SardineCon SF/2026

Learn More
Scams & social engineering4 分で読めます

Port-out fraudとは?

SUBSCRIBE

Port-out fraud is moving a victim's phone number to a carrier or SIM the fraudster controls, so text one-time codes and calls route to the attacker and open the door to account takeover. It works because so many accounts still lean on SMS codes as a security backstop, and whoever controls the number controls those codes.

What is port-out fraud, in plain English?

Port-out fraud abuses number portability, the legitimate feature that lets you keep your phone number when you switch carriers. The fraudster gathers enough personal data on the victim, then requests a port to a new carrier or device under the victim's name. If the transfer goes through, the victim's number now rings and receives texts on the attacker's phone.

That single move breaks a control millions of accounts rely on. With the number in hand, the attacker triggers password resets and one-time codes for email, banking, and crypto accounts, receives those codes by text, and takes over. The victim, meanwhile, notices their phone has gone dead with no service, usually after the damage has started.

In the fraud stack, port-out fraud is a form of number hijacking and a close cousin of SIM swap. The difference is the method: SIM swap reassigns the number to a new SIM within the same carrier, while port-out moves the number to a different carrier entirely through the porting process.

Port-out fraud versus SIM swap

What changes

SIM swap

Port-out fraud

The mechanism

Number moved to a new SIM on the same carrier

Number ported to a different carrier

Who is tricked

The current carrier or a store employee

The gaining carrier's porting process

The result

Attacker's SIM receives the number

Attacker's account at a new carrier holds the number

Key defense

Carrier PIN and account lock

Port-freeze or port-out PIN

How a port-out attack works

  1. Gather — Collect the data. The attacker phishes or buys the victim's name, number, account details, and any port PIN they can find.
  2. Request — Initiate the port. Posing as the victim, they ask a new carrier to port the number to a device or SIM they control.
  3. Capture — Redirect codes. Once the port completes, texts and calls, including one-time codes, arrive on the attacker's phone.
  4. Take over — Reset and drain. They reset passwords and pass SMS verification to seize email, bank, and crypto accounts.

What it looks like in practice

In practice

A customer's phone abruptly loses all service on a weekday afternoon and shows no signal even after a restart. They assume it is a network outage. In the background, their number has been ported to a new carrier by someone using their stolen details.

Within the hour, the attacker resets the customer's email password using an SMS code, then works through to online banking and a crypto exchange, each protected only by a text code that now lands on the attacker's device. By the time the customer reaches a store to investigate the dead phone, several password resets and a fund transfer have already gone through.

Why it matters for operators

Port-out fraud turns the phone number, treated by many systems as a trusted identity anchor, into a single point of failure. Once the number is hijacked, SMS-based multi-factor stops protecting anything, and the attacker inherits the victim's reset paths across email, banking, and crypto. The strongest defenses reduce reliance on the number itself: move customers to app-based or phishing-resistant authentication, and encourage carrier-side protections like a port-freeze or port-out PIN.

On the detection side, the tell is often a burst of high-risk activity right after a device or SIM change: password resets, new-device logins, and beneficiary edits clustered in a short window. Treating a recent SIM or number change as a risk signal, and stepping up verification before honoring resets, buys time to catch the takeover in progress.

What to watch for

  • Sudden loss of service. A customer reporting their phone went dead with no signal is a classic sign the number was ported away.
  • Reset storms after a SIM change. Clusters of password resets and new-device logins soon after a number or device change point to hijacking.
  • SMS codes from new devices. One-time codes being satisfied on a device the customer does not recognize suggest the number moved.
  • Failed logins then success. A run of failed attempts followed by a clean SMS-verified login can mark a completed port-out.
  • High-value targets. Customers with crypto or large balances are prime targets, so weight number-change signals more heavily for them.

Quick questions

How is port-out fraud different from SIM swap?

Both hijack the number, but SIM swap reassigns it to a new SIM within the same carrier, while port-out moves it to a different carrier through the porting process. The outcome is the same: the attacker receives the victim's texts and calls.

What is a port-out PIN?

It is a separate passcode a carrier requires before transferring your number to another provider. Setting one makes it much harder for an attacker to port your number using only your name and account details.

Why is SMS two-factor the weak point?

SMS codes go wherever the number goes. Once the number is ported to the attacker, every account that verifies by text becomes reachable, which is why moving off SMS to app-based or phishing-resistant methods matters.

What is the first sign a victim usually notices?

A sudden and unexplained loss of mobile service, since the number no longer belongs to their device. Failed logins and unexpected account alerts often follow closely.

How can institutions reduce it?

Reduce dependence on SMS verification, treat a recent SIM or number change as elevated risk, step up verification before honoring password resets, and encourage customers to set carrier port protections.

What should a victim do immediately?

Contact the carrier to reclaim the number, then change passwords on email and financial accounts from a secure device and alert those providers to watch for takeover. Speed matters because resets happen fast.

Go deeper

  • FTC Consumer Advice: Scams ↗ — US consumer guidance on current scams and fraud, and how to report them.
  • FBI IC3 ↗ — The FBI Internet Crime Complaint Center. Fraud reporting and annual trend reports.

Port-out fraudと併せて知っておきたい用語