A shopkeeper in Mirpur comes home from Friday prayers and sees that his phone has no signal. He blames the network, as most of us would. By the time he gets to a service centre the next morning, his mobile wallet is empty, he's locked out of Facebook, and three of his cousins have received messages from "him" asking for money.
The shopkeeper is invented, but the sequence is a familiar one. And none of it took clever hacking. Whoever did this only needed his number.
It's worth stopping to think about how much a Bangladeshi phone number carries these days. It receives the one-time password for your wallet. It's how you get back into Facebook when you forget your password, how WhatsApp knows it's you, how the courier confirms your parcel.
Banks lean on it more every year. We built one of the most phone-dependent economies anywhere, and somewhere along the way, 11 digits became the key to nearly everything. Nobody planned it. It just happened.
Attackers noticed long before users did. In my years running security work in Silicon Valley, I saw them go after whatever opened the most doors, again and again. Here, that's the SIM.
Most of the time they don't even have to take it, because we hand it over.
Someone calls, says he's from your wallet provider, warns that your account will be suspended, and asks you to read out the code you've just received.
Or a message arrives: Sorry, I sent my code to your number by mistake, could you forward it?
These tricks work because Bangladeshis are, on the whole, helpful people who trust a polite voice.
A real provider will never ask for your PIN or OTP. Not by phone, not by SMS, and not through a relative who says the company told them to.
When a fraudster can't talk the code out of you, he may go after the SIM itself and get a replacement issued in your name.
Biometric SIM registration made that much harder. I worked on those systems, and it was a real step forward that many wealthier countries still haven't taken.
It didn't make it impossible, though. Forged papers, a bribed insider, or a careless recovery process can still get someone through.
What you'd notice is your phone going dead while everyone around you still has signal. Most people wait a day before dealing with that, and a day is more than enough.
Then there are the apps: A cracked game, an "update" someone forwarded on WhatsApp, a free copy of something that normally costs money.
Some of these ask to read your SMS, or to use Android's accessibility features, which were built for people with disabilities and let an app see and tap whatever is on your screen.
Say yes, and the app can read your OTPs as they arrive. You never share anything. It simply watches.
What should people actually do?
Start with the OTP. Treat it like cash, and don't give it to anyone, including someone who sounds exactly like a family member.
Put a PIN on WhatsApp through their two-step verification settings, which takes about two minutes.
If your signal drops for no obvious reason, call your operator from someone else's phone within the hour, and let your wallet provider know too.
Get your apps from the Play Store, and when a torch app asks to read your messages, ask yourself why.
Finally, have one conversation at home about a family code word, something only you would know, to ask for whenever money comes up. It sounds like something out of a movie, but it costs nothing and it works.
Still, it isn't fair to leave all of this to individuals. A phone number was never meant to prove who someone is on its own.
In several countries, banks and mobile operators have started passing each other one simple piece of information: Has this SIM been replaced in the past few days? If it has, the large transfer waits until someone checks.
Bangladesh has already done the hard part with biometric registration, so it could do this more easily than most.
The same thinking applies inside the phone. Security that catches a malicious app before it gets anywhere near a wallet or banking app should come as standard, rather than something people discover after they've been robbed.
October is Cybersecurity Awareness Month. We tend to measure how digital Bangladesh is by how many people are online. A better measure might be how many of them feel safe once they get there.
Everyone who loses money this way tells their family, their neighbours, the regulars at the tea stall. Each story makes the next person a little warier of going digital, and that wariness takes a long time to wear off.
The number is already our identity. We just haven't started treating it that way.
Zeeshan R Khan led a security practice at Cisco for more than 12 years and is based in Silicon Valley. He is the founder of SurroundApps, which builds mobile security and family-safety technology for Bangladesh.