A cell phone that suddenly shows no service can look like a network glitch or a dead battery. For a growing number of victims, it is the first sign that a thief has taken over their phone number and is already inside their bank, brokerage, and email accounts. The attack is called a SIM-swap, and it turns the very phone people rely on for security into the tool used to rob them.
How a SIM-swap takes control of a phone number
Every mobile line is tied to a SIM, the small chip that connects a number to a specific device. In a SIM-swap, a criminal contacts the victim’s wireless carrier and persuades a representative to move that number onto a SIM the criminal controls. They may pull it off using personal details bought or stolen online, answers to weak security questions, or in some cases an insider at the carrier who is paid to make the switch.
Once the number is ported, the victim’s own phone drops off the network, and every call and text meant for that number flows to the thief instead. That includes the one-time verification codes that banks, investment firms, and email providers send by text to confirm a login or a password reset. With those codes in hand, the attacker can march through account after account.
The reach of a hijacked number is often wider than victims expect. Email is frequently the master key, because whoever controls the email inbox can trigger password resets for nearly everything else linked to it. Once the thief owns the number and then the email, a retiree’s checking and savings accounts, a brokerage or retirement account, and even accounts holding personal records can all be opened in a single session. The order of attack is usually deliberate: seize the phone, capture the reset codes, take over email, and only then drain the accounts that hold real money.
Free retirement updates: Scam calls targeting retirees change every week. Our free Retirement Shield newsletter flags the ones going around and the one tell that stops each. Sign up free.
Why text-message codes are the weak point
Text-message verification became popular because it is convenient, but the SIM-swap exposes its central flaw: a code sent to a phone number protects an account only as long as the rightful owner is the one holding that number. When the number itself is stolen, the extra layer of security is handed straight to the intruder. Passwords can then be reset, and the accounts that hold a retiree’s cash, investments, and identity fall open one by one.
The Federal Trade Commission’s guidance on unwanted and fraudulent text messages underscores how much criminals lean on the phone as a channel of attack, from bogus texts that harvest personal details to schemes that ultimately seize a number outright. Anyone whose bank login depends solely on a texted code has, in effect, made their entire financial life only as secure as their phone account.
The warning sign that gives a thief away
The clearest red flag is abrupt and unexplained: a phone that loses all service and cannot make calls or send texts, even though the device is working and other phones nearby are fine. Because a SIM-swap severs the victim’s line the instant it succeeds, that sudden loss of signal often arrives just as the thief begins draining accounts, which makes every minute count.
A follow-up sign is a wave of account alerts, password-reset emails, or login notices that the victim did not request. Treating a mysterious service outage as a possible security emergency rather than a mere inconvenience can be the difference between catching the attack in progress and discovering it after the money is gone.
Locking down a number before it is stolen
Several defenses make a SIM-swap far harder to pull off. Setting a separate account PIN or passcode with the wireless carrier means a caller cannot move a number without that secret, blocking the most common social-engineering route. Where a bank or brokerage allows it, switching from text-message codes to an authenticator app or a physical security key removes the phone number from the login chain entirely, so a stolen SIM no longer unlocks the account.
Limiting what is public also helps, since the personal details criminals use to impersonate a customer often come straight from social media or old data breaches. A birth date, a childhood address, a pet’s name, or a mother’s maiden name posted online can supply the exact answers a carrier’s representative asks to confirm identity. Keeping that information off public profiles, and avoiding security questions whose answers a stranger could look up, removes some of the raw material a SIM-swap depends on.
If service does vanish without explanation, acting fast is essential. Contacting the carrier from another phone to report a suspected swap and restore the line, then alerting banks and brokerages to watch for or freeze suspicious activity, can shut the door before more damage is done. For older Americans whose retirement savings, Social Security deposits, and brokerage balances all sit behind a phone number, hardening the carrier account and moving away from text-only codes turns the phone back into a shield rather than a skeleton key.
This article was produced with AI assistance and reviewed by The Financial Wire editorial team.
More Financial Reading
- The ideal retirement withdrawal rate so your savings actually last
- Adding someone to your bank account: tax traps and smart moves



