Yes, someone can hack your bank account with your phone number, though not by dialing it. The attack works by taking control of the number itself through your wireless carrier, then using the text-message verification codes your bank sends to reset your password and authorize transfers. It usually plays out in hours, and how much money you get back depends almost entirely on how fast you report it.
How a Criminal Takes Over Your Number
Two methods do most of the damage. In a SIM swap, the attacker calls your carrier, impersonates you using personal details pulled from breaches, social media, or public records, and asks to activate your number on a SIM card in their possession. Once the carrier processes the request, your phone loses service and every call and text meant for you routes to the attacker’s device.
Port-out fraud is the same idea across carriers. The attacker uses your account number and transfer PIN, usually obtained through phishing or by manipulating a customer service rep, to move your number to a carrier they control. Either way, your number is theirs for as long as it takes you to notice and reclaim it.
FCC rules that took effect in January 2024 require carriers to authenticate you securely before processing any SIM change or port-out and to notify you immediately when either is requested.1Federal Register. Protecting Consumers from SIM-Swap and Port-Out Fraud The rules raised the bar. They did not close the door. If your phone suddenly loses service for no reason you can explain, treat that as the warning sign it is.
Why the Text-Message Code Is the Weak Point
Banks lean on SMS one-time codes to verify logins from new devices and to approve large transfers. The logic is that only the person holding your phone can read the code. When an attacker controls the number, that logic collapses. Every code that was supposed to prove your identity now proves theirs.
The password reset is worse than the login. An attacker who receives your texts can go to the bank’s website, click “forgot password,” and have a reset code sent by SMS. They never needed your original password. They set a new one, lock you out, and change the contact details so your recovery attempts fail. From there, moving money is the easy part.
NIST, the federal agency that writes cybersecurity standards for government systems, has flagged SMS-based authentication as deprecated in its digital identity guidelines and cautioned against relying on it for high-security uses. Banks have kept it because customers are used to it, but any verification tied only to your phone number is defeatable by anyone who takes your number.
What You Can Lose, and How Fast You Have to Report It
Federal law caps your liability for unauthorized electronic transfers, but the cap depends on your timing. Regulation E ties everything to when you notify the bank after learning about the problem.2eCFR. 12 CFR 1005.6 – Liability of Consumer for Unauthorized Transfers
- Report within two business days of learning of the loss or theft, and your maximum liability is $50 or the total unauthorized amount before you reported, whichever is less.
- Report after two business days but within 60 days of the statement showing the transfers, and your liability can climb to $500, including transfers the bank can show would have been prevented by earlier notice.
- Report more than 60 days after the statement was sent, and you can be liable for the full amount of any unauthorized transfers that occurred after that 60-day window, with no cap.
That last tier is where people lose life-changing sums. If a bank can extend the reporting window because circumstances kept you from noticing, it is supposed to allow a reasonable additional period, but the burden is on you to show why.2eCFR. 12 CFR 1005.6 – Liability of Consumer for Unauthorized Transfers
Once you file a claim, the bank generally has 10 business days to investigate and resolve it. It can extend the investigation to 45 calendar days, but only if it provisionally credits your account within the first 10 business days so you can use the disputed funds while the review continues.3eCFR. 12 CFR 1005.11 – Procedures for Resolving Errors
What to Do the Moment Your Number Goes Dead
Every minute the attacker holds your number, they can intercept another verification code. Move in this order.
Get Your Number Back
Contact your carrier’s fraud department. You will need to verify your identity, usually with government-issued ID and a new PIN, to reclaim the number and get it ported back to a SIM you control. If your line is dead and you cannot call, walk into a physical store with your ID. Reclaiming the number cuts off the attacker’s stream of codes.
Lock Down Your Bank Accounts
Call every bank and financial institution that has your phone number on file. Ask for a temporary hold on outgoing transfers and a fraud flag on the account. Request a review of recent transactions while the details are still fresh. Change your passwords from a device you know is secure, and do not use SMS reset codes to do it.
File the Reports That Preserve Your Rights
File an identity theft report at IdentityTheft.gov through the Federal Trade Commission. That report is a legal record you can use with banks and creditors when disputing charges.4Federal Trade Commission. Businesses Must Provide Victims and Law Enforcement with Transaction Records Relating to Identity Theft File a police report as well. Some banks and creditors will not process a dispute without a case number from law enforcement.
Freeze Your Credit
Place a credit freeze at Equifax, Experian, and TransUnion. A freeze blocks new credit accounts from being opened in your name and stays in place until you lift it. Freezing and unfreezing are free under federal law.5Consumer Financial Protection Bureau. What Is a Credit Freeze or Security Freeze on My Credit Report A fraud alert is a lighter option that requires lenders to verify your identity before extending credit. An initial fraud alert lasts one year; an extended alert for confirmed identity theft victims lasts seven.6Consumer Advice – FTC. Credit Freezes and Fraud Alerts
Block a Fraudulent Tax Return
If the attacker has your Social Security number, a fake tax return in your name is a real risk. Request an Identity Protection PIN from the IRS. Any taxpayer with a Social Security number or ITIN can enroll through their IRS online account. The PIN is a six-digit number that must appear on your federal return; without it, a return filed under your Social Security number is rejected.7Internal Revenue Service. Get an Identity Protection PIN A new PIN is issued each calendar year, retrievable from your IRS online account starting in mid-January.
How to Make the Attack Fail Before It Starts
Most of these steps take minutes and cost nothing, and each one weakens the chain the attacker has to break.
Move Off SMS Verification
If your bank offers an authenticator app for two-factor authentication, switch to it. Apps like Google Authenticator or Authy generate codes tied to your physical device that refresh every 15 to 30 seconds. The codes never cross the cellular network, so a number hijack yields nothing. Some banks also support passkeys, which use your device’s biometrics or a physical security key. Either option removes the SIM-swap vulnerability from the equation.
Turn On a Port-Out Lock
Most major carriers offer a free number lock or port freeze that blocks any SIM change or carrier transfer until you disable the lock yourself. You can usually enable it in the carrier’s app or website. This gives you a second line of defense that does not depend on a customer service employee correctly following the FCC’s authentication procedure.1Federal Register. Protecting Consumers from SIM-Swap and Port-Out Fraud
Set a Unique Carrier PIN
Your wireless account should have a PIN or passcode that is different from any other password you use. Skip your birthday, the last four of your Social Security number, and anything else that appears in public records. That PIN is exactly what an attacker needs to impersonate you on a support call, so unpredictability is the point.
Watch Your Statements and Set Alerts
The Regulation E liability tiers reset from the date you notice and report unauthorized transfers, so checking your statements is the mechanism that keeps your legal protections intact. Wait more than 60 days after a statement is sent and your liability for later transfers can become unlimited.2eCFR. 12 CFR 1005.6 – Liability of Consumer for Unauthorized Transfers Most banks offer real-time transaction alerts by email or push notification. Turn them on.