Thieves have found a way to drain a bank or brokerage account without ever touching the victim’s phone, using the number itself as the key. In a port-out scam, a criminal armed with a few personal details persuades a wireless carrier to transfer a victim’s number to a device the criminal controls, instantly capturing the text-message codes that banks and brokerages send to confirm a login. Within minutes, the same one-time passcodes meant to protect a retirement account can become the tool used to empty it. The balance at risk is whatever those codes guard, which for many older Americans is a lifetime of savings.
How a port-out quietly drains an account
The attack usually begins offline, with a thief assembling names, birthdates, addresses, and account details harvested from data breaches or phishing messages. Armed with that information, the criminal contacts the victim’s carrier, or walks into a store, and requests that the number be ported to a new carrier or activated on a new SIM. Once the request goes through, the victim’s own phone abruptly loses service, a moment that many people mistake for a network glitch rather than a theft in progress.
From there the number does the damage. Because so many banks and investment firms still send login and password-reset codes by text message, the criminal who controls the number can request those codes, reset passwords, and clear the two-factor prompts that were supposed to stop exactly this kind of intrusion. Federal regulators warn that these schemes let attackers bypass two-factor authentication and reach financial, health, and email accounts, and the window between the port and the first fraudulent transfer can be a matter of minutes.
What makes the scheme insidious is how ordinary the early signs look. A phone that shows no service, a missed verification text, or an unexpected email about an account change can all be dismissed as glitches, and precious minutes pass before the victim realizes the number itself has been stolen. By then the attacker may already be resetting passwords, because the same automated systems that make banking convenient also make takeover fast once the number is in hand.
Free retirement updates: Miss an enrollment or claim deadline and it may be gone. Our free Retirement Shield newsletter keeps readers ahead of the ones that matter. Get the free newsletter.
The money at stake behind the codes
The reason port-out fraud is worth the effort is the size of the accounts it unlocks. A hijacked number is not the prize; the prize is the checking balance, the retirement account, and the credit lines that number can be used to access. Older adults are attractive targets precisely because they tend to hold larger balances and are less likely to have set up the carrier-level safeguards that blunt the attack, making a single successful port potentially far more lucrative than a stolen card number.
The broader toll is well documented. The FBI’s Internet Crime Complaint Center reported that Americans age 60 and older lost nearly $4.9 billion to fraud in 2024, and account-takeover schemes that ride on stolen phone numbers sit squarely within that total. Unlike a fraudulent charge that a card issuer may reverse, money wired out of a compromised bank or brokerage account can be far harder to recover once it leaves the institution.
The asymmetry favors the thief. Assembling the personal details to request a port can be done quietly over days, but executing the takeover and draining an account takes only minutes, and the victim is often asleep or away from a working phone when it happens. For a retiree whose brokerage and bank logins all funnel through one mobile number, a single successful port can expose every account at once rather than one at a time.
That concentration of risk is the quiet cost of convenience. Consolidating logins behind one phone number streamlines everyday banking, but it also means a single stolen number can unlock a whole financial life, and older savers who set up text-based verification years ago may not realize how much now depends on it.
Carrier rules and the defenses that still hold
Regulators have tried to close the gap. The Federal Communications Commission adopted rules requiring wireless providers to use secure methods to verify a customer before moving a number to a new device or carrier, and to notify customers immediately whenever a SIM change or port-out is requested on their account. Those notifications are the early-warning system, and a customer who acts on one the instant it arrives has the best chance of stopping a transfer before it clears.
Individual steps still matter most. Security experts advise setting a separate carrier PIN or port-freeze on the mobile account, moving critical logins from text-message codes to an authenticator app or a physical security key, and treating a sudden loss of cell service as a possible attack rather than an outage. Anyone whose phone goes dark unexpectedly should contact the carrier through another line right away and alert the bank before the codes can be used.
None of these measures is foolproof, which is why layering them matters. A carrier PIN slows an impostor at the store counter, an authenticator app removes the text message as a single point of failure, and prompt attention to a service outage buys time to call the bank. Together they turn a fast, quiet theft into one that trips alarms and demands effort, and effort is exactly what pushes an opportunistic thief toward an easier target.
Recovery after the fact is harder than prevention because the money often moves through channels that resist reversal. Funds pushed out by wire or converted to cryptocurrency can clear before a victim regains control of the number, and unlike a disputed card charge, those transfers may not be reversible. That imbalance is the strongest argument for locking down the mobile account in advance, since the account most exposed is usually the one holding the retirement savings that took decades to build.
The shift to embedded SIM cards has reduced the physical swaps that once dominated these schemes, but it has not closed the door. Port-out fraud persists because it targets the process, not the hardware, exploiting the moment a number moves between carriers and the widespread habit of using text messages as a security backstop. As long as a single passcode delivered to a phone can authorize access to an account, the number itself remains a target worth stealing.
The unresolved tension is that the convenience of text-message verification is also its weakness. Every institution that leans on a phone number as proof of identity is trusting a credential that can be transferred away from its owner in minutes, and until account-recovery systems stop treating a mobile number as a master key, the safest posture for anyone guarding retirement savings is to assume the number can be taken and to build defenses that do not depend on it.
This article was produced with AI assistance and reviewed against primary sources by The Money Overview editorial team.
More Financial Reading