The Night the Phone Went Dark

At dinner one January evening in 2018, the investor Michael Terpin glanced at his phone and saw something unremarkable: no bars. A dead spot, he figured. Restaurants are like that.
By the time he understood what had happened, roughly $24 million was gone.
He hadn't lost a password. He hadn't clicked a poisoned link or downloaded anything. He'd lost his phone number — and a young man three time zones away was using it to walk through the front door of his accounts, one "forgot password" at a time.
The crime is called a SIM swap, and it's disarmingly simple. Every phone number lives on a small chip that a carrier can move from one device to another with a few keystrokes. That's a convenience — it's how you keep your number when you upgrade your phone. It's also the entire exploit. A stranger calls your mobile carrier, says he's you, recites a few details scraped from a data breach or your own Instagram, and asks to activate a new phone. The instant the agent agrees, your number goes dark on your device and lights up on his.
Then he starts collecting. Email first, because email is the skeleton key. He clicks "forgot my password," a six-digit code arrives by text to a phone that is now his, and your inbox is his. From there it's your bank, your brokerage, your wallet. The texted code you were told kept you safe is the exact thing handed to the thief.
Terpin wasn't careless, and he wasn't alone. In 2019 a young man named Joel Ortiz became the first person in America convicted of SIM swapping; he had stolen millions from strangers and was sentenced to ten years. The FBI started counting, and the count is ugly. From 2018 through 2020, Americans reported about $12 million in SIM-swap losses. In 2021 alone, they reported $68 million — nearly six times as much in a single year.
Terpin had the money and the will to chase it — private investigators, lawyers, years of effort. He tracked down the people who robbed him and took them to court. One of them, a young man named Nicholas Truglia, was ordered to pay the money back and simply refused — he went to prison rather than return it. Terpin did recover some of it from another of the thieves, but only after years of fighting and a fortune in legal bills. That is the hard part: even when you catch the person who robbed you, getting your money back is a long, expensive, uncertain fight — and most people never get it back at all.
Here's the part that should change how you think. SIM swapping doesn't work because criminals got smarter than your password. It works because they stopped attacking your password at all. Why pick a lock when the spare key is under the mat — a phone number you've printed on business cards, typed into a thousand forms, and read aloud across store counters for twenty years? The thing that makes you reachable makes you reachable to everyone.
The defense, mercifully, is dull. Move the accounts that matter off text-message codes and onto an authenticator app or a physical security key — a small object a thief three time zones away cannot hold. Call your carrier and add a port freeze so your number can't be moved without a PIN. An afternoon, once, and then it's simply done.
Michael Terpin's phone lost its signal at dinner, and his fortune followed it out the door. Nothing about that night required genius, or malware, or him doing a single thing wrong.
They didn't break his password. They just asked the phone company to be him — and the phone company said yes.
