Skip to main content

The Money Overview

Port-out scammers hijack your phone number to break into your bank account

Most account takeovers require a stolen password, but a growing category of theft skips that step entirely by stealing something harder to change: the victim’s phone number itself. In a port-out or SIM-swap attack, a criminal convinces a wireless carrier to move a number onto a device they control, and from that moment every call and text meant for the victim, including the one-time codes that guard bank logins, flows to the thief instead. The account holder is often the last to know, sometimes noticing only when a phone that should have signal quietly goes dark.

How a stolen number becomes a stolen account

The attack works because phone numbers have quietly become master keys. Banks, brokerages, and email providers routinely text a verification code to confirm a login or approve a transfer, treating possession of the number as proof of identity. When a scammer redirects the number, that assumption collapses, and the thief can request password resets and intercept the codes needed to complete them, walking through the front door of one account after another.

Getting the number moved is often the easy part. Criminals gather personal details from data breaches, social media, and public records, then call the carrier posing as the customer and claim a lost or upgraded phone. The Federal Communications Commission warns that this port-out fraud can also start with an unauthorized transfer to a competing carrier, using stolen identity information to authorize the switch. Once approved, the change can take effect within minutes.

The financial damage compounds quickly. With the number captured, a thief can drain checking and savings, open new lines of credit, and reach retirement or brokerage accounts that rely on text-based security. The FBI’s internet crime unit has recorded SIM-swap complaints rising more than 400 percent over a three-year span, with reported losses topping $68 million, and older adults with larger balances are a favored target.

Crypto holders and people with large cash balances face the sharpest exposure, because those transfers move fast and are rarely reversible once initiated. The same logic reaches retirement and brokerage accounts, where a single approved withdrawal can move a life’s savings before the account holder regains control of the number. That combination of deep balances and text-based security is exactly what draws thieves toward older account holders, who are also less likely to notice a service interruption quickly or to have app-based authentication already in place.


Free retirement updates: Scam calls targeting retirees change every week. Our free Retirement Shield newsletter flags the ones going around and the one tell that stops each. Sign up free.

The warning signs that arrive before the money does

Unlike scams that depend on a convincing phone call, a port-out attack often announces itself through the device. A phone that abruptly loses service in a place with normal coverage, a message that the SIM has been changed, or an inability to make calls or send texts can all signal that a number has been transferred. Emails confirming password changes or new-device logins that no one initiated are a second red flag, especially when they cluster within a short window.

Speed of response separates a scare from a catastrophe. Anyone who suspects a takeover should contact the wireless carrier immediately to reclaim the number, then move to secure financial and email accounts from a different device. The FTC’s alert on protecting against SIM-swap scams recommends acting the moment service drops unexpectedly rather than waiting to see whether it returns on its own.

The defenses that make a number harder to steal

The strongest protection is to make the carrier account itself difficult to breach. Most wireless providers allow customers to add a unique port-out PIN or passcode that must be given before any number transfer, a step the FCC highlights in its overview of cell phone fraud. Because that PIN is separate from the account login, it blocks a thief who has gathered enough personal data to pose as the customer.

Reducing reliance on text messages closes the second gap. Security experts increasingly recommend authentication apps or physical security keys over text codes for banking and email, because those methods do not travel with the phone number. Removing a mobile number as the recovery option on the most sensitive accounts means that even a successful port-out no longer hands over the keys.

Monitoring adds a final layer of defense. Setting account alerts for password changes, new-device logins, and large transfers means an unexpected notification can surface an attack while it is still in progress, and freezing credit with the major bureaus blocks a thief from opening new accounts even after a number is captured. None of these steps is technically difficult, but each removes a rung from the ladder a port-out thief has to climb, and together they buy the minutes that decide whether an account survives.

Why the risk keeps outrunning the fix

Port-out fraud persists because it exploits two systems that were never designed to guard large sums: a carrier’s willingness to move a number on request and a bank’s habit of trusting whoever holds it. Until text-based verification fades as the default, the number attached to a retirement account will remain a single point of failure worth stealing, and the burden of locking it down falls on the account holder well before any thief places the call.

This article was produced with AI assistance and reviewed against primary sources by The Money Overview editorial team.

More Financial Reading