Persuading or bribing a mobile operator to transfer a victim’s phone number to an attacker-controlled SIM, capturing SMS codes and account recovery.
Why it matters
It is why SMS is the weakest second factor: the “something you have” is a number a third party can reassign. App-based authenticators and hardware security keys are not transferable this way.
What you can check
The exposure is any account where a phone number can reset access. Authenticator apps and hardware security keys do not depend on the carrier; SMS codes do. Most carriers offer a port-out PIN or account lock, and most services list which second factors they support.
Not advice. Definitions are for understanding, not instruction. Nothing here is financial, legal, tax or security advice.