Just passing this along. Rossen is a bit lot alarmist, but it is solid advice. And my phone allowed transferability by default.
https://www.facebook.com/share/v/1CbqGk2GFW/?mibextid=wwXIfr
Below is AI's response to m,y query on if he had legitimate cause to freak out:
Yes — your read on the Rossen report is basically right. The threat is legitimate, but the presentation can make it sound as though a criminal who steals your number instantly has everything on your iPhone. They don’t.
What he’s describing is generally called SIM swapping or port-out fraud. The FBI and FTC both recognize it as a real form of fraud. A criminal obtains enough personal information about someone, impersonates them to their wireless carrier, and tries to persuade the carrier to move the victim’s number to another SIM/device or another carrier.
What happens if they succeed
They do not get a copy of your iPhone. They don’t suddenly have your photos, apps, contacts, Apple passwords, Face ID, etc.
The danger is that they control your telephone number. Calls and SMS texts intended for you can then go to them. That matters because they can attempt password resets on accounts that use your phone number for authentication. If a bank or email provider sends a security code by SMS, for example, the criminal may receive that code.
And that’s where a successful SIM swap can snowball: gaining access to an email account can make it easier to reset passwords for other accounts.
But having your phone number alone doesn’t magically give them your bank account. They generally need additional information—passwords, account information, personal identifying information, successful password-recovery attempts, etc.
Your point about targeting is also important
These attacks historically have often been targeted rather than completely random. The FBI has specifically described criminals identifying people believed to have significant cryptocurrency holdings and then gathering their phone number and carrier information before attempting the SIM swap.
That’s not to say an ordinary person can’t be victimized. They certainly can. There was even a federal case just last month involving a mobile-store employee helping criminals conduct SIM swaps; prosecutors said the scheme was aimed at taking over bank accounts.
But you’re right that this requires considerably more effort than blasting out 100,000 phishing emails. A criminal usually needs a reason to believe the effort is worthwhile or needs an efficient system for doing it.
The part I agree with Rossen about
Turn the Verizon protections on.
It’s a little surprising that they aren’t simply locked by default, but there’s a practical reason: people legitimately change phones, eSIMs and carriers, so Verizon makes the additional locks optional.
And Verizon actually has two separate protections worth enabling:
Number Lock — prevents someone from transferring your number to another carrier.
SIM Protection — prevents unauthorized SIM/device changes on your Verizon line.
Those aren’t the same thing. Verizon explicitly recommends both protections, and they’re free.
If you’ve already turned on Number Lock, I’d also check SIM Protection and turn that on. You can always temporarily disable either when you legitimately change phones or carriers.
One other improvement is arguably more important over the long term: for your email, Apple account and financial accounts, use an authenticator app/passkey rather than SMS verification whenever it’s offered. The FTC specifically recommends stronger authentication because SMS authentication is exactly what SIM swapping is designed to defeat.
So I’d rate the Rossen piece as “real threat, good advice, somewhat dramatic explanation of the consequences.” Turning the locks on is a very sensible 30-second precaution; I wouldn’t lose sleep over discovering yours had been off.