Zimbabwe Scam Watch · 9 min read

SIM-Swap Fraud in Zimbabwe: What to Do When Your Number Suddenly Dies

If your phone unexpectedly loses service while everyone else is connected, treat it as a possible account-security event. A stolen mobile number can expose SMS recovery codes, wallets and financial accounts.

Your phone suddenly says No Service. You restart it. Nothing changes. If there is no obvious network outage, do not treat that only as a connectivity inconvenience. It can be a security signal.

In a SIM-swap attack, a criminal persuades or tricks a mobile carrier into moving your number to a SIM or eSIM they control. Once the transfer succeeds, calls and SMS messages intended for you can reach the attacker instead. That matters because many services still use SMS to reset passwords or approve logins.

Why the Mobile Number Is More Valuable Than It Looks

Your number may be linked to email recovery, banking alerts, EcoCash, social media, WhatsApp and two-factor authentication. If an attacker controls the number and also knows enough personal information to reset one key account, the compromise can cascade.

Email is especially important because it often sits above other accounts in the recovery chain. A stolen number can therefore become a route into the email account that resets everything else.

The Zimbabwe Warning Signs

Treat these as reasons to investigate immediately:

  • your SIM loses service unexpectedly while nearby users still have network;
  • you receive messages about a SIM replacement or account change you did not request;
  • WhatsApp or another account says your number was registered on a new device;
  • password-reset messages appear for services you did not touch;
  • mobile-money or banking alerts stop arriving unexpectedly.

None of these proves a SIM swap by itself. The point is that the cost of checking quickly is low compared with the cost of waiting if the number was actually taken over.

The First 15 Minutes

  1. Use another phone or internet connection to contact your mobile network through an official support channel.
  2. Ask whether a SIM replacement, SIM swap or profile change was recently performed on your number.
  3. Contact EcoCash or your bank if the number is linked to money-moving accounts.
  4. Secure the email address used for account recovery and sign out suspicious sessions.
  5. Change passwords on high-value accounts, starting with email and financial services.
  6. Revoke unknown devices and review recovery phone numbers and email addresses.

EcoCash’s terms tell users to notify the provider immediately if the phone or SIM is hacked, lost, stolen or no longer under the user’s control.

Reduce the Blast Radius Before an Attack

Where possible, use an authenticator app, passkey or hardware security key instead of SMS for email and other critical accounts. Use a unique password on your primary email. Do not publish unnecessary identity details that could help someone impersonate you to a provider.

For a business, avoid making one director’s mobile number the single recovery key for every company service. Separate account ownership, document administrators and keep backup recovery methods under controlled access.

If Money Has Already Moved

Contact the bank, wallet or payment provider immediately and request fraud escalation. Preserve transaction references, SIM-change messages, screenshots and timestamps. Ask the mobile network for records or reference numbers associated with the disputed SIM event where available.

Do not delay financial reporting while waiting for the telecom investigation to finish; the two recovery processes can run in parallel.

Frequently Asked Questions

Does losing signal always mean somebody swapped my SIM?

No. Network faults and device problems are common. The warning is sudden unexplained loss of service, especially when accompanied by account-change or login alerts.

Why should I secure email first?

Email is often the recovery channel for many other accounts. If an attacker gets the email account, they may be able to reset multiple services.

Is SMS two-factor authentication useless?

It is better than no second factor for many users, but authenticator apps, passkeys or hardware keys can reduce dependence on the mobile number where supported.

Sources & further reading