The Credit QuestionBorrowing, scored and explained

Protection

Account Takeover Often Starts With The Phone Number

Control of a phone number defeats most text-based account recovery, which is why porting and SIM swap attacks precede a large share of financial account takeovers.

Person using a smartphone and credit card for online shopping or payment.
Photograph by Tima Miroshnichenko via Pexels
General information. This is journalism, not personalised financial advice. Figures, rates and rules change and vary by country — check current terms before acting. How we work.

A phone number has quietly become the master key to financial accounts. It receives the codes, it authorizes the resets, and it can be taken without touching any of those accounts.

Why the number carries so much authority

Text message verification became the default second factor because almost everyone has a phone and no additional setup is required.

Account recovery followed. A forgotten password is commonly reset by sending a code to the number on file, which makes the number a credential rather than a contact detail.

The number is also widely known. It appears on forms, in breached datasets and in public records, so it is not secret in the way a password is.

How control of a number is taken

A port-out moves a number to a different carrier, a routine process designed to let customers switch providers without losing their number.

A SIM swap reassigns the number to a new device on the same carrier, usually by convincing customer service that the request is legitimate.

Both attacks target the carrier rather than the bank, and neither requires any access to the financial accounts that will later be reached.

What happens after the number moves

The original phone loses service, which is the clearest signal something is wrong and is frequently mistaken for a network outage.

Meanwhile the codes go to the attacker's device. Password resets on email, banking and brokerage accounts proceed in sequence, each one enabling the next.

Email is usually taken first because it is the recovery channel for everything else, which turns a single compromised number into access across accounts.

Defenses that address the carrier layer

Carriers generally offer a port-out PIN or a number lock, set on the mobile account, which blocks transfers unless the credential is supplied.

Those controls are opt-in. An account left at default settings relies on the carrier representative correctly refusing a well-prepared social engineering attempt.

Reducing dependence on the number matters as much. Authenticator applications and hardware security keys are not tied to the carrier at all.

What to do when it happens

Speed determines the outcome, because the attacker is working through a chain of accounts and each one takes time.

Contacting the carrier to reverse the transfer and the financial institutions to freeze activity are simultaneous tasks, not sequential ones.

Liability for the resulting transactions depends on the type of account, the payment method and the applicable rules, which vary and change. Where substantial sums are involved, an attorney is the right next step alongside reports to the institutions and law enforcement.

Questions readers ask

Does a credit freeze stop card fraud?

No. It blocks new applications in your name. Fraud on an existing card or an account takeover is unaffected, and needs account security measures instead.

Do I need to freeze with every agency?

Yes, where a freeze is available. Each agency is separate, and a lender consulting an unfrozen agency will proceed normally.

Protectionfreezesfile locksfraud preventionidentity
Nadine Okoro
Editor, The Credit Question

Nadine edits The Credit Question after nine years assessing consumer lending applications.

Also by Nadine Okoro