Number portability is a consumer protection. It is why you can leave a carrier without leaving your number behind, and carriers are required to make it work. The side effect is that the process is built to be completed quickly by whoever supplies the right details — and the details are few. Cash App Mobile's own porting instructions are typical of the industry: to bring a number across you need your account number, your transfer PIN, and your billing ZIP code from your current carrier. That is the whole gate. Anyone holding those three can request your number, and if the request succeeds your phone loses service while theirs gains it.
Why three details are enough
Look at what the three are. Your billing ZIP code is not confidential — it is your address. Your account number appears on every bill and inside your carrier's app — Cash App Mobile spells out the same three requirements for anyone porting a number in. That leaves the transfer PIN as the only piece an attacker cannot simply look up, which means the entire security of your phone number rests on one short number that many people set once and forget.
This is why the attack is usually social rather than technical. The goal is to get you, or a carrier employee, to hand over the PIN or reset it. A caller claiming to be from your carrier's fraud department asking you to confirm your PIN is the classic version.
What it costs you
The number itself is rarely the target. The target is everything that trusts the number. Password resets and two-factor codes sent by text arrive at whichever device holds the number, so once it moves, an attacker can begin resetting email, then anything secured by that email. This is the reason a phone number is a poor second factor and the reason losing one is not a minor inconvenience.
Six things worth doing
- Set a dedicated port-out or transfer PIN with your carrier, and make it different from your voicemail PIN and your account password.
- Ask your carrier what additional account-lock or port-freeze option it offers, and turn it on. The names differ by carrier; the function is to require extra verification before a number can leave.
- Move two-factor authentication off SMS wherever a service allows it. An authenticator app or a hardware key cannot be ported away.
- Never confirm a PIN, code or account number to someone who called you. Hang up and call the number on your bill.
- Keep the email address tied to your carrier account on a separate password from everything else, since that inbox can authorise account changes.
- If you are switching carriers deliberately, generate a fresh transfer PIN for the port and change it again afterwards.
If it has already happened
Call your carrier from any working phone and tell them the number was ported without authorisation — that specific wording routes you to the right team faster than describing an outage. Ask them to reverse the port and to lock the account. Then, in this order, secure your primary email, then any financial account that used SMS codes, then everything else. Numbers can usually be recovered, but the accounts reached through them in the meantime are the actual damage.
It is also worth reporting. Unauthorised port-outs are a regulated matter, and carriers are subject to rules on how they verify these requests — a complaint creates a record that a reversal request alone does not.
Jean Gilles has researched personal finance, consumer technology, and wireless pricing for over a decade. He founded ShopCellPlans in 2019 and writes every review on the site.
Frequently asked questions
What is SIM swapping? +
What does someone need to steal my number? +
How do I know it is happening? +
Is a port-out PIN the same as my voicemail PIN? +
Why is SMS two-factor a problem? +
Can I get my number back? +
One email when a carrier raises rates, drops a plan, or launches a deal worth switching for. No spam, unsubscribe anytime.
- Cash App Mobile support documentation, number-transfer requirements (account number, transfer PIN, billing ZIP code) — checked 3 September 2026
- Metro by T-Mobile prepaid phone plans page, Scam Shield inclusion — checked 3 September 2026



