Desk live·
ForensicPost
Nation-state/Infrastructure/File 26-0205

The Phone Number Became National Identity Infrastructure by Accident

A mobile number is now the recovery channel for banking, email, government services and cryptocurrency. Nothing about the telephone numbering system was designed for that.

Constructed geometry · not a chart of case data
TargetAccount recovery infrastructure
ActorMultiple
S. Rosler12 min readConfidence: medium2 sources reviewed

A telephone number identifies a billing relationship with a carrier. That is what it was designed to do. It now also functions as the recovery channel for a substantial share of a person’s digital life — banking, email, government portals, exchanges.

Nobody decided this. It happened because SMS was universally available and cheap, and every service adopting it made a locally reasonable choice.

The Dependency Is One-Directional And Invisible

A bank relying on a number for recovery has no relationship with the carrier, no visibility of a port request, and no notification when the subscriber changes. It is trusting an assertion controlled by a third party it has never contracted with.

That is why the SIM swap figures at 26-0120 understate the harm. The reported losses are direct theft; the accounts reached afterwards are recorded, if at all, as unrelated incidents.

Every Party Is Behaving Reasonably

The carrier is meeting portability obligations. The bank is using a widely accepted factor. The regulator has protected consumers’ right to switch provider. The subscriber has done nothing.

It is the coordination failure this desk described for vulnerability disclosure at 26-0307, in a different domain: an aggregate exposure produced by parties each acting correctly within their own remit, with nobody positioned to see or own the total.

The Fix Is Known And Slow

Phishing-resistant authentication that does not rely on a number removes the dependency entirely, and adoption is rising. It is not universal, and the accounts most at risk — held by people who cannot easily manage a hardware key — will be last.

Until then, the security of a great many high-value accounts rests on a customer service process at a mobile operator, which is not a control any of the depending services chose or can audit.

How we reported this

This is an analysis file built on published research and regulatory material, listed below. The framing is ours and labelled as such. Corrections: corrections@forensicpost.com.

Sources
  1. A deep dive into the growing threat of SIM swap fraudThomson Reuters Institute
  2. SIM swap scams can be devastatingPIRG
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary