@TheAbbotTrithemius ask your network provider to add a pin/pw to your account
Every major US/UK carrier offers you the option of putting a PIN or a passcode on your account. Take them up on it.
some networks won't offer this so you have to call them up and ask
more here
@TheAbbotTrithemius
The basic lesson here is to understand that any device under control of someone else should not be used as a second factor for important authentication, unless you completely trust that other organization. Never trust Apple, Microsoft, Google, Facebook, Twitter, T-Mobile, etc. to secure your important information. If you read the User Agreements...THEY tell you not to trust them to secure your data and identity, because they won't!
@TheAbbotTrithemius
I'm not clear on the initial step. How was the SIM card ported to the attacker's device. Did they just call up AT&T and Ernestine the Operator took them at their word?