Skip to main content

The Money Overview

Port-out scammers steal your phone number to intercept the codes guarding your bank

The money at stake in a phone-number takeover is roughly everything a bank account will let a thief move in a single afternoon. Criminals who never lay a finger on a victim’s handset can still capture the one-time security codes that a bank, brokerage, or retirement account sends by text before releasing a transfer, then drain the balance while the account holder stares at a phone showing no signal. Federal regulators track the tactic under two names, and both convert an ordinary mobile number into a skeleton key for a retiree’s finances.

How a hijacked number captures a bank’s security codes

The first version is called port-out fraud. A criminal armed with a victim’s name, address, and a few stolen personal details contacts a wireless carrier, poses as the customer, and requests that the number be transferred to a different account or provider. Once the port goes through, every call and text meant for the victim rings on the thief’s device instead. The legitimate owner’s phone goes dark at the same moment.

The second version, SIM swapping, reaches the same result by a different route: the scammer convinces the carrier to move the number onto a SIM card the criminal physically controls. Either way, the text-message codes that banks rely on for two-factor verification start arriving in the wrong hands. From there the attacker triggers password resets on email and financial accounts, catches the confirmation codes, and locks the real owner out.

With those codes in hand, a thief can log into a checking account, authorize a wire, drain a savings balance, or open new credit in the victim’s name. Older adults are frequent targets because they tend to hold larger account balances and are more likely to rely on a single primary phone number tied to every login. The theft often unfolds in minutes, faster than a person can reach a bank branch.


Free retirement updates: Scam calls targeting retirees change every week. The free Retirement Shield newsletter flags the ones going around and the one tell that stops each. Sign up free.

The sudden dead zone that signals a takeover in progress

The clearest warning sign costs nothing to notice: a phone that abruptly loses service. A handset that drops to “No Service” or “SOS only” in an area with normal coverage, and stays there while calls and texts stop arriving, is often the exact moment a number has been moved to someone else’s control. The silence is not a network glitch; it is the theft happening in real time.

Other tells cluster around the same window. A carrier may send a notice that a SIM change or number transfer was requested. Email and banking apps may suddenly reject the correct password. Alerts warning that an account was accessed from an unfamiliar device may pile up. Because the criminal is racing to reset logins before anyone reacts, the minutes immediately after service dies are the ones that matter most.

The right first move is to reach the carrier from a different phone, report the number as compromised, and demand it be restored and locked. Contacting the bank to freeze transfers comes next. Victims can also document the fraud and begin recovery through the Federal Trade Commission’s identity theft recovery service, which generates a step-by-step plan for disputing charges and restoring accounts.

The carrier PIN and number lock that stop the theft

The strongest defense is a separate account passcode, sometimes called a port-out PIN or transfer PIN, set directly with the wireless carrier. This code is distinct from the passcode that unlocks the phone screen, and the carrier is supposed to require it before authorizing any transfer of the number. A criminal holding stolen personal data but not that PIN hits a wall.

Major carriers also offer number-lock or port-freeze settings that block any transfer request until the customer deliberately turns the lock off. Enabling that feature removes the carrier employee’s ability to be talked into a port by a convincing impersonator. The setting sits inside account security menus and takes only a few minutes to switch on.

The deeper fix is to stop depending on text messages for security codes at all. Moving two-factor verification to an authenticator app or a physical security key means a stolen number no longer delivers anything useful, because the codes never travel over the phone network. Banks and brokerages increasingly support both options.

What makes the crime so damaging is the mismatch between the cost of the defense and the size of the loss. A free PIN and a toggled lock can stand between a retiree and an emptied account, yet carriers still approve transfers on the strength of information that data breaches have made cheap to obtain. Until that verification standard tightens, the burden of locking the number down falls squarely on the account holder, and the ones who never set the PIN are the ones the thieves are counting on.

This article was produced with AI assistance and reviewed by The Money Overview editorial team.

More Financial Reading