rosiesol.xyz

Port out fraud using stolen identity to steal your phone number

Port out fraud is a specific type of SIM theft. It differs from a standard swap/sim-swap-fake-id-carrier-store/">carrier SIM swap in one critical way: the attacker never contacts your current carrier. They go straight to a different provider.

This makes the attack harder to detect. You receive no warning text, no email, no confirmation call. One moment your phone works. The next, it doesn't. The number has been moved.

How the attacker gets your information

The attacker needs enough personal data to impersonate you. This is not hard to find.

Data breaches supply the raw material. Your name, address, date of birth, Social Security number or national ID - all of this has leaked from countless companies over the years. Public records fill in the gaps: property records, voter registration rolls, professional license databases. All are searchable.

The attacker pieces together a profile. Name. Address. Date of birth. The last four digits of your SSN. Answers to common security questions: your mother's maiden name, the street you grew up on, the model of your first car. Much of this is already in the public record or available from a breach. They do not need everything. They need enough to pass a carrier's identity check.

The port-out process

The attacker researches which carriers operate in your area and chooses one you do not use.

They call or visit that carrier's store, presenting themselves as you, and say they want to switch their number from your current provider. This is a normal request. Carriers handle port-ins every day. The new carrier asks for verification. The attacker provides the details gathered earlier: name, address, date of birth. Possibly the account number from your current carrier. That number may have appeared in a breach or can be guessed from standard account numbering schemes.

If the new carrier runs a credit check as part of the process, the attacker's profile may match yours. Credit bureaus hold the same breached data. The check confirms the identity. The new carrier initiates the port, sending a request to your current carrier through the centralized number portability system. Your current carrier receives the request. The system is designed to approve these requests automatically unless you have placed a port-out lock on your account. Most accounts do not have port-out locks. The request goes through.

What happens after the port

Your current carrier detects the number has moved. They terminate your service. Your phone loses signal.

The attacker now controls your phone number. Any text message or call meant for you goes to their device. This includes two-factor authentication codes, password reset links, and bank verification messages. The attacker can now reset passwords on accounts tied to that number - email, social media, cryptocurrency exchanges, financial services. Many platforms allow password resets using SMS verification. The attacker triggers a reset, receives the code, and gains access.

Why this bypasses the original carrier entirely

The original carrier never approves the transfer. They do not need to. The portability system is designed to move numbers between providers, not to vet the person requesting the move. The new carrier makes the identity determination.

This is the critical difference from a SIM swap. In a SIM swap, the attacker calls your carrier and tricks a support agent into issuing a new SIM. The carrier has a chance to stop it. The agent could follow procedure, ask the right questions, refuse the request. Port out fraud skips that step. Your carrier has no agent to trick. They receive a legitimate port request from another carrier. They process it.

What makes this attack effective

The attacker does not need access to your phone, your email, or your accounts. They do not need to intercept anything. They just need information that is already available. The attack leaves no trail at your carrier: no unusual support ticket, no suspicious call log, no agent who remembers the interaction. Everything looks routine from the carrier's side. By the time you notice your phone is dead, the attacker has already moved on to account takeovers. Minutes matter. The window to react is small.

What is not known about this attack

No statistics exist on how often port out fraud occurs versus SIM swaps. No public data shows which carriers are most targeted. The frequency varies by region and by carrier security practices. Some carriers now offer port-out locks or PIN requirements. These are optional features. Most users do not enable them.

The attacker's identity is unknown in almost all cases. Port out fraud leaves no physical evidence and no digital trail back to the perpetrator. Recovery of lost accounts is possible. Recovery of the stolen identity is not.

Not financial advice. rosiesol.xyz publishes market data and general information about Rosie. Crypto assets are volatile and you can lose everything you put in. Nothing here is a recommendation to buy, sell or hold, and we make no price predictions.

Prices are sourced from third parties and may be delayed or wrong. Verify anything you intend to act on against a primary source.

Back to sim swaps