A SIM swap attack targets something you might not think of as a security risk: your phone number.
The attacker gathers enough personal details about you, often from data leaks or social media, then contacts your mobile carrier pretending to be you. They convince the carrier to move your number to a SIM card they control. Once that happens, your calls and texts go to them, including the security codes sent by text message.
With your number in hand, they can reset passwords and pass any two-factor authentication that relies on SMS, potentially reaching your exchange accounts and email.
The key defence is to stop relying on text messages for security. Use an authenticator app or a hardware security key for two-factor authentication instead of SMS wherever possible. It also helps to add a PIN or passcode with your mobile carrier, making it far harder for someone to impersonate you and hijack your number.