary contacts in the exact order used.
- Numbers used for alarm verification, service notices, and billing.
- Verbal passwords, duress procedures, permit records, and call lists.
- Whether a temporary alternate number can be used and how it will be removed later.
- Whether the monitoring provider sends SMS links or codes and how staff distinguish genuine messages.
Never send a verbal passcode or one-time code in response to an unsolicited text. Call the monitoring provider using the number on the contract, app, or known official site.
Carrier controls to document before a crisis
Carrier names and features vary by region. Ask the carrier what controls are available now and what each one actually protects. Examples may include an account PIN, number-port lock, transfer PIN, authorized-user list, in-person verification, notification of SIM changes, or a separate account password. A label such as “port protection” does not prove protection against every account or SIM change.
Record:
- Account owner’s legal name and authorized users.
- Carrier account number and official support routes.
- Current SIM/eSIM identifiers only where safely stored and needed.
- Account PIN and transfer controls in a protected recovery record—not a shared plain-text note.
- What the carrier requires for an unauthorized-transfer investigation.
- How to reach support if the affected number cannot receive calls or texts.
Actions that often make recovery worse
- Factory-resetting the alarm hub first. This can erase configuration while leaving the carrier, email, or owner account compromised.
- Changing every code without a map. This can lock out trusted residents or responders and make the incident harder to reconstruct.
- Removing all trusted devices at once. You may delete the last route capable of approving recovery.
- Trusting incoming support. Attackers can exploit the confusion with calls, texts, ads, or remote-access requests.
- Reusing the recovered phone number immediately for every account. First confirm the carrier account, PIN, authorized users, and transfer controls are clean.
- Testing with a live dispatch. Use monitoring test mode and the provider’s approved process.
- Deleting logs and video. Preserve useful evidence before cleanup.
- Assuming a restored number ends the incident. Review persistence in email, password-manager, smart-home, security, and carrier accounts.
Recovery order after the number is restored
- Confirm the carrier account owner, password, PIN, authorized users, SIM/eSIM, devices, forwarding settings, and port controls.
- Recheck primary email, password manager, Apple or Google account, and other identity accounts for sessions or recovery changes made during the outage.
- Recheck alarm, camera, lock, garage, and smart-home owners and users.
- Rebuild MFA using tested non-SMS methods where supported, retaining safe backup routes.
- Restore monitoring contacts and remove temporary numbers only after a callback test passes.
- Rotate any credential confirmed exposed. Avoid unnecessary resets that add failure risk without removing access.
- Run end-to-end alert, access, video, outage, and recovery checks.
- Close the incident with dates, case numbers, remaining unknowns, and a scheduled follow-up review.
60-minute home-security SIM-swap acceptance test
Do not request a real SIM swap for this test. Simulate loss of the primary phone and number while keeping emergency communications available. Notify other household members and any monitoring provider before starting.
| Time | Test | Pass condition |
|---|---|---|
| 0–5 min | Put the primary phone in airplane mode and store it out of reach. Open the printed response sheet. | A trusted person identifies the official carrier route, account owner, second communications path, and incident-log location without using the unavailable phone. |
| 5–12 min | Access primary email and password manager from a designated recovery device. | Recovery works without SMS to the unavailable number, or the plan clearly identifies the current limitation and a corrective action. |
| 12–20 min | Open the alarm account from the second owner or recovery route. Review users, system state, contacts, and recent events. | The system remains in the expected state; no unknown user or change appears; local keypad control works. |
| 20–28 min | Review smart-lock and garage access, then use a non-phone entry method. | A key, keypad, or approved backup route works; active users and schedules match the written register. |
| 28–36 min | Trigger an approved door or motion event without creating a dispatch. | The second owner receives the expected alert through a route that does not rely on the unavailable number. The event has the correct zone and time. |
| 36–44 min | Create a test camera event and export it. | The camera records as expected, a trusted user can review it, and the export retains a usable timestamp. |
| 44–52 min | Use monitoring test mode and the provider’s approved callback process. | Signal, zone, contact order, verbal verification, and temporary alternate contact behavior match the account record. |
| 52–57 min | Inspect recovery methods for email, carrier, alarm, camera, lock, and smart-home accounts. | No account depends solely on an undocumented phone-number route; backup keys or codes are current and safely stored. |
| 57–60 min | Restore the phone, close test mode, and record results. | Normal alerts resume, temporary changes are removed, and every failure has an owner and retest date. |
Measure alert timing with the home-security alert-delay test. A push alert, text, email, call, monitoring event, and local siren are different paths; test the paths your household actually expects to use.
After-action review
Within 24 hours, document what happened, what was confirmed, which accounts were exposed, which credentials changed, which sessions were removed, and which evidence was preserved. Within seven days, verify carrier records, monitoring contacts, account recovery, and any financial or identity follow-up recommended by the relevant provider or authority.
Then reduce future concentration risk:
- Give a second trusted owner the minimum authority needed to keep the home safe.
- Separate alarm, lock, garage, and guest codes rather than recycling one value.
- Use unique passwords and the strongest recoverable MFA each account supports.
- Keep offline recovery records current and protected.
- Retest after changing a carrier, phone, email, password manager, monitoring provider, lock, hub, or smart-home owner.
- Schedule a quarterly review of users, sessions, recovery methods, and emergency contacts.
Frequently asked questions
Can a SIM swap disarm my security system?
Not by itself. A SIM swap moves control of a phone number. Disarming depends on whether that number can help an attacker enter the alarm, email, smart-home, or vendor account and whether the system permits remote disarming. Check the exact account, users, sessions, recovery methods, and local alarm records.
Should I remove my phone number from every security account?
Not blindly. Some services require a number for alerts, callbacks, or recovery. Review what the number does, add stronger supported authentication and safe backup methods, and test recovery before removing any route.
Should I factory-reset cameras, locks, or the alarm hub?
Usually not as a first step. Secure the carrier, email, password manager, and owner accounts; preserve evidence; remove untrusted access; then reset only a device whose ownership or configuration cannot be made trustworthy another way.
What if professional monitoring calls the compromised number?
Contact the provider through a known official route. Verify the contact order, verbal passcode process, and temporary alternate number. Test the corrected record in the provider’s approved test mode.
Are authenticator apps safe during a SIM swap?
An authenticator app does not normally depend on receiving an SMS for each code, but the device, account backup, recovery process, or vendor account may still create risk. Follow the app and account provider’s current instructions, protect the device, and keep tested recovery routes.
What is the most important preparation?
Create a dependency map and prove that a second trusted person can keep alarms, entry, alerts, cameras, and monitoring working when the primary phone and number are unavailable. A written plan that has never been tested is only a draft.