MalwareZero
Mobile phone showing a fake port-out SMS warning the user to act fast

Texts and calls

The 'confirm your number transfer' text scam

Updated 6 October 2026

You assume the text is a typo from your own carrier, so you tap the link. By the time the page loads, a stranger already owns your number, and your bank is one verification code away from being emptied. The message that says your number is being transferred to another carrier is not a notice, it is a request, and you have a window of minutes to cancel it.

What the message actually says

Carrier app screen with a port freeze toggle highlighted

How a SIM swap actually drains an account

A SIM swap, also called a SIM hijack or port-out scam, is when a criminal convinces your carrier to move your phone number onto a SIM card they hold. Once that switch happens, your phone loses signal. Their phone receives your calls, your SMS, and crucially your one-time passcodes.

From there, the criminal opens the password reset page for your email. They request a code, your bank, or your crypto exchange, and that code arrives on the SIM they control. They change the password, lock you out, and start moving money. The whole sequence from first text to first transfer can take under an hour.

The Federal Trade Commission logged a sharp rise in SIM swap reports through 2024 and 2025, and the FBI's Internet Crime Complaint Center has tracked eight-figure losses tied to the technique. In the UK, Action Fraud continues to list SIM swap as one of the most reported account takeover methods for the year. The pattern is consistent: a port-out text, a brief loss of signal, then a wave of password resets the victim never asked for.

The first 60 seconds: what to do right now

Do not tap the link. Do not call the number in the text. Both belong to the person trying to take your number.

Open the carrier's app or website on a device that still has working internet, such as your laptop or a tablet on Wi-Fi. Sign in and look for a security or account protection section. If you can place a "port freeze," "SIM lock," or "number lock" on your account, do it now. T-Mobile customers can dial 611 from another T-Mobile line or use the T-Life app, AT&T customers can use the myATT app, Verizon customers can call 611 or use the My Verizon app. In the UK, EE customers can ring 150, O2 customers can ring 202, Three customers can ring 333, and Vodafone customers can ring 191.

If your phone has already lost signal and you cannot reach your carrier through the app, find the customer service number from a paper bill, a credit card statement, or a Google search you trust. Tell the agent you believe a SIM swap or port-out is in progress on your line and ask them to lock the port and freeze the account. Do not hang up until you hear back that the request is on hold.

How to tell the real carrier text from the fake one

The honest truth is that on a phone screen, you often cannot. Both messages can come from a short code, both use carrier branding, and both contain a link or a callback number. Three signals tilt toward scam.

First, you did not just switch carriers or buy a new SIM, so there is no business reason for a port text to exist. Second, the message creates urgency, telling you to act within minutes or lose your number. Third, the link does not point to a domain the carrier actually owns. Real carrier short message service traffic uses the carrier's own domain, not a random top-level country code address that was registered last month.

If you receive a port text and you genuinely started a transfer yourself, the message will match the timing of a request you placed with a salesperson or a store. If the message is unsolicited, treat it as fraudulent regardless of how official it looks. When in doubt, call the carrier through a number you typed into a browser yourself.

Set a port-out PIN before anyone asks

Every major US carrier now offers a separate PIN or passcode that must be quoted before a number can be ported. The industry calls this a "port-out PIN," and it is the single most effective control against a SIM swap because the criminal would need to know it as well as your name and address.

On T-Mobile, the setting is called a Port-Out PIN and lives under Account > Line Settings > SIM protection. On AT&T, it is the Account Passcode and Wireless Passcode, which serve the same function for porting. Verizon customers can set a Number Transfer PIN in the My Verizon app or by dialling *61 and following the prompts.

In the UK, all four major networks now require a PAC or porting PAC plus account verification, and EE specifically added a "Port Out Bar" feature in 2025 that you can switch on through the app. The bar must be lifted by you, in person or in the app, before any number transfer is processed. If you only do one thing today, set the port-out PIN on your account and write it down somewhere that is not your phone.

If the swap already happened: the recovery list

Your phone says "No service" or "SIM not provisioned" and you did nothing. That is the moment you are inside the window where the criminal has your number and you do not.

Call your carrier from another phone, tell them the line has been hijacked, and ask for an immediate port reversal and a port-out PIN set so the same person cannot try again. Ask the agent to flag the account for in-store identity verification, which means a thief cannot ring in and bypass the lock later.

The link in a fake port text usually leads to a page that looks like a carrier login. The page is a credential harvester. If you type your account password, you have just handed over the second factor the criminal needs to walk into your account the legal way.

Some links go further and ask for the one-time code that your bank sends to confirm a transaction. The criminal triggers the bank's password reset, you receive a code on your real phone, you type it into the fake page, and the bank hands the account over. The whole thing is designed to feel cooperative, as if you and the carrier are working together to cancel a transfer you never asked for.

The fix is structural. No carrier will ever ask for your account password in a text-driven flow. No carrier will ever ask you to read a one-time code into a website. If a page linked from an SMS asks for either, you are on a phishing site and the safest move is to close the tab.

The accounts that hurt most if you lose your number

Not every account is equal when your phone number changes hands. The damage ladder starts with anything that uses SMS for password recovery, which today is most of them.

At the top: your primary email, because it is the reset method for everything else. Below that, your bank, your brokerage, your crypto exchange, and your payment apps. Then the second tier: social media accounts, because a hijacker can use them to impersonate you and ask your friends for money. Then anything with stored value, including Apple Pay, Google Pay, PayPal, and Venmo. Finally, the long tail: airline accounts, food delivery, and shopping sites where the criminal can charge stored cards and rack up loyalty fraud.

Walk this list in order. The goal is to get ahead of the criminal's password reset queue, not to catch up with it. If you can change the recovery method on your email from your phone number to a hardware security key or an authenticator app before the hijacker asks for a code, you win.

Replace SMS codes with something stronger

SIM swap exists because SMS exists. As long as your bank is willing to send a one-time code to a phone number, that phone number is a target.

Switch the second factor on your most important accounts to an authenticator app, such as Google Authenticator, Microsoft Authenticator, or Authy, or to a hardware security key such as a YubiKey. The codes from these methods are generated on a device the carrier cannot move, so a SIM swap does not break them. Where an app is not an option, choose a backup phone number that is on a different carrier, ideally a prepaid line you keep in a drawer, so the criminal would have to swap two numbers to reach you.

This is not a future project. Every account that still uses SMS as its only second factor is the one you lose first.

What to tell the police, and what they can actually do

Local police often treat SIM swap as a banking matter and not their case, which is frustrating but accurate. File the report anyway, because insurers and banks will want the incident number before they refund losses.

The report that actually moves the needle goes to the FBI at ic3.gov for US cases, or to Action Fraud for UK cases, and to the FTC at reportfraud.ftc.gov. The carriers themselves have dedicated abuse teams for SIM swap, and a well-timed email to abuse at the relevant carrier domain with timestamps and screenshots will often accelerate the port reversal and the internal fraud review.

Keep every screenshot. Keep the SMS header. Keep the timestamps of when your phone lost signal and when the password resets hit your email. The carrier's fraud team will ask for these, and so will your bank.

Quick answers

Can a SIM swap really happen without me tapping a link?
Yes. A SIM swap starts with a phone call to your carrier from someone pretending to be you, using personal data bought on the dark web. If they pass security and your account has no port-out PIN, the carrier moves your number to their SIM. The unsolicited port text you receive is the warning, not the cause.
How long does a SIM swap take from first text to empty account?
Often under an hour. The criminal triggers the port, your phone loses signal within minutes, then they hit your email reset, your bank reset, and your exchange reset in sequence. That is why the first 60 seconds after an unexpected port text matter so much.
Should I reply STOP to a suspicious port text?
No. Replying confirms your number is live and routes you into the criminal's script. The safer move is to ignore the text entirely and call your carrier on a number you found yourself through a search engine or a recent bill.
Does a port-out PIN stop every SIM swap?
It stops the lazy ones. A criminal who cannot quote your port-out PIN has to either social engineer the agent further or visit a store in person with forged ID, which raises the cost of the attack. It is not perfect, but it removes the path of least resistance.
Will switching to an authenticator app make my accounts SIM-swap proof?
It removes the phone number from the recovery chain, which is what the criminal needs. As long as your second factor lives on a device the carrier cannot port, a SIM swap no longer hands over the keys. A hardware security key is the strongest option, an authenticator app is a close second.
Can I get my number back after a successful SIM swap?
Usually yes, but the timing matters. Call your carrier from another phone the moment your line goes dark, ask for a port reversal and a port-out PIN set, and require in-store identity verification before any future change. The faster you report, the better the chance the port has not fully completed.
Who do I report a SIM swap to in the US and UK?
In the US, file with the FTC at reportfraud.ftc.gov and the FBI at ic3.gov, and contact your carrier's abuse team. In the UK, file with Action Fraud at actionfraud.police.uk and add a CIFAS Protective Registration. Your bank and email provider also need to hear from you on the same day.
Is a no-service message on my phone enough to prove a SIM swap?
It is a strong signal, especially if it follows an unexpected port text or a short loss of signal that came back wrong. Capture the timestamp, screenshot any messages, and call your carrier from another line immediately. The combination of evidence and speed is what gets the port reversed.

This is general safety information, not legal advice. Scams change. If you need an official desk: FTC ReportFraud or IC3.