Live data from Hacker News

NY Man Pleads Guilty in $20M SIM Swap Theft

krebsonsecurity.com

1–10 of 176 posts

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#2
Tangentially, the FCC is forcing the hand of mobile carriers on this. T-Mobile just the other day has updated their policy so that two employees must be present and part of the process to swap a customer’s SIM. The perils of your phone number being your identity.

Refreshing to see these active theft and wire fraud prosecutions.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#3

Tangentially, the FCC is forcing the hand of mobile carriers on this. T-Mobile just the other day has updated their policy so that two employees must be present and part of the process to swap a customer’s SIM. The perils of your phone number being your identity. Refreshing to see these active theft and wire fraud prosecutions.

Lawyers have been making bank filing claims against the Telecoms for sim swap losses.

Never did any myself, but have friends who have done well with these cases. They essentially allow the lawyers to share in the appreciation of crypto.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#4

Tangentially, the FCC is forcing the hand of mobile carriers on this. T-Mobile just the other day has updated their policy so that two employees must be present and part of the process to swap a customer’s SIM. The perils of your phone number being your identity. Refreshing to see these active theft and wire fraud prosecutions.

That's nice to hear. So the SIM swappers have to double their bribes.

I think the best solution is to cut the mobile providers out of the equation altogether. I've long advised removing your phone number from anything you can, or at least substituting a voip service that can't be social engineered over the phone. Some services don't let you use voip services for multi-factor or signup, so your mileage may vary.

Also, it's important where possible to use types of multi-factor that don't rely on your phone number. The tricky part is, so many sites will let you reset your password if you can receive a link via SMS at the phone number on file for the account. Which means anyone who SIM-swaps you then can reset the passwords on those accounts that allow SMS resets (which is a lot, still).

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#5

Tangentially, the FCC is forcing the hand of mobile carriers on this. T-Mobile just the other day has updated their policy so that two employees must be present and part of the process to swap a customer’s SIM. The perils of your phone number being your identity. Refreshing to see these active theft and wire fraud prosecutions.

That's nice to hear. So the SIM swappers have to double their bribes. I think the best solution is to cut the mobile providers out of the equation altogether. I've long advised removing your phone number from anything you can, or at least substituting a voip service that can't be social engineered over the phone. Some services don't let you use voip services for multi-factor or signup, so your mileage may vary. Also,…

One of the few things I miss about giving up my landline a couple years ago is that I pretty much have to give out my cell phone number for anything that needs a valid phone number. (yes, I could use Google Voice or some sort of VOIP number but that starts making things complicated.) I used to be very selective at giving out my cell number.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#6
I wonder if the following idea has occurred to anyone else?

We have more and more kinds of accounts, financial products, online services, etc. that would benefit from some kind of real in-person verification at points in the process (initial application, maintenance, changes to account) that are imperfectly done with credit checks, questions/answers, logins, etc.

We have Post Offices in nearly every corner of this country. How about turning them into a kind of value-added identity verification service where any company wanting/needing an identity verification could rely on the Post Office to accept someone in person to prove who they are (through fingerprint, document, etc) and be the 3rd party to make this proof easy?

Sure you would need to have normal fraud protections, etc. but I bet the act of having to come to a post office would make things very secure / reliable. And it would give the post office a new function. I heard of this being done in some other countries.

It seems like a way to avoid us all having to pay for fraud so frequently.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#8

Tangentially, the FCC is forcing the hand of mobile carriers on this. T-Mobile just the other day has updated their policy so that two employees must be present and part of the process to swap a customer’s SIM. The perils of your phone number being your identity. Refreshing to see these active theft and wire fraud prosecutions.

That's nice to hear. So the SIM swappers have to double their bribes. I think the best solution is to cut the mobile providers out of the equation altogether. I've long advised removing your phone number from anything you can, or at least substituting a voip service that can't be social engineered over the phone. Some services don't let you use voip services for multi-factor or signup, so your mileage may vary. Also,…

>That's nice to hear. So the SIM swappers have to double their bribes.

Most SIM-swappers are retiring with their ill-gotten crypto, but the ones remaining are at the "bribing prosecutors" level now.

With crypto skyrocketing and the pitfalls of SMS becoming more apparent, I fully expect the jump to amateurs purchasing and leveraging state-level 0days against unwitting wallet holders.

The gap between profit and cost is getting larger, and more crypto-millionaires are going to get their Teamviewer 0dayed.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#9

Tangentially, the FCC is forcing the hand of mobile carriers on this. T-Mobile just the other day has updated their policy so that two employees must be present and part of the process to swap a customer’s SIM. The perils of your phone number being your identity. Refreshing to see these active theft and wire fraud prosecutions.

That's nice to hear. So the SIM swappers have to double their bribes. I think the best solution is to cut the mobile providers out of the equation altogether. I've long advised removing your phone number from anything you can, or at least substituting a voip service that can't be social engineered over the phone. Some services don't let you use voip services for multi-factor or signup, so your mileage may vary. Also,…

One thing I don't understand about the suggestion to remove my phone number from 2FA is that 1FA seems worse. I'd prefer something like Google authenticator, but none of my banks offer that. Did I misunderstand the suggestion? Is there something else I should do?

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#10

I wonder if the following idea has occurred to anyone else? We have more and more kinds of accounts, financial products, online services, etc. that would benefit from some kind of real in-person verification at points in the process (initial application, maintenance, changes to account) that are imperfectly done with credit checks, questions/answers, logins, etc. We have Post Offices in nearly every corner of this co…

There's a number of KYC services where you're basically asked to be filmed and a person in a call centre looks at it and decides whether it's really you.

When I went looking at them they were boasting with using AI, and then in the meeting it turned out it was mostly farmed out to someone in India.

Post reply on HN