SmishAlert brief · September 2026
The phone number was never proof of the person.
iOS 27 lets one phone number live on two iPhones. As of this month, the number is not even proof of the phone. Here is what changes for fraud teams, and what to do before the first case lands.
No form. No email required.
Reported cybercrime losses in 2025, up 26% on the prior year
FBI IC3 Annual Report, 2025
The most reported crime type of 2025, and the way most of these takeovers begin
FBI IC3, 2025
SMS one-time codes have been a restricted authenticator. Most retail fraud programs still rely on them
NIST SP 800-63B
What changed this month
One number, two iPhones, and the codes follow whichever one you are holding.
iOS 27 adds a feature Apple calls iPhone Handoff. A customer designates a main iPhone, which keeps the real eSIM and controls every cellular setting. A second iPhone receives a companion eSIM, issued by the carrier, carrying the same phone number on different hardware.
Whichever phone is unlocked and in use becomes the active endpoint, and calls, texts and one-time codes follow it there. The carrier hands out the second profile on purpose.
Confirmed
The mechanics above, setup under Settings, Cellular, and that carrier support is required.
Not yet confirmed
Which US carriers will turn it on and when, what confirmation steps Apple requires, and what identity check a carrier applies before issuing a companion profile.
The point is that the feature ships before the fraud playbook around it is written, and the people who run SIM swaps today will write it.
Why this is quieter than a SIM swap
A classic SIM swap has a tell. The victim’s phone goes dead, they notice within hours, and the window closes.
A companion profile obtained by the same means, a social-engineered carrier rep, an insider, or a compromised carrier account, leaves the victim’s phone working normally. The one-time codes simply arrive somewhere else, and nothing in the customer’s day says anything is wrong until money moves.
How the attack actually runs
It starts with a conversation, not a device.
Every version begins with a conversation, not a device: a text or a call wearing a brand the customer trusts, their carrier or you, over channels that never touch your infrastructure.
The customer is the target
A call or text from “carrier support” about a security update or an unrecognized device. The caller walks the customer through their cellular settings, or has them read back a code that approves the new profile. Ninety seconds, and the customer believes they just protected their line.
The carrier is the target
The attacker calls the carrier as the customer, using details harvested from an earlier phishing text, and asks for a companion profile on a second phone. The customer never gets a call at all. This is the SIM-swap script with the outage removed.
You are the pretext
A text from “your fraud team” about a suspicious charge, with a callback number the attacker controls. The security step on that call is the carrier profile or the one-time code itself, read aloud by a customer who thinks they are talking to you.
These scenarios are our assessment based on what Apple and carriers have published so far. The exact steps to provision a companion profile, and the checks around them, are not yet public and may change how each variant plays out. The pattern they share, a conversation that precedes any device change, does not depend on those details.
What your controls see, and when
By the time you get a signal, the decision is four steps old.
The takeover is detectable at the third step below, if device identity is part of your authentication model. The first two steps are where the customer could have stopped it, and where you had no way to help them.
Minute 0
The pretext
A text or call from “carrier support” or “your fraud team”. Invisible to you. The customer decides alone.
Minutes later
The companion profile
A second device now receives the line’s texts. Recorded at the carrier, not with you. The customer’s phone still works.
Hours later
Password reset, one-time code
Your first signal. It comes from the right number and looks exactly like the customer.
Days later
The dispute
Your second signal. The money is gone and the campaign has moved on.
Controls worth changing before the first case lands
Five changes, in the order they pay off.
Treat a device change on an existing number as a step-up event
Carrier data providers already expose SIM-change and device-change signals. Consult one before trusting an SMS code on a high-risk action, and expect companion profiles to show up there as carriers roll out support.
Move high-value actions off SMS codes
App-based approval, passkeys or an authenticator for wires, payee changes, contact changes and limit increases. NIST has treated SMS as a restricted authenticator for nearly a decade, and Handoff removes the last argument for waiting.
Rewrite the customer script, and put it where customers will see it
“We will never call you to change your phone settings” belongs in every branded channel you run, not only on the security page of your website.
Add one question to takeover intake
“Was a second iPhone ever added to your line?” The first cases will be written off as isolated takeovers unless someone asks.
Give customers somewhere to send the text or the callback number before they act on it
Every control above starts after the conversation is over. This one starts during it, at the only moment the customer can still walk away.
Where SmishAlert fits
SmishAlert gives every customer a trusted place to send a suspicious message and get immediate guidance, with no app required. The reply says in plain language what evidence of fraud was found and what to do next: do not tap the link, open your institution’s app, call the number on your card.
Every report also gives your fraud team a view of the campaign while it is still running: the brand being impersonated, the lure, the timeline and how many of your customers it has reached, so you can warn the next customer before the call comes.
What SmishAlert does not do
It cannot see a companion profile being provisioned at a carrier, and it does not authenticate any message or caller. It identifies evidence of risk in the conversation that leads there, the part of this attack your existing stack cannot see.
FAQ
Questions security leaders ask
What is iPhone Handoff in iOS 27?
iPhone Handoff is a feature in iOS 27 that lets one phone number work on two iPhones. The customer designates a main iPhone that keeps the real eSIM, and a second iPhone receives a companion eSIM issued by the carrier carrying the same number. Whichever phone is in use becomes the active endpoint, so calls, texts and one-time codes are delivered there.
Why does iPhone Handoff matter for account takeover?
Because SMS one-time codes follow the active phone. If an attacker obtains a companion profile on a device they control, through a social-engineered carrier representative, an insider or a compromised carrier account, the codes arrive on their phone. Unlike a SIM swap, the customer's own phone keeps working normally, so nothing signals that anything is wrong until money moves.
How is this different from a SIM swap?
A SIM swap announces itself. The victim loses service and usually notices within hours, which closes the attacker's window. A companion profile leaves the victim's line working, so the loss of exclusive control over one-time codes is silent. It is the same outcome with the warning removed.
What should a fraud team do about it now?
Treat a device change on an existing number as a step-up event and consult carrier device-change signals before trusting an SMS code on a high-risk action. Move wires, payee changes, contact changes and limit increases off SMS codes. Publish a clear customer script stating you will never call to change phone settings. Add a question about second devices to takeover intake. And give customers somewhere to send a suspicious message before they act on it.
Which US carriers support iPhone Handoff?
That is not confirmed. As of September 2026 the mechanics of the feature are documented and carrier support is required, but the carrier rollout schedule, the confirmation steps Apple requires, and the identity check a carrier applies before issuing a companion profile have not been published. This brief is written on what is known and is explicit about what is not.
Sources
- Apple iOS 27 release coverage, September 2026 (MacRumors, 2 September; TechTimes, 3 September; MacDailyNews and Cult of Mac, 4 September).
- FBI Internet Crime Complaint Center, 2025 Annual Report.
- NIST Special Publication 800-63B.
SmishAlert. "The Carrier-Support Call: The Ninety Seconds Before the Takeover." SmishAlert LLC, September 2026.