Your mobile number is more than a way to call or text—it’s a recovery key for bank logins, email accounts, and two-step verification codes. Criminals know this, which is why SIM swaps and unauthorized ports have become common routes to steal accounts and money. This guide explains how these attacks work, the red flags to catch them early, and the exact steps to lock your number with your carrier so your identity stays in your hands.
What Is a SIM Swap and an Unauthorized Port?
Both attacks move your phone number away from the SIM card in your phone to one controlled by a criminal.
- SIM swap (SIM hijack): An attacker convinces your carrier to activate a new SIM on your line. Your phone loses service while their phone starts receiving your calls and texts.
- Unauthorized port-out: The attacker transfers (ports) your number from your current carrier to a different one. If successful, your number leaves your account entirely.
In both cases, the goal is to intercept one-time passcodes and password resets, then drain financial accounts, breach email, and lock you out.
How Attackers Pull It Off
Attackers combine exposed personal information with social engineering to impersonate you. Common ingredients include:
- Leaked data: Name, address, date of birth, and the last four of SSN often appear in old data breaches or on data broker sites.
- Public profiles: Details from social media (employment, hometown) that help answer knowledge-based questions.
- Phishing and vishing: Fake texts, emails, or calls that trick you into revealing one-time codes, account PINs, or carrier login credentials.
- Weak carrier protections: If your account lacks a strong PIN or transfer lock, a smooth-talking fraudster can push through changes.
Early Warning Signs You Shouldn’t Ignore
- Sudden loss of cellular service: Calls go straight to voicemail and texts stop, while others around you still have service.
- Notifications about SIM or line changes: You receive emails or texts from your carrier about a SIM change, port request, or account update you didn’t make.
- Unfamiliar MFA prompts: Your email or financial apps ask for verification you didn’t initiate.
- Account lockouts: Passwords inexplicably stop working across email, cloud storage, or bank apps.
If any of these happen, act immediately using the steps in the next section.
Immediate Steps if You Suspect a SIM Swap or Port-Out
- Call your carrier from another phone and report a suspected SIM swap or port-out. Ask to freeze your line, disable eSIM changes, and require in-store ID verification for any future changes.
- Change your carrier account passcode/PIN and your account password. Do this over a secure channel or official website, not through links in texts.
- Secure critical accounts (email first, then banks and crypto). Change passwords and revoke active sessions. Switch two-factor authentication (2FA) to an app-based or hardware key method.
- Check recovery options in email and financial accounts. Remove phone-number SMS as the primary reset method and add backup codes or a security key where available.
- Contact your bank and card issuers to flag the account and monitor or temporarily lock transactions if needed.
- File reports with your carrier’s fraud team and your local authorities if funds were stolen. Preserve logs, messages, and timestamps.
Locking Down Your Mobile Account: Core Protections
Every major carrier offers security features that block or slow SIM swaps and ports. Turn on all of the following:
- Strong account password and unique passcode/PIN: Use a long, random password for the carrier login and a distinct numeric PIN for phone support. Avoid birthdays or repeats.
- Number transfer lock (port freeze): A carrier-level setting that blocks ports and transfers until you remove the lock. This is one of the strongest defenses.
- Account change notifications: Enable SMS and email alerts for SIM changes, eSIM downloads, plan updates, and logins.
- In-store verification requirement: Ask your carrier to require a government ID and your PIN for any SIM or line changes made in-store.
- Limit eSIM changes: Where supported, require a one-time code in the carrier app before activating a new eSIM.
Step-by-Step: Enabling Protective Settings with Major Carriers
The exact names vary by brand and region, but the protections are similar. If you don’t see these options in your account, call customer support and request them.
AT&T (including AT&T Prepaid)
- Set or update your Wireless Passcode and ensure a strong myAT&T password.
- Enable a Port Validation/Number Transfer Lock for each line to prevent unauthorized ports.
- Turn on Account Activity Alerts for SIM changes, logins, and plan updates.
- Ask support to require in-store ID verification for SIM swaps.
T-Mobile (including Metro by T-Mobile)
- Create a strong Account PIN/Passcode and set a separate online account password.
- Enable Number Transfer Lock in the T-Mobile app for each line.
- Turn on Login and Change Alerts (text and email).
- Request in-store ID checks for SIM/eSIM changes and consider limiting eSIM activations through the app.
Verizon (including Verizon Prepaid and Visible)
- Set a unique Account PIN and strong My Verizon password.
- Enable Number Transfer Pin protection/Port Freeze to block unauthorized ports.
- Turn on Security Notifications for SIM, eSIM, and account changes.
- Ask support to require government ID for any store-based SIM swap.
Google Fi
- Use a strong Google Account password and app-based or hardware key 2FA.
- Enable Fi’s Number Lock/Porting Lock to block transfers.
- Turn on Security Alerts and review connected devices regularly.
Other and Regional Carriers
- Call support and ask for a port freeze/number transfer lock and whether they can restrict SIM changes without in-store ID.
- Set a service PIN and ensure alerts are enabled on email and SMS.
Harden Your Logins Beyond SMS Codes
Even with a locked line, treat SMS as a backup, not your primary defense. Stronger options reduce the fallout if your number is ever compromised.
- Use app-based 2FA (e.g., authenticator apps) for banks, email, and cloud accounts. Favor apps that support encrypted cloud backup or device transfer codes.
- Adopt hardware security keys for critical accounts that support them. They resist phishing and SIM-based interception.
- Store and rotate backup codes in a password manager or secure physical storage. Remove old devices from your account’s trusted device list.
- Update recovery methods to emphasize email or security keys. Avoid relying on your mobile number as the sole reset path.
Reduce the Data Fueling Social Engineering
The less personal information attackers can reference, the harder it is to impersonate you with a carrier. Take simple steps to shrink your exposure:
- Remove your data from people-search sites that list addresses, phone numbers, and family ties.
- Limit public profile details (birthdates, hometowns, employer lists) and lock down privacy settings on social platforms.
- Use unique, long passwords and a trusted password manager; never reuse your carrier credentials on other sites.
- Be skeptical of urgent texts and calls claiming to be from your carrier. Hang up and call the number on your bill or the official website.
Routine Checkup: A 15-Minute Security Audit
Put these tasks on a quarterly calendar reminder:
- Review carrier settings: Confirm your number transfer lock and account PIN are still enabled and unchanged.
- Test alerts: Ensure email and SMS notifications for account changes still arrive.
- Scan account logins: In your email and bank accounts, remove old devices and sessions.
- Rotate passwords for your carrier account if it appears in breach alerts or has not changed in a year.
- Review 2FA to prefer authenticator apps or hardware keys over SMS, and refresh backup codes.
If You’ve Already Experienced a SIM Swap
Act quickly to contain damage and document the incident:
- Get your number back through carrier fraud support; ask them to note the account and apply a transfer lock.
- Reset passwords for email, banks, crypto, and any accounts that used SMS for logins.
- Check for new forwarding rules in email and phone settings that could siphon messages and calls.
- Monitor for financial and identity misuse: Look for new credit inquiries, loans, or card openings you didn’t authorize.
- Place a fraud alert or credit freeze with the credit bureaus if you see suspicious activity.
Ongoing monitoring helps you catch follow-on fraud. For credit and identity-related activity, consider a dedicated monitoring service that alerts you to changes in your credit reports and high-risk events. If you’re building a layered defense, you can review options like SmartCredit for privacy, credit monitoring, and identity protection to stay informed.
FAQs
Is a number transfer lock the same as a port freeze?
Yes—different carriers use different names, but both block your number from moving to another carrier until you remove the lock inside your account or with support.
Can an attacker still SIM swap me if I have a strong PIN?
A strong PIN stops most fast attempts, but determined attackers may target weak store processes or compromised employee accounts. That’s why combining a transfer lock, strong PIN, in-store ID requirements, and non-SMS 2FA provides the best protection.
Is app-based 2FA safe if my phone is stolen?
Use a device screen lock, biometric unlock, and remote-wipe capability. Choose an authenticator that supports secure backups or transfer codes so you can recover without relying on your number.
Should I remove my phone number from all accounts?
Keep it as a backup where required, but prefer app-based 2FA or hardware keys as the primary method. Also ensure account recovery can happen via email or backup codes, not just SMS.
Do prepaid plans have these protections?
Yes. Prepaid accounts can enable account PINs and transfer locks. Contact your specific provider if you don’t see the option online.
Checklist: Lock Your Line Today
- Create a long, unique carrier account password and a separate, strong support PIN.
- Enable a number transfer lock/port freeze for each line.
- Turn on alerts for SIM changes, logins, and account updates.
- Ask your carrier to require in-store ID for SIM swaps.
- Move key accounts to app-based or hardware-key 2FA and update recovery options.
- Reduce public exposure of your personal information and remove data from people-search sites.
- Schedule a recurring 15-minute security checkup.
Conclusion
Your phone number can unlock—or expose—your digital life. By enabling a transfer lock, using a strong account PIN, requiring in-person verification for SIM changes, and shifting away from SMS-based logins, you close the most common paths criminals use for SIM swaps and unauthorized ports. Pair these steps with regular checkups and identity monitoring so you can catch problems early, respond quickly, and keep control of your accounts and your privacy.
Good to Know
Your phone number is a master key for password resets. If attackers move your number to their SIM, they can intercept texts and one-time codes. Adding a transfer lock and a strong account PIN blocks most fast-takeover attempts.