
Texts and codes
Port-out SMS: the SIM-swap setup hiding in your texts
Updated 6 October 2026
You assume the text is about your phone, so you act on your phone. That assumption is what the sender is buying. A port-out SMS is a five-second message that gives a criminal the running start they need to take over your number, and from there your bank, your email, and every account that uses a one-time code by text. The fix is not clever. The fix is speed, a phone call to a number you already trust, and a carrier-side lock that makes your line boring to steal.
The text that looks like a carrier alert
The text lands in the same thread as your shipping updates and your two-factor codes, which is exactly why it works. It usually arrives from a short code, the kind of five or six digit sender that real carriers use for legitimate alerts, and it reads like a system message rather than a sales pitch. The wording is clinical. "Your number is being ported to another carrier. If you did not request this, visit this link to stop the transfer." Or sometimes even shorter. "Port-out PIN requested. Reply STOP to cancel." The reply is the trap, or the link is, or both.
Mobile number porting is the industry process that lets you keep your phone number when you switch carriers. The carriers built it for convenience, and in October 2026 the convenience is well worn. A port-out is the one transaction that a criminal can start against you without holding your phone, your password, or your ID. They only need your name, your phone number, and a few details that have probably already leaked from a data broker. Once the port goes through, your real SIM goes dark. Their SIM lights up with your number, and every text message sent to you, including the one-time codes your bank uses to verify you, starts arriving on a device in a different postcode.
This is the part people miss. The text is not the scam. The text is the cover story. The scam is the SIM swap that the text is either trying to start, trying to detect, or trying to make you cancel in a way that hands over the very information the criminal needs. Treat every port-out message that you did not personally trigger as live fraud, and the rest of this page walks you through how to tell the real ones from the fakes, and what to do in the next sixty seconds.

How to tell a real port-out alert from a fake
Real carriers do send port-out related messages. That is the awkward truth. When you start a port yourself, your old carrier will text you a confirmation, and some will text you again if they see a port they did not expect. The Federal Communications Commission has required carrier-side port-out confirmation since 2022, and the four national carriers have added their own port-out PIN steps on top. So the existence of a port-out text is not the red flag. The trigger is the text appearing when you did nothing.
Look at the sender. A real port-out alert comes from a short code that matches your carrier, or from the carrier's own ten digit business number. Verizon uses codes in the 600 to 900 range, AT&T uses specific short codes that start with 28, T-Mobile uses 937, and so on, but these change, and the safest test is whether the code matches one you have received before from the same carrier. A scam port-out text often comes from a random short code, an email-to-text bridge that shows up as a regular email address, or a long number that looks like a personal mobile. None of those are how your carrier actually talks to you about porting.
Look at the link. If there is a URL in the message, it should point to the carrier's own domain. Anything shortened, anything with extra hyphens, anything that ends in a country code you do not recognise, is the tell. Look at the ask. Your carrier will never ask you to reply with a port-out PIN, a one-time code, or the last four digits of your Social. The whole point of a port-out PIN is that you do not share it. If a message asks for it, you are looking at the scam.
What to do in the next sixty seconds
You did not ask for a port. The text says one is happening. The first sixty seconds matter more than anything else on this page, so do them in this order.
Step one is do not tap the link. Do not reply STOP. Do not reply anything. Open your phone app the long way, dial your carrier's customer service number from your last bill or from the carrier's website, and ask the agent to confirm whether a port has been started against your line. If no port is pending, you have just dodged a probe and you should still set a port-out PIN and a port freeze as a precaution. If a port is genuinely pending, the agent can place a freeze on the line while you verify your identity in a branch or through the carrier's app.
Step two is add the protection that should already be on your line. Every major US carrier offers a port-out PIN or a port freeze. AT&T calls it Wireless Account Lock. Verizon calls it Number Lock. T-Mobile calls it Port Out Protection. The exact name changes, the effect does not. Once enabled, your number cannot be ported to another carrier without a PIN that lives only with you. In October 2026 all four carriers allow you to set this through the app without visiting a store, and none of them will ask for the PIN over SMS.
Step three is assume the worst about the next twenty four hours. If a port did go through, the criminal now has your texts. Sign in to your bank, your email, your cloud storage, and any crypto exchange, and remove SMS as a two-factor method. Replace it with an authenticator app or a hardware key. Rotate the passwords on the accounts that were tied to your number. Watch for password reset emails you did not request. If you see one, the attacker is moving from your phone to your money, and that is when the call to your bank's fraud line stops being optional.
The law on the other side of the text
United States law treats an unauthorised port as a form of identity theft under the Truth in Caller ID Act and the federal identity theft statutes, and the FCC has held carriers responsible for failing to authenticate port requests properly. The 2022 confirmation rules require carriers to send a port-out confirmation and to honour a freeze placed within a short window, and in October 2026 the carriers have settlement-grade obligations to compensate customers for direct losses caused by an unauthorised port where the carrier failed to follow its own procedure. That last bit is not a slogan. The FCC's 2023 and 2024 enforcement actions against carriers for sloppy port handling resulted in multi-million dollar settlements and a published expectation that good-faith victims get refunded.
The recovery path is concrete. File a police report and keep the reference number, because your bank and your carrier will both want it. File a complaint with the FCC at fcc.gov/complaints and with the FTC at reportfraud.ftc.gov. Both portals accept port-out fraud as a category. Send a written dispute to your carrier's fraud team, citing the date of the text, the time you called, and the name of the agent who confirmed the port. If your bank lost money because the attacker used your number to receive a one-time code, attach the bank's fraud affidavit and ask the carrier to escalate under their SIM-swap loss policy. Most carriers will cover direct loss where their own port process was the failure point, and where the customer can show they responded to the alert within the carrier's stated window.
The accounts the attacker will hit next
The first follow-up call is to your bank, not your carrier. The reason is simple. The phone number is the credential. The bank account is the prize. Walk into a branch or call the number on the back of your card and tell the fraud team that your phone number may have been ported. Ask them to flag the account for SIM-swap style withdrawal attempts, to require in-branch verification for any address change, and to issue new card numbers if the attacker had time to read your texts. If you use Zelle, Venmo, or Cash App, the same rule applies. Those services are tied to your phone number by design, and a ported number is a logged-in number on someone else's device until the platform is told otherwise.
The second follow-up is to your email provider. Gmail, Outlook, Yahoo, and Apple all allow you to remove SMS as a recovery method and to add a hardware security key. Do both. If the attacker already used the ported number to reset your email password, the password reset email went to you and the confirmation code went to them, and you have already lost the account. The recovery path is the provider's account recovery form, which is slow and painful, and the prevention path is the one you should be on right now.
The third follow-up is to your credit. The attacker now has enough personal information to try opening new accounts in your name. Place a free fraud alert with any one of the three credit bureaus, and it carries across all three. In October 2026 the bureaus are still required to offer this under the Fair Credit Reporting Act, and the alert lasts one year. For stronger protection, freeze your credit, which is free, instant, and stops new account opening cold.
The short version, on a card you can keep
Real port-out alerts come from a short code that matches the carrier, point to the carrier's own domain, and do not ask you to reply with a PIN or a one-time code. Real port-out alerts also arrive in response to something you did, like visiting a store, starting an online port, or calling the carrier to switch. A text about a port that you did not start is the tell, and the safest move is the same every time.
Open the carrier's app or call the carrier on a number you already trust. Ask whether a port is in progress. Set a port-out PIN or a port freeze if you do not have one. Replace SMS two-factor with an authenticator app on any account that holds money. Watch your email for password resets you did not request, and treat any such email as the next step in the same attack.
Why the messages are so well written
Prosecutors have used the wire fraud and access device fraud statutes to charge SIM-swap crews, and the Department of Justice has run a string of cases since 2022 against groups that ran port-out scams as a service. The attackers are rarely the person who texted you. They are usually a buyer who paid a crew for access to a high-value number, and the crew is the one who sent the port-out SMS, performed the port, and handed the number over. The crew is also the one who pays the text-message service, which is why the messages look the way they do. They are buying credibility at scale.
If your number was actually ported, the forensic value of the text message is high. Screenshot the message, the sender, the timestamp, and the link. Do not delete it after you have reported it. The carrier's port log will show the originating request, and law enforcement can subpoena the short code provider for the account that paid for the send. In several 2024 and 2025 cases those logs were the thread that unraveled a crew.
Long-term moves that close the door
Use an authenticator app for two-factor on every account that matters. Banks, email, cloud storage, crypto, payroll. SMS is the fallback, not the default. If a service offers a hardware key, use it. If a service only offers SMS, that is a signal to move your money somewhere that does not treat your phone number as a master key.
Set a port-out PIN and a port freeze on your wireless line today. Five minutes in your carrier's app closes the door that the port-out SMS is trying to open.
Keep a written list of the customer service numbers for your bank, your carrier, and your email provider. When the text arrives, you will not be in a state to Google anything. You will be in a state to dial the number on the back of the last letter they sent you.
Quick answers
- Can a port-out happen without a text at all?
- Yes. A determined attacker with enough personal data can sometimes push a port through a carrier store or a call centre insider, which is why a port-out PIN and a port freeze are the real protection, not the text.
- Will my carrier refund money stolen after a port?
- Often, but only where the carrier failed to follow its own port procedure or ignored a freeze you placed in time. File the police report, the FCC complaint, and a written dispute, and attach the bank's fraud affidavit.
- Does replying STOP to a port-out text cancel the port?
- No. Replying confirms your number is live and willing to engage, which is more valuable to the attacker than the port itself. Call your carrier on a number you trust instead.
This is general safety information, not legal advice. Scams change. If you need an official desk: FTC ReportFraud or IC3.