Federal prosecutors have now charged phone company insiders and outside accomplices in schemes that hijacked customer phone numbers to intercept bank verification codes sent by text. In one case out of the Eastern District of Louisiana, a former carrier employee helped attackers target at least 19 customers, rerouting their numbers so that one-time passcodes flowed straight to criminals. The cases expose a gap that no single institution controls: once a number moves to a new device, banks keep sending SMS codes to whoever holds it.
How port-out fraud breaks SMS banking codes
The mechanics are straightforward and fast. A criminal convinces or bribes a carrier employee to transfer a victim’s phone number to a SIM card the attacker controls. Court filings in a New Jersey federal case describe SIM swapping as an unauthorized takeover that links a victim’s number to a device in the attacker’s hands. Calls and texts, including the short-lived codes banks send for login or wire-transfer approval, then arrive on the criminal’s phone instead of the account holder’s.
The FBI’s Internet Crime Complaint Center has warned that criminals are increasing these schemes to steal millions of dollars from the American public. The bureau’s advisory spells out the result: once a number is swapped, account providers send one-time passcodes by text to the victim’s number, which is now controlled by the criminal. That single redirect can unlock email, banking, and cryptocurrency accounts that rely on SMS-based two-factor authentication.
Carrier insiders and the single-factor weak point
Prosecutions show that insider access is a reliable entry point for attackers. In the Eastern District of Louisiana, prosecutors charged a former phone company employee who allegedly performed SIM swaps on behalf of a co‑conspirator, targeting at least 19 customers by abusing his insider access. A separate indictment in New Jersey charged a Burlington County man in a similar cell phone SIM swap scheme that relied on carrier-level changes to redirect victims’ numbers. Both cases illustrate how a single cooperating employee inside a carrier can bypass whatever customer-facing security the company advertises.
The pattern points to a structural problem. Carriers that still approve port-out requests through voice calls or basic knowledge-based questions give insiders and social engineers a short path to success. Once a dishonest worker or persuasive caller is on the line, they can override safeguards that would stop an ordinary customer from moving a number. Banks, meanwhile, cannot unilaterally stop SMS delivery once a number has already been transferred. They keep sending codes to the phone number on file, unaware that it now sits in someone else’s pocket. That split responsibility between carriers and financial institutions is exactly the seam attackers exploit.
Federal standards flag SMS but banks still depend on it
Federal technical guidance already treats SMS verification as a known risk. The National Institute of Standards and Technology’s digital identity guidance in Special Publication 800‑63B restricts use of the public switched telephone network, including SMS and voice channels, for out‑of‑band verification. The same standard directs verifiers to check risk indicators such as device swap, SIM change, and number porting before sending a one-time secret, and to consider alternative authenticators where telephone-based methods are vulnerable.
Bank supervisors have echoed those concerns. Interagency guidance posted by the Federal Reserve on authentication and access to financial institution services warns that certain multi-factor approaches can be exposed to interception or redirection attacks. The document highlights that out‑of‑band codes delivered over channels like text messaging may not provide strong assurance when the underlying phone number can be taken over, and urges institutions to evaluate threats such as man‑in‑the‑middle and session hijacking in their choice of controls. In particular, the interagency guidance stresses that authentication should be layered and risk‑based, not treated as a one‑size‑fits‑all solution.
Yet banks and fintech firms still lean heavily on SMS because it is cheap, familiar to customers, and already integrated into many legacy systems. For lower-risk transactions, some institutions view texted codes as an acceptable compromise between usability and security. Others have added app-based prompts or hardware tokens for high-value transfers but left SMS in place as a backup, which attackers can then target as the weakest link. The result is a patchwork in which the most convenient factor often remains the least resistant to takeover.
Closing the seam between carriers and banks
Reducing SIM swap fraud will require changes on both sides of the carrier–bank divide. Mobile providers can raise the bar for port-out approvals by requiring in‑store identity checks, separate PINs for account changes, and automated alerts before a number is moved. Stronger internal controls on employee access, including monitoring of unusual SIM-change patterns, can make it harder for insiders to operate undetected.
Financial institutions, for their part, can treat SMS codes as a fallback rather than a primary security measure. Risk-based authentication that looks at device history, geolocation, and behavioral signals can help flag suspicious logins even when the correct code is entered. Encouraging customers to adopt app-based authenticators or physical security keys, and reserving SMS for exceptional cases, would align practice more closely with federal guidance. Until then, the combination of hijacked phone numbers and one-time passcodes will remain a lucrative opening for criminals willing to exploit the weakest point in the chain.