A bank account can be drained without a password ever being guessed, because the weakest link is often a phone number rather than a login. In a port-out or SIM-swap attack, a criminal persuades a wireless carrier to move a victim’s number onto a device the criminal controls, then catches the text-message security codes banks send to confirm a transfer or a password reset. Federal regulators have tightened the rules carriers must follow, but the defenses that stop these takeovers still rest largely on steps account holders set up in advance.
How a hijacked number becomes an open bank account
The attack has two common forms. In a SIM swap, a scammer contacts the victim’s carrier, claims the phone was lost or damaged, and convinces a representative to activate the victim’s number on a new SIM card. In a port-out, the number is transferred to an entirely different carrier without the owner’s consent. Either way the outcome is identical: calls and texts stop reaching the real owner and start flowing to the attacker’s phone. The Federal Trade Commission describes the mechanics plainly, noting that once the number is captured, the criminal receives the two-factor codes meant for the victim and uses them, together with stolen banking details, to break into accounts.
Text-message verification is the pivot point. Many banks and brokerages still confirm logins, password resets and large transfers by sending a one-time code by SMS, a system built on the assumption that only the account owner controls the phone number. When that assumption fails, the second layer of security becomes a gift to the intruder, who can approve the very transactions the code was designed to block. A retiree who does everything else right, guarding passwords and avoiding suspicious links, can still be exposed if the phone number itself is stolen.
Free retirement updates: A quiet rule change can shrink your Social Security or Medicare check, and no one warns you. The free Retirement Shield newsletter catches these early and tells you what to do. Get it free.
What the FCC now requires of wireless carriers
Regulators moved to close the gap after a wave of these thefts. The Federal Communications Commission adopted an order in November 2023, with a compliance date of July 8, 2024, that requires wireless providers to use secure customer-authentication methods before transferring a number to a new SIM card or a new carrier. The FCC’s announced effective date set the point at which carriers had to have those protections in place across their networks, including resellers and smaller providers that ride on the major networks.
The rules also require carriers to alert customers when a SIM change or port request is made on their account, a warning meant to give the real owner a chance to intervene before the transfer completes. The full text of the FCC order lays out these obligations, but a notification only works if the customer sees it and responds fast, and in practice the takeover can happen in minutes. That is why regulators frame the carrier rules as a floor, not a substitute for account-holder precautions.
The carrier PIN and number lock that block a transfer
The most effective defenses are settings on the wireless account itself. Every major carrier lets customers add a separate PIN or passcode that must be provided before any SIM change or port can go through, and setting one that differs from other passwords stops a scammer armed with a name, address and date of birth from talking a representative into a transfer. Many carriers also offer a number lock, sometimes called a port freeze, that must be switched off before the number can move at all, adding a second barrier that a remote attacker cannot easily clear.
The other decisive step is retiring text-message codes for the accounts that matter most. The FTC recommends that account holders use an authentication app or a physical security key instead of SMS for banking and email, because a code generated inside an app on the device is not tied to the phone number and cannot be intercepted through a SIM swap. Email deserves the same protection, since a compromised inbox is often the doorway attackers use to reset every other account.
The warning signs that a takeover is underway
Speed of response matters because the theft announces itself if anyone is watching for it. A phone that suddenly shows “no service” or “SOS only” in an area with normal coverage, an unexpected message that a SIM or number change was requested, or an inability to make calls and texts can all signal that a number has been ported away. The FTC advises anyone who suspects a swap to contact the carrier immediately to reclaim the number, and to alert banks before the intruder can move money.
The larger point for older savers is that phone security and financial security have merged. A wireless account is no longer just a line of communication; it is a master key to bank logins, brokerage transfers and benefit portals. Locking down the carrier account with a PIN and a number freeze, and shifting critical logins off text codes, closes the exact path these thieves rely on, and it costs nothing but a few minutes with each provider.
This article was researched and drafted with the assistance of AI and reviewed by The Money Overview editorial team.
More Financial Reading