Earlier quoted context omitted.
> BTW - give me some of that big-swinging-credit-balls you seem to gotts... 15 * 500 = 7,500 USD. Having a steady job should put that within reach.
[flagged]
Hackers claim they breached T-Mobile more than 100 times in 2022
141–150 of 342 posts
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#142The rise of SMS as a second factor for security across the web has raised the incentive for SIM-swapping tremendously. No one should be shocked that when tech companies start outsourcing their identity verification to cell phone providers those providers come under attack.
SMS as a second factor is almost a security downgrade. Phone companies are terrible, you shouldn't be trusting them with authentication. Plus it means you can't authenticate when your phone is out of coverage. Just a bad solution that shouldn't be used. TOTP is so easy to set up that it makes no sense to use SMS, and the even better hardware keys are only slightly less convenient.
I think totp would probably get more traction with normal users if people started calling it app verification, or something similar eventhough that is slightly incorrect.
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#143Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#144Earlier quoted context omitted.
> BTW - give me some of that big-swinging-credit-balls you seem to gotts... 15 * 500 = 7,500 USD. Having a steady job should put that within reach.
[flagged]
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#145Earlier quoted context omitted.
Interesting. Was your 2FA setup to use Google Authenticator or regular SMS? It's been a while since I used Google services but from what I recall from a previous company where we used Gmail was that the only way to do 2FA with Google Authenticator if you lost access to the phone was with a backup code you are given at 2FA setup time. Is that no longer the case?
2FA with authenticator. As someone correctly points out, Google appears to keep SMS as a recovery option unless you specifically opt out? Edit: I can't actually find a help article, but it's under "Try another way to sign-in" and they'll text you a verification code to your registered account phone number.
Does anyone know if Authy uses SMS for any kind of recovery? I don’t see an option in the security settings
https://support.authy.com/hc/en-us/articles/360012427914-Is-...
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#146Earlier quoted context omitted.
[flagged]
If this scammer thought they were a high value target, I imagine they would have gone bigger than buying $500 GoPros.
It will be easier to go after high income middle class types than HVTs, who will likely have someone watching things closer than busy working folk.
If you hit a target for multiple low value charges you face less scrutiny than large transactions. Fraud should pickup multiple purchases of the same product to different addresses though.
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#147Earlier quoted context omitted.
> BTW - give me some of that big-swinging-credit-balls you seem to gotts... 15 * 500 = 7,500 USD. Having a steady job should put that within reach.
[flagged]
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#148I was a victim of this last October and November on a T-Mobile number. This is what occurred: - My Gmail account was compromised - My Amazon account was compromised In Gmail, they added a filter to hide any shipping or customer service messages from Amazon. In Amazon, every other day, they placed an order for a ~500 USD GoPro device, delivered to an address in NYC. This address changed with every order. Both password…
They were able to reset your Google password using only the simjacked phone? Or was the password the same as the T-mobile one as well? It’s hardly a second factor if it can be used to entirely replace the primary one.
https://support.google.com/accounts/answer/183723?hl=en&co=G...
I think years ago I found my number there with no-recollection of every agreeing to it and quickly yeeted it. (You can remove the number but keep recovery email)
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#149Earlier quoted context omitted.
> BTW - give me some of that big-swinging-credit-balls you seem to gotts... 15 * 500 = 7,500 USD. Having a steady job should put that within reach.
[flagged]
I don't know if it's controversial, but I think for most people, keeping up with your current card statement isn't something you do daily. Sometimes companies have a way to notify you of new charges immediately, sometimes not. Being surprised at the end of the month is more common than you'd think.
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#150It is an open secret that criminal groups also pay unscrupulous T-Mobile employees to assist with SIM-swap attacks. I am not sure at what scale this happens, as those instances _should_ be easy to trace and prosecute. But I have seen evidence of criminals reaching out and offering "side work" on the T-mobile subreddits, as an example. In those cases, hardware keys for employees would not help.
> those instances _should_ be easy to trace and prosecute I suspect that the employees aren't merely doing a sim swap attack with their work login credentials. Like you say, they'd clearly get fired/prosecuted for that. Instead, I suspect criminal X buys a nice thing delivered to employee Y's house. Then, criminal X phones the helpdesk repeatedly till they get connected to employee Y during working hours. Then, they…
They just walk in to the store, steal a tablet out of the manager's hands, run away with it, and make all the changes they can with the logged-in session until corporate locks out the device.