That "text WIN to 55555" entry feels harmless โ it's just a phone number, right? But your mobile number is the master key to your digital life. It's tied to your bank alerts, your email recovery, and most of your two-factor logins. When a sweepstakes entry form, an SMS shortcode campaign, or a leaky promoter puts that number into circulation, you're not just risking spam. You're handing attackers the first ingredient in a SIM swap โ the fastest-growing account-takeover attack in the US.
How a leaked number turns into a SIM swap
A SIM swap works like this: a criminal calls your carrier pretending to be you and convinces them to move your number to a SIM card they control. The moment it works, your phone goes dark and every SMS code โ bank, email, crypto exchange โ rings to their device instead. The FBI's Internet Crime Complaint Center logged over $48 million in reported SIM-swap losses in a single recent year, and the real total is higher because most victims never file.
Giveaways are a feeder for this because they collect your number plus the context that makes impersonation easy. A single sweeps entry often asks for your name, email, birthday, and ZIP alongside your phone โ exactly the "identity verification" answers a carrier rep asks to confirm you are you. Shady promoters sell those entry lists to data brokers, breaches leak them, and the bundle gets resold. An attacker who buys "phone + name + DOB + ZIP" for pennies has enough to pass a lax port-out check. The number you typed to win a $500 gift card becomes the thread that unravels your bank login.
Enter with a burner number, not your real one
The cleanest defense is to never give a giveaway your primary cell number. Set up a dedicated VoIP number โ Google Voice is free, or a service like MySudo runs a few dollars a month โ and use only that number for contest entries, loyalty signups, and any form you don't fully trust. If it gets sold, spammed, or breached, it's disposable, and it isn't the number your bank texts codes to. Google Voice numbers also can't be SIM-swapped the way a carrier line can, because there's no physical SIM to hijack.
Keep a hard wall between your "public" burner number and your "private" carrier number. Your real cell line should be known only to your bank, your close contacts, and your two-factor logins โ never a sweepstakes form. When you win something legit and the sponsor needs to reach you, the VoIP number forwards texts and calls to you just fine, so you lose nothing. The point is that the number floating around data-broker lists is one you can burn and replace in five minutes.
Lock the port-out and ditch SMS codes
Call your carrier today and add a port-out PIN (also called a "Number Transfer PIN" or account passcode). All four major US carriers โ Verizon, AT&T, T-Mobile, and the networks that ride on them โ support this, and it forces anyone trying to move your number to enter a code they don't have. It's the single most effective block against a SIM swap, and it takes about ten minutes to set up in the app or over the phone.
Then move your two-factor authentication off text messages. SMS codes are exactly what a SIM swapper steals, so replace them with an authenticator app โ Google Authenticator, Authy, or the codes built into your password manager โ or better, a physical security key like a YubiKey for your email and bank. Start with the accounts that matter most: your primary email (it's the reset path for everything else), your bank, and any crypto or payment app. Once those live in an app instead of a text, a stolen number can't unlock them. ๐
Enter sweeps with a burner number, PIN-lock your real one, and put your logins behind an authenticator app โ then a leaked number is just spam, not a break-in.