I'm a blockchain pro and there was a couple month period in 2017 when tons of people I know got SIM swapped including me. The T-Mobile call person kept asking me "Are you sure you didn't go into a store in Detroit and ask for your phone to be changed? They showed an ID!" No, I didn't do that. Luckily I had 2-factor for everything, but I know some people who lost a lot. SMS is totally broken, use 2FA and hardware key…
(Googler, opinions on my own) This is a nice benefit of Google Fi. Since swap attacks are not possible with it, as customers support agents aren't able to do sim swaps. Sims for Google Fi are fully tied to your Google account, and you must have access to that account to be able to register or unregister a phone.
Two Charged in SIM Swapping, Vishing Scams
11–20 of 71 posts
Re: Two Charged in SIM Swapping, Vishing Scams
#12I'm a blockchain pro and there was a couple month period in 2017 when tons of people I know got SIM swapped including me. The T-Mobile call person kept asking me "Are you sure you didn't go into a store in Detroit and ask for your phone to be changed? They showed an ID!" No, I didn't do that. Luckily I had 2-factor for everything, but I know some people who lost a lot. SMS is totally broken, use 2FA and hardware key…
Why are the phone companies not responsible for swapping the number over? In a similar vein, I've known people who had unsigned checks stolen and their signature forged very poorly. The banks are supposed to check the signature, so why aren't the banks liable?
Re: Two Charged in SIM Swapping, Vishing Scams
#13Earlier quoted context omitted.
I was also the victim of a T-Mobile SIM swap back in February. My assumption is that the attackers target individuals that have a high likelihood of owning bitcoin or other digital currency. This can be easily determined by looking at data breaches, and targeting emails that are found both on a cryptocurrency breach and a personal information breach with phone number, name, address, and anything else that would help…
I SIM swapped myself twice on Sprint without authorization at an Apple store. Sales reps can generate a one time code for Sprint Support that allows them to bypass some of the IVRs and prove the call is coming from an Apple Store. Sprint support won't ask for a PIN or SSN. Just the line's number. Bam! How many people can do this? See those mom and pop "authorized resellers" at the mall? Yeah.
AT&T still let them order 4 new lines on a new account even though I already had an account with 2 lines.
Re: Two Charged in SIM Swapping, Vishing Scams
#14I'm a blockchain pro and there was a couple month period in 2017 when tons of people I know got SIM swapped including me. The T-Mobile call person kept asking me "Are you sure you didn't go into a store in Detroit and ask for your phone to be changed? They showed an ID!" No, I didn't do that. Luckily I had 2-factor for everything, but I know some people who lost a lot. SMS is totally broken, use 2FA and hardware key…
(Googler, opinions on my own) This is a nice benefit of Google Fi. Since swap attacks are not possible with it, as customers support agents aren't able to do sim swaps. Sims for Google Fi are fully tied to your Google account, and you must have access to that account to be able to register or unregister a phone.
Re: Two Charged in SIM Swapping, Vishing Scams
#15Text message based 2FA needs to die.
Re: Two Charged in SIM Swapping, Vishing Scams
#16Re: Two Charged in SIM Swapping, Vishing Scams
#17It's insane to me that the only thing standing between me and having my life ruined is some minimum wage cell phone store employee. Text message based 2FA needs to die.
Re: Two Charged in SIM Swapping, Vishing Scams
#18I'm a blockchain pro and there was a couple month period in 2017 when tons of people I know got SIM swapped including me. The T-Mobile call person kept asking me "Are you sure you didn't go into a store in Detroit and ask for your phone to be changed? They showed an ID!" No, I didn't do that. Luckily I had 2-factor for everything, but I know some people who lost a lot. SMS is totally broken, use 2FA and hardware key…
Why are the phone companies not responsible for swapping the number over? In a similar vein, I've known people who had unsigned checks stolen and their signature forged very poorly. The banks are supposed to check the signature, so why aren't the banks liable?
Re: Two Charged in SIM Swapping, Vishing Scams
#19Ah yes, of course they were only caught because the two had a falling out and then one swatted the other.
You and your partner stole a bunch of Bitcoin via SIM swapping. If you split it, you each get half. If you don’t split it, the other one will SWAT you and you both go to jail.
Re: Two Charged in SIM Swapping, Vishing Scams
#20I'm a blockchain pro and there was a couple month period in 2017 when tons of people I know got SIM swapped including me. The T-Mobile call person kept asking me "Are you sure you didn't go into a store in Detroit and ask for your phone to be changed? They showed an ID!" No, I didn't do that. Luckily I had 2-factor for everything, but I know some people who lost a lot. SMS is totally broken, use 2FA and hardware key…
(Googler, opinions on my own) This is a nice benefit of Google Fi. Since swap attacks are not possible with it, as customers support agents aren't able to do sim swaps. Sims for Google Fi are fully tied to your Google account, and you must have access to that account to be able to register or unregister a phone.
I think the risk is too big. Use U2F, or something similar.