Your phone was never touched. Your number was moved.
There is a version of account theft where nothing gets broken into. No password is cracked, no malware is installed, and your handset never leaves your pocket. Someone simply persuades your mobile carrier that they are you, and your number is assigned to a SIM in their phone.
From that second, every code sent to you by text arrives with them. And there are two settings people reach for to prevent it, with confusingly similar names. Only one of them works.
A SIM PIN does not stop a SIM swap. It locks the SIM card inside your handset, and this attack never touches your handset. The control that works is held at your mobile carrier, usually called a number transfer lock, port-out lock or account lock. It is free on every major US carrier, it lives in the carrier's app rather than your phone settings, and on most accounts it is switched off until you turn it on.
Nothing failed. That is the problem
The instinct is to ask what was hacked. The answer is nothing, and holding onto that is what makes the rest of this make sense.
A port-out is not an intrusion. It is a substitution. The attacker does not defeat your bank's security, they satisfy it. Every check still runs, every check still passes, and every check passes for someone else.
Read that column again. At no point does anything read as an error, because nothing is an error. The system was asked whether the person holding the number is the account owner, and the honest answer, by the only definition the system has, is yes.
The two locks
This is where the practical mistake happens, and it is an easy one to make because both controls sound like they protect the same thing.

The naming is genuinely part of the problem. Every major carrier is required to offer this kind of protection, but each one calls it something different, so there is no single phrase to search for and no shared vocabulary between the advice you read and the menu you are looking at.
AT&T calls its version Wireless Account Lock, describes it as free, and puts the toggle in the myAT&T app. In AT&T’s own words it “disables several key account changes including billing updates or wireless number transfers” and “prevents anyone from buying a device on the account, for example, or conducting a SIM swap.” On other carriers the equivalent exists under a different name. Look in the carrier’s app for a setting that mentions porting, number transfer or locking the account, and treat anything labelled SIM PIN in your phone’s settings as a different control that will not do this job.
The protection is free, required, and switched off
At its meeting on 15 November 2023, the FCC adopted rules aimed specifically at SIM swap and port-out fraud, requiring wireless providers to use secure methods to authenticate customers before making SIM changes, and to maintain a clear process for reporting and remediating fraud. The compliance date was 8 July 2024.
So the controls exist because regulation put them there. What regulation did not do is switch them on. A provider being required to offer secure authentication is not the same as your account having the lock enabled, and the gap between those two things is the entire operating space for this attack.
What to do tonight
Two jobs, in this order. First make the number harder to move. Then make it worth less if it moves anyway.
The order matters more than it looks. People protect the bank first because that is where the money is, but the attacker does not need the bank if they hold the email that can reset it.
The sentence the attack needs you to ignore
Once the lock is on, there is exactly one thing standing between it and an attacker: a phone call or a message asking you to turn it off. Which is presumably why AT&T published this line on its own site, in the same announcement:
“Just like you’d never give someone your password or a one-time PIN code over the phone, please know that AT&T will never call or text you and ask you to turn off Wireless Account Lock.”AT&T, 1 JULY 2025
That is a published never-statement, and it is the useful kind. It does not ask you to judge whether a caller sounds convincing. It gives you a rule you can check against a company’s own words: a request to remove the protection is, by the carrier’s own account, never something the carrier makes. We keep a running list of statements like it in the Impersonation Index, because a published never-statement turns an impossible job, spotting a convincing fake, into an easy one.
If your carrier is not AT&T, the same logic holds even where the wording is theirs rather than published. No carrier needs you to disable your own account security in order to help you.
If it has already happened
Speed is the whole game, and the first move is not the bank. From a device that is not the affected phone, take back the email account, then work outward. Contact the carrier and ask them to reverse the transfer and document it, which the FCC rules require them to have a process for. Then report it, and if accounts were opened or money moved, use IdentityTheft.gov ↑ which produces a personalised recovery plan rather than a generic checklist.
The uncomfortable part of this one is also the reassuring part. Nothing about it required you to be careless, because the attack never went through you at all. It went around you, to a company that holds something you have always assumed was yours, and moved it.