NOTHING WAS HACKED

Your phone was never touched. Your number was moved.

There is a version of account theft where nothing gets broken into. No password is cracked, no malware is installed, and your handset never leaves your pocket. Someone simply persuades your mobile carrier that they are you, and your number is assigned to a SIM in their phone.

From that second, every code sent to you by text arrives with them. And there are two settings people reach for to prevent it, with confusingly similar names. Only one of them works.

The short answer

A port-out is your phone number being moved to a different carrier, and a SIM swap is it being moved to a different SIM at the same carrier. In both, the attacker asks the carrier, not your phone, so a SIM PIN does not stop either. The control that works is held at your carrier: Verizon calls it Number Lock, AT&T calls it Wireless Account Lock, T-Mobile calls it Account Takeover Protection. All three are free, all three live in the carrier's app or account rather than your phone settings, and none is switched on for you. Port-out protection is that switch.

Nothing failed. That is the problem

The instinct is to ask what was hacked. The answer is nothing, and holding onto that is what makes the rest of this make sense.

A port-out is not an intrusion. It is a substitution. The attacker does not defeat your bank's security, they satisfy it. Every check still runs, every check still passes, and every check passes for someone else.

The check
Your bank sends a one-time code to the number on file.
What it concludes
The code was delivered to the registered number, and it came back correct.
VERDICT: IDENTITY CONFIRMED
The check
Your email provider offers to text you a reset link.
What it concludes
The link went to the number the account owner registered.
VERDICT: IDENTITY CONFIRMED
The check
A payment app asks you to verify a new device by SMS.
What it concludes
Verification succeeded on the first attempt.
VERDICT: IDENTITY CONFIRMED

Read that column again. At no point does anything read as an error, because nothing is an error. The system was asked whether the person holding the number is the account owner, and the honest answer, by the only definition the system has, is yes.

You are not locked out because something failed. You are locked out because it worked, and the definition of “you” that it worked on is a phone number that now belongs to someone else.

The two locks

This is where the practical mistake happens, and it is an easy one to make because both controls sound like they protect the same thing.

A schematic comparing two protections. On the left, boundary A is your handset, containing the SIM or eSIM, protected by a SIM PIN, which does not stop a port-out. On the right, boundary B is the carrier, holding your phone number, protected by a number transfer lock, which does stop a port-out. The attack happens entirely on the carrier side and never crosses to the handset at all.
Two controls on two different boundaries. The attack only ever reaches one of them.
A SIM PIN lives in your phone. It is set in your handset's own settings, and it stops someone taking the physical SIM card out of your phone and using it in a different one. That is a real protection against a stolen handset. It is not a protection against this, because the attacker never wanted your card. They asked the carrier for a new one.
A number transfer lock lives at your carrier. It sits on the account rather than the device, and it tells the carrier not to move your number or issue a new SIM without an extra step. This is the one that stops a port-out, and it is the one most people have never switched on.

The naming is genuinely part of the problem. Every major carrier is required to offer this kind of protection, but each one calls it something different, so there is no single phrase to search for and no shared vocabulary between the advice you read and the menu you are looking at.

AT&T calls its version Wireless Account Lock, describes it as free, and puts the toggle in the myAT&T app. In AT&T’s own words it “disables several key account changes including billing updates or wireless number transfers” and “prevents anyone from buying a device on the account, for example, or conducting a SIM swap.” On other carriers the equivalent exists under a different name. Look in the carrier’s app for a setting that mentions porting, number transfer or locking the account, and treat anything labelled SIM PIN in your phone’s settings as a different control that will not do this job.

What each carrier calls the lockread at source 9 Sep 2026
Verizon
Number Lock
verizon.com
Verizon's own words: Number Lock "offers you the ability to lock lines on your account to prohibit the port out of your number", "at no cost to you". Turned on in My Verizon under Account, then Account Settings, then Security Settings, then Number Lock, toggled per line. Verizon texts you when it is active. Its page does not say the lock is on by default, and it is not.
AT&T
Wireless Account Lock
about.att.com
Announced 1 July 2025 as "a free feature". It "disables several key account changes including billing updates or wireless number transfers" and "prevents anyone from buying a device on the account, for example, or conducting a SIM swap". The switch is a toggle in the myAT&T app for postpaid consumer accounts; a Business Account Lock and a Prepaid lock exist alongside it. You may need to unlock it temporarily for a family member's device purchase.
T-Mobile
Account Takeover Protection
t-mobile.com (unread today)
T-Mobile publishes this as a free feature added per line in the T-Mobile app or on T-Mobile.com, which blocks unauthorised transfers of your lines to another carrier, and which only the Billing Responsible Party can remove by contacting T-Mobile. We could not read T-Mobile's support page ourselves on 9 September 2026, so treat this row as T-Mobile's description reported second-hand and confirm it in the app.
Three carriers, three names, one control. On every one of them the lock is free, sits on the account rather than the handset, and is off until the account holder turns it on. The FCC's rules, adopted 15 November 2023 with a compliance date of 8 July 2024, require providers to offer an account lock; they do not require it to be on.
From the field: the tell that something is a carrier-side control rather than a handset one is simply where you found it. If you set it inside your phone’s own settings menu, it protects the card. If you set it inside your carrier’s account, it protects the number.

The protection is free, required, and switched off

At its meeting on 15 November 2023, the FCC adopted rules aimed specifically at SIM swap and port-out fraud, requiring wireless providers to use secure methods to authenticate customers before making SIM changes, and to maintain a clear process for reporting and remediating fraud. The compliance date was 8 July 2024.

So the controls exist because regulation put them there. What regulation did not do is switch them on. A provider being required to offer secure authentication is not the same as your account having the lock enabled, and the gap between those two things is the entire operating space for this attack.

This is why “my carrier is a big company, they must have this covered” is the wrong instinct. They do have it covered, in the sense that the feature is built and free. On most accounts it is sitting there unused.

What to do tonight

Two jobs, in this order. First make the number harder to move. Then make it worth less if it moves anyway.

Lock the number at the carrier. In the carrier's app or online account, not your phone settings. Go there by typing the address or opening the app yourself. A message inviting you to review your account security is exactly what this attack sends.
Move email off SMS codes first. Not the bank. Email is the master key: it resets the bank, the payment apps and almost everything else. An authenticator app or a passkey generates codes on the device itself, so a stolen number does not carry them.
Then the accounts holding money. Banking and payment apps next. Where a provider offers nothing but SMS, that is worth knowing now rather than discovering later.
Learn the alarm. An unexplained loss of service, when you have not moved and other devices nearby still work, is the signal. Contact the carrier from a different device immediately and ask whether your number has been transferred.

The order matters more than it looks. People protect the bank first because that is where the money is, but the attacker does not need the bank if they hold the email that can reset it.

The sentence the attack needs you to ignore

Once the lock is on, there is exactly one thing standing between it and an attacker: a phone call or a message asking you to turn it off. Which is presumably why AT&T published this line on its own site, in the same announcement:

“Just like you’d never give someone your password or a one-time PIN code over the phone, please know that AT&T will never call or text you and ask you to turn off Wireless Account Lock.”
AT&T, 1 JULY 2025

That is a published never-statement, and it is the useful kind. It does not ask you to judge whether a caller sounds convincing. It gives you a rule you can check against a company’s own words: a request to remove the protection is, by the carrier’s own account, never something the carrier makes. We keep a running list of statements like it in the Impersonation Index, because a published never-statement turns an impossible job, spotting a convincing fake, into an easy one.

If your carrier is not AT&T, the same logic holds even where the wording is theirs rather than published. No carrier needs you to disable your own account security in order to help you.

If it has already happened

Speed is the whole game, and the first move is not the bank. From a device that is not the affected phone, take back the email account, then work outward. Contact the carrier and ask them to reverse the transfer and document it, which the FCC rules require them to have a process for. Then report it, and if accounts were opened or money moved, use IdentityTheft.gov, which produces a personalised recovery plan rather than a generic checklist.

Expect the second approach. Once an account takeover is visible, offers to recover the money arrive quickly, and a fee to unlock funds is the reliable tell. We cover that pattern in recovery scams.

The uncomfortable part of this one is also the reassuring part. Nothing about it required you to be careless, because the attack never went through you at all. It went around you, to a company that holds something you have always assumed was yours, and moved it.

Sources

FCC — SIM swapping rules, compliance dateFCC — Report and Order, cell phone accountsAT&T — Introducing Wireless Account LockVerizon — Avoid port fraud: Number LockFTC — IdentityTheft.gov recovery plan

Keep reading

REFERENCE
What 28 companies say they will never do
THE SECOND CON
Recovery scams: the offer that arrives after the loss
THE ONE-WORD TEST
Is that bank fraud alert real or a scam?
EMERGENCY · FREE TOOL
If money just moved, what to do in the first hour