NOTHING WAS HACKED

Your phone was never touched. Your number was moved.

There is a version of account theft where nothing gets broken into. No password is cracked, no malware is installed, and your handset never leaves your pocket. Someone simply persuades your mobile carrier that they are you, and your number is assigned to a SIM in their phone.

From that second, every code sent to you by text arrives with them. And there are two settings people reach for to prevent it, with confusingly similar names. Only one of them works.

The short answer

A SIM PIN does not stop a SIM swap. It locks the SIM card inside your handset, and this attack never touches your handset. The control that works is held at your mobile carrier, usually called a number transfer lock, port-out lock or account lock. It is free on every major US carrier, it lives in the carrier's app rather than your phone settings, and on most accounts it is switched off until you turn it on.

Nothing failed. That is the problem

The instinct is to ask what was hacked. The answer is nothing, and holding onto that is what makes the rest of this make sense.

A port-out is not an intrusion. It is a substitution. The attacker does not defeat your bank's security, they satisfy it. Every check still runs, every check still passes, and every check passes for someone else.

The check
Your bank sends a one-time code to the number on file.
What it concludes
The code was delivered to the registered number, and it came back correct.
VERDICT: IDENTITY CONFIRMED
The check
Your email provider offers to text you a reset link.
What it concludes
The link went to the number the account owner registered.
VERDICT: IDENTITY CONFIRMED
The check
A payment app asks you to verify a new device by SMS.
What it concludes
Verification succeeded on the first attempt.
VERDICT: IDENTITY CONFIRMED

Read that column again. At no point does anything read as an error, because nothing is an error. The system was asked whether the person holding the number is the account owner, and the honest answer, by the only definition the system has, is yes.

You are not locked out because something failed. You are locked out because it worked, and the definition of “you” that it worked on is a phone number that now belongs to someone else.

The two locks

This is where the practical mistake happens, and it is an easy one to make because both controls sound like they protect the same thing.

A schematic comparing two protections. On the left, boundary A is your handset, containing the SIM or eSIM, protected by a SIM PIN, which does not stop a port-out. On the right, boundary B is the carrier, holding your phone number, protected by a number transfer lock, which does stop a port-out. The attack path crosses at the carrier, never touching the handset.
Two controls, two different boundaries. The attack only ever crosses one of them.
A SIM PIN lives in your phone. It is set in your handset's own settings, and it stops someone taking the physical SIM card out of your phone and using it in a different one. That is a real protection against a stolen handset. It is not a protection against this, because the attacker never wanted your card. They asked the carrier for a new one.
A number transfer lock lives at your carrier. It sits on the account rather than the device, and it tells the carrier not to move your number or issue a new SIM without an extra step. This is the one that stops a port-out, and it is the one most people have never switched on.

The naming is genuinely part of the problem. Every major carrier is required to offer this kind of protection, but each one calls it something different, so there is no single phrase to search for and no shared vocabulary between the advice you read and the menu you are looking at.

AT&T calls its version Wireless Account Lock, describes it as free, and puts the toggle in the myAT&T app. In AT&T’s own words it “disables several key account changes including billing updates or wireless number transfers” and “prevents anyone from buying a device on the account, for example, or conducting a SIM swap.” On other carriers the equivalent exists under a different name. Look in the carrier’s app for a setting that mentions porting, number transfer or locking the account, and treat anything labelled SIM PIN in your phone’s settings as a different control that will not do this job.

From the field: the tell that something is a carrier-side control rather than a handset one is simply where you found it. If you set it inside your phone’s own settings menu, it protects the card. If you set it inside your carrier’s account, it protects the number.

The protection is free, required, and switched off

At its meeting on 15 November 2023, the FCC adopted rules aimed specifically at SIM swap and port-out fraud, requiring wireless providers to use secure methods to authenticate customers before making SIM changes, and to maintain a clear process for reporting and remediating fraud. The compliance date was 8 July 2024.

So the controls exist because regulation put them there. What regulation did not do is switch them on. A provider being required to offer secure authentication is not the same as your account having the lock enabled, and the gap between those two things is the entire operating space for this attack.

This is why “my carrier is a big company, they must have this covered” is the wrong instinct. They do have it covered, in the sense that the feature is built and free. On most accounts it is sitting there unused.

What to do tonight

Two jobs, in this order. First make the number harder to move. Then make it worth less if it moves anyway.

Lock the number at the carrier. In the carrier's app or online account, not your phone settings. Go there by typing the address or opening the app yourself. A message inviting you to review your account security is exactly what this attack sends.
Move email off SMS codes first. Not the bank. Email is the master key: it resets the bank, the payment apps and almost everything else. An authenticator app or a passkey generates codes on the device itself, so a stolen number does not carry them.
Then the accounts holding money. Banking and payment apps next. Where a provider offers nothing but SMS, that is worth knowing now rather than discovering later.
Learn the alarm. An unexplained loss of service, when you have not moved and other devices nearby still work, is the signal. Contact the carrier from a different device immediately and ask whether your number has been transferred.

The order matters more than it looks. People protect the bank first because that is where the money is, but the attacker does not need the bank if they hold the email that can reset it.

The sentence the attack needs you to ignore

Once the lock is on, there is exactly one thing standing between it and an attacker: a phone call or a message asking you to turn it off. Which is presumably why AT&T published this line on its own site, in the same announcement:

“Just like you’d never give someone your password or a one-time PIN code over the phone, please know that AT&T will never call or text you and ask you to turn off Wireless Account Lock.”
AT&T, 1 JULY 2025

That is a published never-statement, and it is the useful kind. It does not ask you to judge whether a caller sounds convincing. It gives you a rule you can check against a company’s own words: a request to remove the protection is, by the carrier’s own account, never something the carrier makes. We keep a running list of statements like it in the Impersonation Index, because a published never-statement turns an impossible job, spotting a convincing fake, into an easy one.

If your carrier is not AT&T, the same logic holds even where the wording is theirs rather than published. No carrier needs you to disable your own account security in order to help you.

If it has already happened

Speed is the whole game, and the first move is not the bank. From a device that is not the affected phone, take back the email account, then work outward. Contact the carrier and ask them to reverse the transfer and document it, which the FCC rules require them to have a process for. Then report it, and if accounts were opened or money moved, use IdentityTheft.gov which produces a personalised recovery plan rather than a generic checklist.

Expect the second approach. Once an account takeover is visible, offers to recover the money arrive quickly, and a fee to unlock funds is the reliable tell. We cover that pattern in recovery scams.

The uncomfortable part of this one is also the reassuring part. Nothing about it required you to be careless, because the attack never went through you at all. It went around you, to a company that holds something you have always assumed was yours, and moved it.

Sources

FCC — SIM swapping rules, compliance dateFCC — Report and Order, cell phone accountsAT&T — Introducing Wireless Account LockFTC — IdentityTheft.gov recovery plan

Keep reading

REFERENCE
What 28 companies say they will never do
THE SECOND CON
Recovery scams: the offer that arrives after the loss
THE ONE-WORD TEST
Is that bank fraud alert real or a scam?
EMERGENCY · FREE TOOL
If money just moved, what to do in the first hour