Live data from Hacker News

Hackers claim they breached T-Mobile more than 100 times in 2022

krebsonsecurity.com

141–150 of 342 posts

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#141
post #115

Earlier quoted context omitted.

> BTW - give me some of that big-swinging-credit-balls you seem to gotts... 15 * 500 = 7,500 USD. Having a steady job should put that within reach.

[flagged]

Putting the "15" in italics isn't doing yourself any favors when asking aita

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#142
post #54

The rise of SMS as a second factor for security across the web has raised the incentive for SIM-swapping tremendously. No one should be shocked that when tech companies start outsourcing their identity verification to cell phone providers those providers come under attack.

SMS as a second factor is almost a security downgrade. Phone companies are terrible, you shouldn't be trusting them with authentication. Plus it means you can't authenticate when your phone is out of coverage. Just a bad solution that shouldn't be used. TOTP is so easy to set up that it makes no sense to use SMS, and the even better hardware keys are only slightly less convenient.

Most users don't know what the words sms or totp mean. I'm not saying that totp isn't easy to implement in the grand scheme of things, but for many people it's not straight forward to setup. Entering a cellphone number and responding to text messages is well known since we've been doing it for 20 something years now.

I think totp would probably get more traction with normal users if people started calling it app verification, or something similar eventhough that is slightly incorrect.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#144
post #115

Earlier quoted context omitted.

> BTW - give me some of that big-swinging-credit-balls you seem to gotts... 15 * 500 = 7,500 USD. Having a steady job should put that within reach.

[flagged]

He noticed the first time he got a bill at the end of the month, it doesn't seem that difficult to understand.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#145
post #116

Earlier quoted context omitted.

Interesting. Was your 2FA setup to use Google Authenticator or regular SMS? It's been a while since I used Google services but from what I recall from a previous company where we used Gmail was that the only way to do 2FA with Google Authenticator if you lost access to the phone was with a backup code you are given at 2FA setup time. Is that no longer the case?

2FA with authenticator. As someone correctly points out, Google appears to keep SMS as a recovery option unless you specifically opt out? Edit: I can't actually find a help article, but it's under "Try another way to sign-in" and they'll text you a verification code to your registered account phone number.

Just noticed that Authy’s answer to the FAQ of “ Is the Authy App Susceptible to a SIM Swap?” does not have the word “No” in it.

Does anyone know if Authy uses SMS for any kind of recovery? I don’t see an option in the security settings

https://support.authy.com/hc/en-us/articles/360012427914-Is-...

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#146
post #126

Earlier quoted context omitted.

[flagged]

If this scammer thought they were a high value target, I imagine they would have gone bigger than buying $500 GoPros.

Not always.

It will be easier to go after high income middle class types than HVTs, who will likely have someone watching things closer than busy working folk.

If you hit a target for multiple low value charges you face less scrutiny than large transactions. Fraud should pickup multiple purchases of the same product to different addresses though.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#147
post #115

Earlier quoted context omitted.

> BTW - give me some of that big-swinging-credit-balls you seem to gotts... 15 * 500 = 7,500 USD. Having a steady job should put that within reach.

[flagged]

I for one don't really look at any banking stuff these days. I just live well within my means. If you have a generally healthy financial situation there is no need to constantly check.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#148
post #138
post #65

I was a victim of this last October and November on a T-Mobile number. This is what occurred: - My Gmail account was compromised - My Amazon account was compromised In Gmail, they added a filter to hide any shipping or customer service messages from Amazon. In Amazon, every other day, they placed an order for a ~500 USD GoPro device, delivered to an address in NYC. This address changed with every order. Both password…

They were able to reset your Google password using only the simjacked phone? Or was the password the same as the T-mobile one as well? It’s hardly a second factor if it can be used to entirely replace the primary one.

Google still allows you to setup recovery phone numbers unforunately.

https://support.google.com/accounts/answer/183723?hl=en&co=G...

I think years ago I found my number there with no-recollection of every agreeing to it and quickly yeeted it. (You can remove the number but keep recovery email)

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#149
post #115

Earlier quoted context omitted.

> BTW - give me some of that big-swinging-credit-balls you seem to gotts... 15 * 500 = 7,500 USD. Having a steady job should put that within reach.

[flagged]

> Why is that controversial?

I don't know if it's controversial, but I think for most people, keeping up with your current card statement isn't something you do daily. Sometimes companies have a way to notify you of new charges immediately, sometimes not. Being surprised at the end of the month is more common than you'd think.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#150

It is an open secret that criminal groups also pay unscrupulous T-Mobile employees to assist with SIM-swap attacks. I am not sure at what scale this happens, as those instances _should_ be easy to trace and prosecute. But I have seen evidence of criminals reaching out and offering "side work" on the T-mobile subreddits, as an example. In those cases, hardware keys for employees would not help.

> those instances _should_ be easy to trace and prosecute I suspect that the employees aren't merely doing a sim swap attack with their work login credentials. Like you say, they'd clearly get fired/prosecuted for that. Instead, I suspect criminal X buys a nice thing delivered to employee Y's house. Then, criminal X phones the helpdesk repeatedly till they get connected to employee Y during working hours. Then, they…

On darknet diaries the stories told are a little more straightforward.

They just walk in to the store, steal a tablet out of the manager's hands, run away with it, and make all the changes they can with the logged-in session until corporate locks out the device.

Post reply on HN