Live data from Hacker News

Two Charged in SIM Swapping, Vishing Scams

krebsonsecurity.com

1–10 of 71 posts

Re: Two Charged in SIM Swapping, Vishing Scams

#3

Ah yes, of course they were only caught because the two had a falling out and then one swatted the other.

lmao, I want to know how the incident response was. Can't find an article on that. The indictments make it seem like the authorities immediately laughed and charged them both.

Re: Two Charged in SIM Swapping, Vishing Scams

#4
I'm a blockchain pro and there was a couple month period in 2017 when tons of people I know got SIM swapped including me. The T-Mobile call person kept asking me "Are you sure you didn't go into a store in Detroit and ask for your phone to be changed? They showed an ID!" No, I didn't do that.

Luckily I had 2-factor for everything, but I know some people who lost a lot. SMS is totally broken, use 2FA and hardware key if you can.

The craziest one was two people at another firm were sending each other a lot of money, and sent the address over Telegram. The hacker manipulated the address in the message - they checked after the (failed) transaction and the address sent was different than the address in the message received! I think the most likely cause was that the receiver's computer was rooted and the application itself was manipulated on the device, rather than the message contents changed en-route. This is why I recommend both visual and audio confirmation when sending large amounts.

Re: Two Charged in SIM Swapping, Vishing Scams

#5
post #4

I'm a blockchain pro and there was a couple month period in 2017 when tons of people I know got SIM swapped including me. The T-Mobile call person kept asking me "Are you sure you didn't go into a store in Detroit and ask for your phone to be changed? They showed an ID!" No, I didn't do that. Luckily I had 2-factor for everything, but I know some people who lost a lot. SMS is totally broken, use 2FA and hardware key…

I was also the victim of a T-Mobile SIM swap back in February.

My assumption is that the attackers target individuals that have a high likelihood of owning bitcoin or other digital currency. This can be easily determined by looking at data breaches, and targeting emails that are found both on a cryptocurrency breach and a personal information breach with phone number, name, address, and anything else that would help impersonate the victim.

They accessed my insecure email with SMS authentication, but everything else was locked down more securely. Also, since that day I have been getting 20 times more spam calls and texts, I'm guessing they added my number to some other targeted list.

Re: Two Charged in SIM Swapping, Vishing Scams

#6
post #4

I'm a blockchain pro and there was a couple month period in 2017 when tons of people I know got SIM swapped including me. The T-Mobile call person kept asking me "Are you sure you didn't go into a store in Detroit and ask for your phone to be changed? They showed an ID!" No, I didn't do that. Luckily I had 2-factor for everything, but I know some people who lost a lot. SMS is totally broken, use 2FA and hardware key…

Why are the phone companies not responsible for swapping the number over?

In a similar vein, I've known people who had unsigned checks stolen and their signature forged very poorly. The banks are supposed to check the signature, so why aren't the banks liable?

Re: Two Charged in SIM Swapping, Vishing Scams

#7
post #4

I'm a blockchain pro and there was a couple month period in 2017 when tons of people I know got SIM swapped including me. The T-Mobile call person kept asking me "Are you sure you didn't go into a store in Detroit and ask for your phone to be changed? They showed an ID!" No, I didn't do that. Luckily I had 2-factor for everything, but I know some people who lost a lot. SMS is totally broken, use 2FA and hardware key…

I know of a number of oil companies who had tens, if not hundreds of millions of dollars stolen in 2016. Their accountants were spear phished and their outboxes were closely monitored. When an outbound invoice was sent the email was caught and then altered to show the fraudsters bank and routing numbers. Oil companies are notoriously slow to pay (and frequently take lots of nudging to get a payment out) so the payment never showing up didn't seem out of the ordinary.

It was all kept hush hush to prevent copycat attacks. It took intervention from the FBI and a big netsec firm to even figure out how it had happened.

Re: Two Charged in SIM Swapping, Vishing Scams

#8
post #4

I'm a blockchain pro and there was a couple month period in 2017 when tons of people I know got SIM swapped including me. The T-Mobile call person kept asking me "Are you sure you didn't go into a store in Detroit and ask for your phone to be changed? They showed an ID!" No, I didn't do that. Luckily I had 2-factor for everything, but I know some people who lost a lot. SMS is totally broken, use 2FA and hardware key…

(Googler, opinions on my own)

This is a nice benefit of Google Fi. Since swap attacks are not possible with it, as customers support agents aren't able to do sim swaps. Sims for Google Fi are fully tied to your Google account, and you must have access to that account to be able to register or unregister a phone.

Re: Two Charged in SIM Swapping, Vishing Scams

#9
post #5
post #4

I'm a blockchain pro and there was a couple month period in 2017 when tons of people I know got SIM swapped including me. The T-Mobile call person kept asking me "Are you sure you didn't go into a store in Detroit and ask for your phone to be changed? They showed an ID!" No, I didn't do that. Luckily I had 2-factor for everything, but I know some people who lost a lot. SMS is totally broken, use 2FA and hardware key…

I was also the victim of a T-Mobile SIM swap back in February. My assumption is that the attackers target individuals that have a high likelihood of owning bitcoin or other digital currency. This can be easily determined by looking at data breaches, and targeting emails that are found both on a cryptocurrency breach and a personal information breach with phone number, name, address, and anything else that would help…

I SIM swapped myself twice on Sprint without authorization at an Apple store. Sales reps can generate a one time code for Sprint Support that allows them to bypass some of the IVRs and prove the call is coming from an Apple Store. Sprint support won't ask for a PIN or SSN. Just the line's number. Bam!

How many people can do this? See those mom and pop "authorized resellers" at the mall? Yeah.

Re: Two Charged in SIM Swapping, Vishing Scams

#10
post #8
post #4

I'm a blockchain pro and there was a couple month period in 2017 when tons of people I know got SIM swapped including me. The T-Mobile call person kept asking me "Are you sure you didn't go into a store in Detroit and ask for your phone to be changed? They showed an ID!" No, I didn't do that. Luckily I had 2-factor for everything, but I know some people who lost a lot. SMS is totally broken, use 2FA and hardware key…

(Googler, opinions on my own) This is a nice benefit of Google Fi. Since swap attacks are not possible with it, as customers support agents aren't able to do sim swaps. Sims for Google Fi are fully tied to your Google account, and you must have access to that account to be able to register or unregister a phone.

I'm guessing this likely also applies to a Google Voice account phone number.
Post reply on HN