Your phone is the key to everything else. Here is how people try to take it.
Most phone fraud is not clever. It is a text that looks like your bank, a call that looks like your carrier, or a stranger who convinces a store clerk to move your number to their SIM. The defenses are boring and they work.
What is actually out there
A text with a link: a delivery problem, a bank alert, a refund. The link goes to a copy of a real login page and takes your password.
Someone talks a carrier into moving your number to their SIM. Your texts — including your login codes — start arriving on their phone.
The caller ID says your bank or your carrier. It is not. Anyone can print any number on a caller ID.
An app store lookalike, or a "security update" pushed from a web page. Installing it hands over everything on the phone.
Free airport or hotel Wi-Fi with no password. Traffic on it can be watched and, on badly built apps, changed.
You are told you were overcharged and asked to install remote-access software to "process the refund." Nobody legitimate does this.
SIM swap: the one that costs the most
A SIM swap is not a hack. It is a conversation: someone calls a carrier pretending to be you, gives your name, address and the last four of something, and asks for the number to be moved to a new SIM. When it works, every text code for every account you own goes to a stranger.
- Set a PIN on your line and do not share it. Your Mac Wireless account PIN is set at activation and can be changed from My Account. We ask for it before we change anything on a line.
- Use an authenticator app, not text codes, for your email, your bank and anything holding money.
- Treat a sudden loss of signal as an alarm. If your phone drops to "No Service" for no reason and stays there, call us from another phone.
Eight things worth doing today
- Turn on two-factor authentication with an app (not SMS) on email, banking and your phone-maker account.
- Use a password manager and stop reusing passwords. One breach elsewhere should not open your bank.
- Install updates the week they land — for the operating system and for the apps. Most attacks use holes that were already patched.
- Never tap a link in an unexpected message. Open the app or type the address yourself.
- Do not install anything from a link, only from the official app store. Check the developer name, not just the icon.
- Review app permissions once a quarter. Anything that wants contacts, location or SMS without a reason gets turned off.
- Back up the phone so a lost or wiped device is an inconvenience rather than a disaster.
- Lock your screen with a passcode of six digits or more, plus the face or fingerprint unlock.
What we do on our side
Your Mac Wireless account carries a PIN, and we ask for it before changing a line, moving a number or issuing a new SIM. Payments run through Stripe — we never see or store a full card number. When something changes on your account you get an email, so an unexpected message is itself a warning. If a number transfer request arrives that you did not start, it gets held and we call you.
We will never call or text you asking for your account PIN, your password, a one-time code, a gift card or remote access to your phone. If someone claiming to be Mac Wireless asks for any of those, hang up and call 866.729.9569.
If it already happened
- Call us right away at 866.729.9569 from any phone. We can suspend the line so nobody can use it, and lock the number against transfer.
- Change the passwords on your email first, then your bank, then everything else — from a device you trust.
- Tell your bank and card issuers and ask them to watch the accounts.
- Report it. The FTC takes reports at reportfraud.ftc.gov, and identity theft at identitytheft.gov. For a SIM swap or fraud involving money, file with the FBI's IC3 as well.
- Then clean up the phone: remove apps you do not recognize, review permissions and, where the phone was rooted or jailbroken, factory reset it.
Call 866.729.9569, Monday – Friday, 8 a.m. – 6 p.m. Central, and a specialist walks through it with you.
