Call‑forwarding, voicemail, and “number‑sharing” features that mirror your phone number across watches, tablets, and laptops are convenient. They also create hidden paths for attackers to intercept one‑time passcodes (OTPs), password reset links delivered by voice, and security alerts. This guide explains how these features work, how criminals abuse them for account takeover, and the exact settings you can change today to close the gaps without giving up essential functionality.
How Call‑Forwarding and Number‑Sharing Enable Takeovers
When you reset a password or sign in, companies often send a code by SMS, voice call, or both. If your calls or messages can be mirrored or re‑routed, that code may reach a device or destination you didn’t expect. Attackers aim to quietly add or modify forwarding rules, connect an extra device to your number, or exploit shared-line features in families and business accounts. Once they receive a code meant for you, they can reset passwords, add their own authenticators, and lock you out.
Common Risk Scenarios
- Unnoticed call forwarding: Conditional forwarding (busy, no answer, unreachable) is left on after travel or troubleshooting. A forgotten forward sends password reset calls to a different number.
- Number sharing to extra devices: Features like “calls on other devices,” “NumberSync,” “Call & Text on Other Devices,” or “link to Windows/macOS/watch” mirror calls and sometimes SMS/voicemail to additional hardware. A lost, sold, or borrowed device may still receive codes.
- Business or family plans: Shared voicemail boxes, receptionist forwarding, or hunt groups route calls broadly. A compromised coworker account can receive your reset calls.
- Voicemail fallback: If a code-by-call reaches voicemail, weak or default PINs (or visual voicemail access) can expose your OTP.
- eSIM and dual‑SIM complexity: Multiple lines on one phone can mirror calls and messages in ways that are easy to forget, especially after device migrations.
Quick Diagnostic: Are You Exposed Right Now?
Take five minutes to check for silent forwarding and extra device endpoints:
- Call forwarding status: In your phone app settings, review unconditional and conditional call forwarding (no answer, busy, unreachable). Ensure they are off unless required.
- Carrier account devices: Log in to your carrier account. Review “linked devices,” “companion devices,” “NumberSync,” or “calls on other devices.” Remove anything you do not actively use.
- Voicemail security: Set a unique voicemail PIN, disable default PIN, and turn off “skip PIN when calling from my number.”
- Platform mirroring: On iOS, macOS, Android, and Windows, review features like “Calls on Other Devices,” “Text Message Forwarding,” “Link to Windows,” or “Phone Link.” Disable mirroring you don’t need.
- Recovery pathways: In email, banks, and key accounts, confirm your recovery phone number and email are correct, and remove old or unfamiliar ones.
Best Practices to Prevent OTP and Reset Call Interception
These practices reduce the chance that a forwarded call, mirrored device, or shared voicemail exposes your codes.
1) Prefer Authenticator Apps and Passkeys Over SMS/Voice Codes
- Use app-based TOTP (e.g., an authenticator) or hardware security keys where available. These do not rely on your phone number.
- Enable passkeys on accounts that support them; they resist phishing and phone-number attacks.
- Keep SMS/voice as backup only, not your primary second factor.
2) Minimize and Control Call Forwarding
- Turn off unconditional forwarding by default. Only use it temporarily and to a number you control.
- Audit conditional forwarding (busy, no answer, unreachable). If you must keep it, verify the destination monthly and after any carrier support call.
- Use device-level DND/Focus instead of forwarding when you simply need quiet.
- Document legitimate forwarding (e.g., travel). Set a reminder to disable it when you return.
3) Lock Down Number‑Sharing and Mirroring
- iOS/macOS: Settings > Phone > Calls on Other Devices: turn off for devices you don’t fully control. Settings > Messages > Text Message Forwarding: allow only trusted, current devices.
- Android/Windows: Review Phone Link/Link to Windows permissions and turn off call/SMS relaying you don’t need.
- Wearables and tablets: Remove cellular plans from devices you no longer use. Unpair watches before selling or gifting.
- Carrier portals: Disable “number sync,” “digits,” or similar multi‑device features unless necessary.
4) Secure Voicemail Thoroughly
- Strong, unique PIN that is not reused elsewhere. Avoid birthdays or repeating digits.
- Disable PIN bypass that trusts calls from your own number; caller ID can be spoofed.
- Check greetings and messages for unfamiliar activity. Some attackers change the greeting to hide missed call alerts.
- Avoid voicemail for password resets where possible. If a service offers SMS/app/email instead of voice, prefer those.
5) Harden Your Carrier Account
- Add a carrier account PIN/passcode that is required for changes (including forwarding, number sharing, and SIM changes).
- Enable high‑security notes/flags with your carrier. Ask that changes require in‑person verification or multiple factors when available.
- Review recent changes after any suspicious activity or support call. Confirm no new forwarding rules or devices were added.
6) Isolate Critical Accounts From Your Main Number
- Use a dedicated number (e.g., a second SIM/eSIM or VoIP line you control) solely for account recovery and 2FA, not shared publicly.
- Do not enable forwarding or sharing on that dedicated line. Keep it private and locked down.
- Periodically test that recovery codes arrive only on the expected device.
7) Control Who Can Change Your Settings
- Lock your phone with a strong passcode; disable lock‑screen access to control center and settings that could toggle forwarding in a hurry.
- Guard carrier credentials. Use a password manager and unique passwords for the carrier portal and app.
- Beware social engineering: Attackers may pose as you to carrier support. Know your account PIN and “do not disclose” it in calls you did not initiate.
Step‑by‑Step: Checking and Disabling Forwarding on Your Devices
Exact menus vary by device and carrier, but these steps help most users locate forwarding and sharing features.
On iPhone
- Open Settings > Phone > Call Forwarding. Turn off. If you see a destination number you don’t recognize, take a screenshot and contact your carrier.
- Settings > Phone > Calls on Other Devices. Turn off for all but your current, trusted devices.
- Settings > Messages > Text Message Forwarding. Allow only devices you physically control.
- Phone app > Voicemail: Set or change your PIN via your carrier’s voicemail settings; disable “skip PIN” options.
On Android (varies by manufacturer)
- Phone app > Settings > Calling accounts/Carrier call settings > Call forwarding. Disable unconditional and conditional forwarding entries.
- Phone app > Voicemail > Settings. Set a strong PIN; disable any “trust this device” bypass.
- Settings > Connected devices or Link to Windows/Phone Link. Disable call and message relaying you don’t need.
With Your Carrier
- Log in to your carrier account. Review linked or companion devices, shared lines, and forwarding services. Remove anything unfamiliar.
- Add or confirm your account security PIN and request a high‑security flag if offered.
- Call support from a known number and ask them to confirm no unconditional or conditional forwarding is active on your line.
Recognize Red Flags of Call‑Based Account Takeover
- Silent missed calls you never saw, but that appear in your carrier call detail records.
- Unexpected password reset emails shortly after you missed a call or saw a “ring once” event.
- Visual voicemail messages for services you did not contact.
- New devices listed under carrier “linked devices” or platform “calls/messages on other devices.”
What to Do If You Suspect Abuse
- Disable all forwarding and linked device features on your phone and in the carrier account portal.
- Change your voicemail PIN and disable PIN bypass immediately.
- Rotate 2FA methods on critical accounts to authenticator apps or passkeys; remove your phone number as a factor where possible.
- Reset carrier and email passwords and enable strong MFA for both. Your email often controls resets for everything else.
- Review account recovery details across banks, email, cloud storage, social media, and financial services. Remove unknown numbers and emails.
- Monitor for new activity—transactions, new credit lines, or sign‑ins from unfamiliar locations.
Special Considerations for Families and Small Businesses
- Avoid shared voicemail for numbers used with financial or administrative accounts.
- Use role‑based numbers (e.g., a separate line for customer calls) and keep the administrator’s recovery number private and unshared.
- Document forwarding rules used for coverage hours and require approval for any changes.
- Require MFA on the carrier portal for all lines and assign unique logins per person with least‑privilege access.
Layered Monitoring for Early Warning
Even with forwarding and number‑sharing locked down, it’s wise to watch for downstream identity risks that follow account takeovers, like fraudulent credit applications or new accounts opened in your name. Adding continuous credit and identity monitoring helps you spot these signals early so you can act fast. If you want an easy place to start, see our overview of tools that combine privacy, credit monitoring, and identity alerts: SmartCredit for privacy, credit monitoring, and identity protection.
Maintenance Checklist (Do This Quarterly)
- Confirm all call‑forwarding settings are off or correctly configured.
- Review linked devices on phones, computers, watches, tablets, and carrier accounts.
- Change voicemail PIN and ensure bypass is disabled.
- Test a password reset on a non‑critical account to verify the code only reaches your intended device or method.
- Reassess which accounts still use SMS/voice and migrate them to app‑based MFA or passkeys.
Conclusion
Call‑forwarding and number‑sharing are helpful, but they expand the routes your security codes can travel. By auditing forwarding rules, pruning mirrored devices, strengthening voicemail, and prioritizing app‑based MFA or passkeys, you remove the most common paths attackers use to take over accounts. Make these checks part of your routine, and keep a dedicated, tightly controlled recovery channel for your most important logins. Small changes now can prevent costly lockouts and identity fraud later.
Good to Know
If you must keep call forwarding on, set it only for trusted scenarios and verify the destination number every month. Attackers sometimes change just one digit to silently capture password reset calls.