Live data from Hacker News

Hackers claim they breached T-Mobile more than 100 times in 2022

krebsonsecurity.com

251–260 of 342 posts

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#251

Earlier quoted context omitted.

Simjacking. https://en.wikipedia.org/wiki/SIM_swap_scam

Wait. Isn't it painfully obvious when you've been simjacked? If your phone suddenly loses signal and refuses to register with the network, you know something is up. You may think it was a malfunction of your phone or your network, but it's pretty much a definition of a modern-day "drop everything you're doing and deal with it" emergency. You can't not be aware of it, or be unsure if it happened to you.

The phone may not lose signal immediately (or at all) - this is implementation dependent, so it's not a reliable indicator.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#252

Which cell phone network would you guys recommend for people who care about security?

Efani is the only carrier I'm aware of that is security-centric, I have not used them myself, but they claim zero SIM-swap attacks have been successful against them. Even though they are an MVNO they claim their upstream networks cannot change their customers' SIMs. Downside is it's expensive, it depends on what you need to protect I suppose.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#253
post #65

I was a victim of this last October and November on a T-Mobile number. This is what occurred: - My Gmail account was compromised - My Amazon account was compromised In Gmail, they added a filter to hide any shipping or customer service messages from Amazon. In Amazon, every other day, they placed an order for a ~500 USD GoPro device, delivered to an address in NYC. This address changed with every order. Both password…

There must be something especially lucrative about GoPros as stolen devices.

I’ve heard multiple independent stories from a few friends in Law Enforcement about cases involving trafficking of large quantities of stolen GoPros (obtained via methods not unlike what happened to you).

Interesting you mention NYC - at least one of these cases involved a very high volume fencing syndicate operating as a legitimate storefront in NYC - with merchandise fraudulently obtained from Amazon[0]. A friend of mine worked this case.

Small, fairly high value, high demand, and no remote shutdown/disable/reporting - somewhat of a perfect storm I suppose.

[0] - https://www.cnbc.com/amp/2018/06/07/how-the-finans-stole-1-p...

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#254

Earlier quoted context omitted.

I have no idea what you are talking about here. SIM swap and spam texts/calls are entirely different issues.

If it's scalable to mass call a good chunk of the US population, I'm sure it's scalable to mass call providers to socially engineer a SIM swap.

To perform a SIM swap I need an employee at Verizon or whatever to take some steps on their computer (or have their computer infected with a RAT). To call 100,000 people on the phone I just need a computer that can make phone calls.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#255

Would switching to an eSIM based phone offer any sort of risk mitigation in these scenarios?

An eSIM will prevent a physical swap. However, an eSIM will not prevent a port-out of your phone number.

To defend against port-out you should enable port protection. The name of such a feature varies by carrier, and T-Mobile seems to refer to it as "Takeover Protection."

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#256

Earlier quoted context omitted.

IIRC, on Darknet Diaries podcast they shared that one of the approaches is that someone comes to a location that services T-Mobile customers and has T-Mobile terminal (not necessarily a T-Mobile brand boutique shop). They come with a random request and wait for an employee to sign into the terminal and then pull it out of their hands and run away. They then run against the clock (whatever time it takes to report thef…

not sure if a yubikey or similar would help here because they would probably just steal that as well, no?

There are fingerprint-unlocked hardware keys. Not perfect, but also not trivial to get around in the time it takes to report the key as stolen.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#257

Earlier quoted context omitted.

I was about to comment the same thing. It's very simple but I don't think I would have thought of it

It's quite common, in fact my "go-to" hacked account rule in Office 365 is "alert me, system admin, anytime anyone creates an outlook/exchange rule". Our group is small enough that I get very few alerts at all, and I've caught two compromises that way.

Thanks for the tip that's a pretty good one I wouldn't have thought of

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#258

It is an open secret that criminal groups also pay unscrupulous T-Mobile employees to assist with SIM-swap attacks. I am not sure at what scale this happens, as those instances _should_ be easy to trace and prosecute. But I have seen evidence of criminals reaching out and offering "side work" on the T-mobile subreddits, as an example. In those cases, hardware keys for employees would not help.

IIRC, on Darknet Diaries podcast they shared that one of the approaches is that someone comes to a location that services T-Mobile customers and has T-Mobile terminal (not necessarily a T-Mobile brand boutique shop). They come with a random request and wait for an employee to sign into the terminal and then pull it out of their hands and run away. They then run against the clock (whatever time it takes to report thef…

I remember a that or a similar episode! And it was apparently even more intricate, the robber being only the lowest member of a whole food pyramid of criminals - after the robbery his only task was to grant remote access to someone who knew the terminal software (probably that would be the paid insider), while in some secret chatroom a third guy already started running an auction of who would get his sim swap processed while the guy who organised the whole thing was relaxing somewhere at the beach watching his percentage of the profits rolling in.

I was kind of amazed and shocked at the same time how there already seems to be an established sim-swap-as-a-service economy with specialized roles and plenty demand to warrant expansion...

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#259
post #65

I was a victim of this last October and November on a T-Mobile number. This is what occurred: - My Gmail account was compromised - My Amazon account was compromised In Gmail, they added a filter to hide any shipping or customer service messages from Amazon. In Amazon, every other day, they placed an order for a ~500 USD GoPro device, delivered to an address in NYC. This address changed with every order. Both password…

Googlefi just uses their towers, your telecom data isn’t communicated with T-Mobile just the data of whatever you’re using (calls Netflix browsing porn)

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#260

Earlier quoted context omitted.

Both Fidelity and Schwab allow non-SMS 2FA. They both use Symantec VIP but it’s fairly easy (for developers at least) to export those tokens and import them into something like Authy, Google Authenticator etc. https://ketanvijayvargiya.com/257-symantec-vip-authy/

Do you happen to know if they allow you to also totally disable SMS 2FA? I know that Vanguard, for instance, supports non-SMS 2FA but doesn't let you disable SMS as a fallback (and I'd rather not just totally remove all phone numbers, but maybe I have to...).

I believe you can remove SMS fallback now on Vanguard.
Post reply on HN