A hack into your bank account is hardly the worst thing that can happen. Also, when they pilfer your phone number
After connecting to my home Wi-Fi network to check my email, I saw that $20,000 was being moved from my credit card to a Discover Bank account that I was not familiar with. My horror was just beginning, but I managed to stop that transfer and notify the cell phone problems. Some days later, my credit card balance of $19,000 was successfully transferred to the same peculiar bank account by someone else.
I was the victim of a type of fraud known as port-out hijacking, also called SIM-swapping. This less-common form of identity theft involves criminals taking over your phone number. Any calls or texts go to them, not to you.

When your own phone access is lost to a criminal, the very steps you once took to protect your accounts, such as two-factor authentication, can be used against you. It doesn’t help to have a bank send a text to verify a transaction when the phone receiving the text is in the hands of the very person trying to break into your account.

Even if you’re a relatively tech-savvy individual who follows every recommendation on how to protect your tech and identity, it can still happen to you. Experts say these scams will only increase and become more sophisticated, and the data show they are on the rise.
I am not the most tech-savvy person, but I am a law-school-educated journalist who specializes in finance reporting. Due to the very online nature of my job, I was taught all the methods of staying safe online: constantly changing my passwords with multi-factor authentication, signing out of apps that I don’t use regularly, and keeping my personal information off the internet.
Still, despite being safe, I was vulnerable to criminals. It took a lot of time and legwork before I got my money and phone number back.
With 1,611 SIM-swapping complaints involving personal losses of more than $68 million, the FBI Internet Crime Complaint Center says that SIM-swapping complaints grew by more than 400% between 2018 and 2021. From 275 complaints in 2020 to 550 reports in 2023, the number of complaints to the FCC regarding the crime has doubled.
Since most identity thefts go unreported, according to Rachel Tobac, CEO of SocialProof Security, an online security company, the crime rate is probably much higher. She further claims that since social security numbers, phone numbers, and birthdays can be found online in a variety of public and commercial databases, two-factor authentication is an antiquated method of protecting users.
The ability of thieves to obtain your personal information was again made clear when AT&T said the data of nearly all of its customers was downloaded to a third-party platform in a security breach two years ago. Although AT&T claims no personal information was leaked, cybersecurity experts have warned that breaches involving telephone companies leave customers vulnerable to SIM swapping.
Currently, changing a phone number is a simple process that may be completed over the phone or online. If a criminal has access to your personal information, the process can be completed in a matter of hours or less. Customers should “put pressure on companies where it’s their job to protect our data,” according to Tobac, in addition to being wise and using a variety of passwords and security measures. She stated that two-factor authentication is insufficient and that “we need them to update consumer protection protocols.”
FCC rules have recently changed to force companies to do more to protect consumers from this type of scam. In 2023, the FCC introduced rulemaking that requires wireless providers to “adopt secure methods of authenticating a customer before redirecting a customer’s phone number to a new device or provider” among other new rules. Companies could require more information when a customer tries to port over a phone number to another phone — from requiring government identification, voice verification, or additional security questions.

The rules were scheduled to take effect on July 8, but the FCC on July 5 granted phone companies a waiver that delays implementation until the White House Office of Management conducts a further review. The wireless industry had sought the delay, stating among other reasons that companies need more time to comply. CTIA, which lobbies on behalf of the companies, said the new rules will require major changes in technology and procedures both within the wireless companies and in their interactions with phone manufacturers.
But if the FCC rules had been in place, my phone number might have been harder to steal, experts say. Ohio State University Professor Amy Schmitz says the new FCC rules make it easier for consumers to protect themselves, but it is still reliant on the action and awareness of the consumers. “I still question whether consumers will be aware of this and will take action to protect themselves,” she said.
It took ten days to get my number back from Cricket Wireless — and that wasn’t until I told company representatives that I was writing a story about my experience. In that period of time, the scammer was able to access my bank account three times and eventually successfully transferred $19,000 from my credit card— even though I removed my number from the bank account, froze my credit, changed all my passwords, among other measures.
Bank of America worked to reverse the $19,000 wire after I visited a branch near the AP bureau in Washington. Cricket apologized for the error and said in an email that its “expectation is to deliver a much better customer experience.” “Fraudulent port-outs are a form of theft committed by sophisticated criminals,” reads a company statement that was emailed to me. “We have measures in place to help defeat them, and we work closely with law enforcement, our industry, and consumers to help prevent this type of crime.”
Through email, I received word from an AT&T official that “all providers are working to implement the FCC’s new rules on port-outs and SIM swaps.” My date of birth, phone number, social security number, or even a voice recording could have been the means by which this person gained access to my accounts, but I’m still not sure. It was an eye-opening experience that made us realize how exposed we are when we misplace control over our highly visible personal data.
The sense of helplessness and frustration was overwhelming. Despite my knowledge and precautions, I felt exposed and unprotected. The process of regaining control over my accounts and my life was arduous. Each call to customer service, each visit to the bank, and every email exchanged with service providers was a reminder of how easily one’s life can be disrupted by digital thieves.

What stands out most is the inadequacy of current protective measures. Two-factor authentication, once heralded as a strong security measure, seems almost quaint in the face of modern cyber threats. The criminals’ ability to reroute my phone number and intercept security texts exposed a glaring vulnerability. It was clear that more robust security protocols are needed.

The support from friends and colleagues during this time was invaluable. Sharing my experience not only brought awareness to this type of fraud but also connected me with others who had faced similar ordeals. We exchanged tips, offered support, and collectively called for better security measures from service providers.
The experience has made me more vigilant. I now advocate for greater awareness of SIM-swapping and other forms of identity theft. It’s crucial for everyone to understand that even the most cautious individuals can become victims. Awareness and advocacy are the first steps towards more robust protections.
In the aftermath, I remain in close contact with my bank and service providers, ensuring that all possible security measures are in place. The ordeal has been a stark reminder of the importance of digital security in our interconnected world. It’s a call to action for companies and consumers alike to prioritize and enhance their protective measures.
My perspective on digital security has ultimately changed as a result of this encounter. It has brought attention to the significance of keeping up with new threats and regularly changing security procedures. Even though recovery was difficult, the experience highlighted how important it is to be vigilant and resilient when dealing with cybercrime.

If you like the article please follow on THE UBJ.