Join our Newsletter — 33% off our NHI Course
Home› FAQ› Authentication, Authorisation & Trust› What happens when an account reset depends on…
Authentication, Authorisation & Trust

What happens when an account reset depends on a texted OTP after a porting attack?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 25, 2026 Domain: Authentication, Authorisation & Trust

Once a number is ported, the fraudster can receive the OTP instead of the victim. If the OTP is required for password reset or step-up authentication, the attacker can complete the possession check, reset the password, and take over the account. The result is rapid account takeover, often before the victim notices the phone service disruption.

Why texted OTP creates a takeover path after porting

A porting attack breaks the assumption that a phone number still belongs to the real user. Once the number is moved, the attacker receives the SMS OTP and can satisfy any reset or step-up flow that treats possession of that code as proof of account control. The security failure is not the port itself, but the way the reset path still trusts the number as an authentic factor.

In practice, this makes the account recovery flow a high-value target because password resets are often designed to be fast and low-friction. If the OTP is the only gate, or the only gate before a password change, the attacker does not need the victim’s existing password or device session. They only need the diverted message and enough time to complete the reset before the victim notices the phone service change.

What the attacker gains once the OTP is intercepted

With control of the texted OTP, the attacker can usually complete the same recovery steps the legitimate user would have completed, including confirming possession, setting a new password, and invalidating the victim’s access. That can also break downstream controls that rely on the original session, because many systems treat a successful reset as a trusted account event.

If the account is tied to email, cloud services, payment apps, or enterprise portals, takeover can quickly become broader than the first login. The attacker may use the reset to change recovery options, add new trusted devices, or move to step-up flows on other services that still trust the same phone number or email chain. The practical consequence is that a single diverted OTP can become an entry point into multiple linked systems.

Why this failure is especially severe for recovery and step-up flows

Recovery and step-up authentication are often built to resolve uncertainty, so they tend to favor availability and user convenience. That is appropriate only when the possession factor is itself hard to divert. When a phone number is the possession factor, number porting turns that assumption into a liability because the channel can be reassigned outside the victim’s control.

The result is a mismatch between the control’s design and the threat model. A reset flow that is safe against password guessing may still be weak against telecommunications takeover. When the factor used to restore access is also the factor most easily hijacked during account recovery, the control stops being a safeguard and becomes the attacker’s fastest route in.

Risk and Threat Considerations

This pattern creates a direct account takeover risk because the recovery path itself becomes the compromise path. The victim may lose access before any suspicious login alert fires, and the attacker can often move faster by changing credentials, recovery data, and linked sessions immediately after the reset.

Failure mechanism: the system accepts SMS OTP delivery to the ported number as proof of user control, so the attacker inherits the reset channel and completes the password reset or step-up process.

Impact: the attacker can seize the account, lock out the victim, and use the compromised account to access connected services, reset further credentials, or impersonate the user in trusted workflows.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while CIS Controls v8, NIST SP 800-53 Rev 5 and OWASP ASVS set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationSMS OTP resets are vulnerable when the delivery channel is diverted.
NHI-07 — Long-Lived SecretsReset-dependent OTP paths often persist as reusable recovery secrets.
Recommendation — Use stronger recovery factors than texted OTP for account reset flows. Shorten recovery-secret lifetime and rotate any exposed reset credentials immediately.
CIS Controls v8CIS-6 — Access Control ManagementThe issue is unauthorized access through a weak recovery path.
Recommendation — Restrict high-risk recovery paths and review who can regain access after compromise.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementOTP-based reset flows depend on authenticators whose lifecycle and strength must be managed.
Recommendation — Manage recovery authenticators so a diverted number cannot satisfy account reset.
OWASP ASVSV6 — AuthenticationThe scenario is a failure of authentication during password reset and step-up.
Recommendation — Verify that reset and step-up flows do not rely on easily diverted SMS codes.

Practitioner Guidance

What to verify: Treat SMS-delivered OTP as a weak recovery factor wherever a porting event can redirect it. The key question is not whether the code was “correct,” but whether the channel delivering the code could have been reassigned without the user’s knowledge.

Decision rule: If a password reset or privileged step-up depends on a phone number alone, require a stronger out-of-band recovery path for high-value accounts, especially where account compromise would expose money, data, or administrative access. If the account is business-critical, assume the reset path will be targeted first.

What practitioners underestimate: The race condition matters. Porting attacks are dangerous because they combine silent channel redirection with fast credential replacement, so by the time the victim reports the missing service, the attacker may already control the account and its recovery settings.

Practitioner takeaway: Recovery controls must be harder to hijack than the account they protect; if the reset factor can be ported, it should not be the only thing standing between the attacker and a new password.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 25, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org