30 Minutes of silence cost a verizon user their phone number and nearly their bank balance

A Reddit user walked into a Verizon store with a fake ID and walked out with someone else’s digits. Half an hour later the real customer—phone still on silent—lost service, then got a cascade of password-reset emails from their bank. SIM-swap fraud is supposed to be yesterday’s problem; yesterday just called to say it’s back.

The fake id that slipped through two layers of verification

Verizon’s own playbook demands a PIN or a government photo ID before any SIM change. Yet the clerk accepted the forged license, the computer matched the name on the account, and the swap sailed through. Company literature calls this a “two-rep check,” but in practice one employee clicked override after the customer “forgot” their PIN. The second rep, if there was one, appears to have rubber-stamped the override from across the store.

Number Lock and SIM Protection—Verizon’s optional roadblocks—were disabled on the victim’s line. They are buried in the My Verizon app under “Security,” off by default, and advertised only to customers who click deep enough to find them. Most never do.

Why the 30-minute window still exists

Why the 30-minute window still exists

Once the swap request hit the tower, Verizon pinged the old SIM with a series of “Reply STOP to cancel” texts. The victim, at lunch with the phone face-down, missed the blizzard of alerts. Industry standard treats silence as consent; the attacker’s new SIM activated automatically. Carriers call this a “customer convenience” feature. Fraudsters call it lunch money.

European operators solved this years ago: a 24-hour cooling-off period for any SIM change, push notification to every registered device, and a voice call that must be answered. U.S. carriers rejected the wait time, citing retail throughput and customer churn. The result is a marketplace where convenience for the hurried shopper doubles as an express lane for criminals.

The buck stops nowhere—until it stops with you

The buck stops nowhere—until it stops with you

Verizon’s boilerplate response: “We follow federal ID standards and remind customers to activate security tools.” Translation: we gave you the keys, you left them on the counter. Regulators have fined T-Mobile and AT&T for similar breaches, but the penalties amount to hours of quarterly revenue. Until silence is no longer interpreted as approval, the easiest patch is the one consumers must apply themselves: open the app, flip the toggle, lock the number. Otherwise the next 30-minute window is only a fake ID and a sleepy lunch hour away.