A phone number has become an identity credential for password resets and login codes. That makes the carrier account holding it a target in its own right.

The number is portable by design

Federal rules require that customers be able to move their number between carriers, and carriers must make that process reasonably fast and frictionless.

The same machinery lets a number move to a new SIM or an eSIM profile on a different device, which is routine when someone upgrades or loses a phone.

An attacker does not defeat this system. They use it, having convinced the carrier that they are the customer requesting a normal transfer.

Retail identity checks were designed for convenience

Store and call-center staff verify account holders using information that is widely available or guessable: address, billing details, partial identifiers and account history.

Those checks exist to help genuine customers who have lost access, and they are deliberately forgiving because false refusals generate complaints and churn.

Social engineering exploits that tolerance rather than any technical flaw. The system behaves exactly as specified while producing the wrong outcome.

Why the second factor fails once the number moves

Codes sent by text arrive wherever the number currently terminates. Control of the number is control of the factor, with no additional step required.

Account recovery flows compound this, because many services treat a verified phone number as sufficient to reset a password entirely.

The result is that a single successful transfer can cascade through email, financial and cloud accounts within a short window.

Carrier-side locks are the effective control

Carriers now offer number-transfer locks, port-out PINs and account-change alerts that must be cleared before a transfer is processed.

These sit where the attack happens, which is why they help more than anything done on the handset. Regulators have pushed operators toward making them standard.

They are not automatic on legacy accounts, and they can be undone through the same support channels, so their strength depends on how strictly the carrier enforces them.

Moving off text-based codes is the durable fix

Authenticator applications and hardware security keys generate or hold their factor locally, so a transferred number does not carry them.

Passkeys go further by binding the credential to a device and a service, removing the shared secret that a reset flow could otherwise expose.

The migration is uneven because many services still treat the phone number as a fallback. A stronger factor added alongside a weak recovery path inherits the weaker one's strength.