Protection
Account Takeover Often Starts With The Phone Number
Control of a phone number defeats most text-based account recovery, which is why porting and SIM swap attacks precede a large share of financial account takeovers.

A phone number has quietly become the master key to financial accounts. It receives the codes, it authorizes the resets, and it can be taken without touching any of those accounts.
Why the number carries so much authority
Text message verification became the default second factor because almost everyone has a phone and no additional setup is required.
Account recovery followed. A forgotten password is commonly reset by sending a code to the number on file, which makes the number a credential rather than a contact detail.
The number is also widely known. It appears on forms, in breached datasets and in public records, so it is not secret in the way a password is.
How control of a number is taken
A port-out moves a number to a different carrier, a routine process designed to let customers switch providers without losing their number.
A SIM swap reassigns the number to a new device on the same carrier, usually by convincing customer service that the request is legitimate.
Both attacks target the carrier rather than the bank, and neither requires any access to the financial accounts that will later be reached.
What happens after the number moves
The original phone loses service, which is the clearest signal something is wrong and is frequently mistaken for a network outage.
Meanwhile the codes go to the attacker's device. Password resets on email, banking and brokerage accounts proceed in sequence, each one enabling the next.
Email is usually taken first because it is the recovery channel for everything else, which turns a single compromised number into access across accounts.
Defenses that address the carrier layer
Carriers generally offer a port-out PIN or a number lock, set on the mobile account, which blocks transfers unless the credential is supplied.
Those controls are opt-in. An account left at default settings relies on the carrier representative correctly refusing a well-prepared social engineering attempt.
Reducing dependence on the number matters as much. Authenticator applications and hardware security keys are not tied to the carrier at all.
What to do when it happens
Speed determines the outcome, because the attacker is working through a chain of accounts and each one takes time.
Contacting the carrier to reverse the transfer and the financial institutions to freeze activity are simultaneous tasks, not sequential ones.
Liability for the resulting transactions depends on the type of account, the payment method and the applicable rules, which vary and change. Where substantial sums are involved, an attorney is the right next step alongside reports to the institutions and law enforcement.
Questions readers ask
Does a credit freeze stop card fraud?
No. It blocks new applications in your name. Fraud on an existing card or an account takeover is unaffected, and needs account security measures instead.
Do I need to freeze with every agency?
Yes, where a freeze is available. Each agency is separate, and a lender consulting an unfrozen agency will proceed normally.





