The Plain Record

What things really cost, and why.

One reused password, four accounts, and the phone number that let it happen

Posted on by Emmett Rasmussenin Technology4 min read

A phone lying face down on a weathered picnic table beside a set of house keys, late afternoon light across the wood
A phone lying face down on a weathered picnic table beside a set of house keys, late afternoon light across the wood

A household discovered the problem on a Tuesday morning, when the phone stopped having service in the middle of a normal week. Not a dead battery and not an outage. The number had been ported to a different carrier and a different device, and by the time anyone understood that, two account recovery emails had already been sent and acted on.

The chain is worth laying out in order, because at each step the weak point was something ordinary that had been set up years earlier and never revisited.

The order it actually went in

It started with a breach at a retailer the household had used twice, years ago, and forgotten. The email address and a password came out of it. That password was reused, in a slightly altered form, at the household's main email account.

The altered form is the part people find surprising. Adding a number or a punctuation mark to a familiar password does not defeat anyone, because the tools used at this stage try those variations automatically. What defeats them is a password used nowhere else.

With the email account open, the attacker could see which banks, which brokerage, and which card issuers the household used, because all of it is in the inbox. Then came the phone number, obtained by contacting the carrier with enough personal information to pass a verification questionnaire and requesting a transfer to a new device.

Why the phone number was the weak link

Because so much recovery depends on it. Text message codes are the most widely deployed second factor in the country, meaning the extra step beyond a password, and they are secured by a carrier's customer service process rather than by anything cryptographic.

That process is designed to help people who genuinely lost a phone, which is a much larger group than people trying to steal one. The result is a system that is likely to be helpful and therefore possible to persuade. It is not a hypothetical weakness and it is also not the most common way accounts are lost, which is worth saying plainly. Most losses are still simple password reuse. The phone number is what turns a bad situation into a much worse one.

What stopped it, and what nearly did not

Two things. The brokerage account had a separate authentication app rather than text codes, meaning a code generated on the device itself with no carrier involved. That account was never reachable.

The bank held a transfer for review because the destination account was new and the amount was unusual for the household, and a person called the landline, which had not been touched in the port. That call is the reason this story has a manageable ending.

What nearly failed was the credit side. Two applications for new credit were submitted in the household's name in the same forty eight hours. Neither completed, but neither was blocked either. A freeze placed years earlier would have made them impossible rather than merely unsuccessful.

The protections that applied

Unauthorized electronic transfers from a consumer bank account carry federal protections, and the amount a consumer is responsible for depends substantially on how quickly the institution is notified. That is the single most important operational fact in this whole piece: reporting time affects liability, and the windows are measured in days.

Credit card fraud protections are stronger still, which is one reason paying for things by credit card rather than debit is a quiet form of risk management. Fraudulent accounts opened in your name are handled through a separate process involving reports to the credit bureaus and a report of identity theft.

None of these protections are automatic in the sense of requiring nothing from you. Each one starts with a notification you have to make, and the earlier the better.

The first hour, if it happens to you

Order matters here more than thoroughness, because the first hour is when the damage is still being done.

Get the phone number back first, from another phone, by calling the carrier and reporting an unauthorized port. Everything else depends on it. Then regain the email account, because email is the master key to every other account you own. Then call the bank and the card issuers on the numbers printed on the cards rather than any number in an email, and tell them the words unauthorized transaction, which starts a defined process on their side.

Write down the time of every call and the name of every person you speak to. That log is what settles any later argument about when you notified them, and notification timing is precisely what the liability rules turn on.

What the household changed

  • A password manager, and a genuinely different password everywhere, which is the single change that would have prevented the entire sequence.
  • An authentication app instead of text codes on every account that offers one, starting with email.
  • A port freeze or transfer PIN with the mobile carrier, which most carriers offer and almost nobody enables.
  • Credit frozen at all three bureaus, lifted only when applying for something.
  • A written list of which accounts exist and which email address each uses, kept on paper, because reconstructing that during a crisis is what costs the first day.

Likely versus merely possible

Worth keeping the two apart. Having your number ported is not likely. Having a reused password turn up in a breach is close to certain over a long enough period, and it is the step everything else depended on.

So the ranking is clear. Unique passwords first, because that addresses the likely case. An authentication app second, because it removes the phone number from the chain. Everything else after that. A household that does the first two has closed the path this attack actually took, and can treat the rest as maintenance rather than emergency.

About Emmett Rasmussen

Emmett writes about where household advice and professional practice diverge.

View all posts by Emmett Rasmussen

About the author

Emmett Rasmussen

Emmett writes about where household advice and professional practice diverge.

More from Emmett Rasmussen