Live data from Hacker News

Man sues AT&T over 'SIM Swap' hack allegedly involving employees

foxla.com

111–120 of 129 posts

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#111
post #84

Earlier quoted context omitted.

How did they know your email password and phone number at the same time?

A scary amount of services will let you reset a password over SMS.

Even more scary with the Yahoo account in particular, I have it set up as an app-based authentication, so I get a popup on my phone if someone tries to log in. However, when they (I assume) clicked the "I don't have access to this, send an SMS instead" message, that notification immediately disappeared, so I didn't even have time to hit the "don't allow" button before it was no longer an option.

Google at least seems to have this right, in that when they attempted to do the same with those, the notification was still there. I also received a separate "request to reset account password" which stated it would take like 15 days to occur, and I was given the option to cancel it.

Regardless, I think I'm going to try to go hardware key with an TOTP app backup for 2FA going forward, wherever possible.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#112
post #50

Had this happen to me last week. Thankfully they only tried to get into a few e-mail accounts, which I was quick enough to get into, kill their session, and recover them before any real damage was done. AT&T of course claimed it was impossible for that to happen, despite a different phone showing up in my account, a bunch of unexplained SMS messages I never received, and two calls accessing my voicemail that I didn't…

One thing I've noticed lately is that Google Voice numbers are working with fewer and fewer companies. For example, I don't think that they work with Wells Fargo or Chase. Wells Fargo said flat out that the phone number can't be validated.

That's interesting, I appreciate the heads up. I'll have to see if I can find some other workaround whenever that pops up.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#113

Earlier quoted context omitted.

Did you have a PIN setup with ATT? I am trying to figure out which of their employees can modify the account without the PIN.

As of a year or two ago when I worked at a authorized att dealer, manager logins can access any account without a pin and any employee can access prepaid accounts without a pin. Edit:for whatever its worth att does keep a record of what employees accessed an account and when, and notes when managers bypass the pin, so doing this an an employee seems really stupid to me.

Interesting, I figured since they claimed that wasn't possible that they didn't keep records. I'll have to go bug them again to see if they can investigate it further. I'm not sure if this was an instance of targeted social engineering or an employee, though I would assume the former is more likely.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#114
post #109

Earlier quoted context omitted.

You can also add an authorized user or open up an entirely new line. You won't notice until you receive your bill.

Wouldn't a new line have a different phone number which wouldn't allow these hacks?

Yes. It won't allow the number take over, but you will end up with 1+ new iPhones in hand for the attacker. You can swap the number at any point afterward easier than just setting up a new phone at the store with a suspecting employee.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#115
post #113

Earlier quoted context omitted.

As of a year or two ago when I worked at a authorized att dealer, manager logins can access any account without a pin and any employee can access prepaid accounts without a pin. Edit:for whatever its worth att does keep a record of what employees accessed an account and when, and notes when managers bypass the pin, so doing this an an employee seems really stupid to me.

Interesting, I figured since they claimed that wasn't possible that they didn't keep records. I'll have to go bug them again to see if they can investigate it further. I'm not sure if this was an instance of targeted social engineering or an employee, though I would assume the former is more likely.

I'm not sure what customer service policy is about telling customers but in store at least we definetely had a notes section of every account with breakdowns of what internal usernames accessed the accounts and when. The fraud dept I assume would be the ones to look at who the employees were from the usernames but we didn't handle that kind of stuff at the authorized retailer stores so no advice to give you unfortunately :/

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#116
post #97

> When FOX 11 reached out to AT&T for comment on the SIM swap lawsuits against them, the company responded “This is an industry problem,” and referred us to the CTIA for more information. And AT&T is the industry leader.

I don't even see how it's an industry problem - AT&T didn't do thorough verification before swapping the SIM, there's nothing broader about it.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#117
post #112

Earlier quoted context omitted.

One thing I've noticed lately is that Google Voice numbers are working with fewer and fewer companies. For example, I don't think that they work with Wells Fargo or Chase. Wells Fargo said flat out that the phone number can't be validated.

That's interesting, I appreciate the heads up. I'll have to see if I can find some other workaround whenever that pops up.

I've been using Voip.ms to pretty reasonable success. They support most SMS short codes, and everything else I've needed it for has worked as a voice call.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#118
post #5
post #2

Wasn’t there a pin on his account?

Employees are able to override the pin entering requirement. There is absolutely nothing you can do to stop this from happening if you happen to get targeted. (Speaking from experience)

It is a liability to trust another party with keys to cryptocurrency with such high value.

To step out of the regulated financial system is to open oneself up to these liabilities with little recourse.

That is not to say that telecom companies should not fix this. They absolutely should.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#119
post #33

Earlier quoted context omitted.

It's rather sad that Canadian banks still view SMS as the best way forward. They'll text you, they'll email you, they'll validate over the phone... all of which are really this same problem. I'm waiting for the days our banks will accept multiple 2FA solutions.

And when you (unavoidably) get hacked, they tell you it's your fault and that it sucks to be you, because you are not getting that money back. https://www.cbc.ca/news/business/banks-deny-compensation-onl...

Tell me about it. The whole thing makes me cringe. Frequently I wonder if the goal is just to have enough insurance, such that when people and their money are separated, life is fine.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#120
post #96

Earlier quoted context omitted.

Sad that one of my current banks (Chase) won't add TOTP to their login. Edit: https://twitter.com/skunkworker/status/1131297869703438337 @ChaseSupport Hey Chase, when will offline TOTP be added for a more secure login? Thank you for reaching out! What we have is the multi-factor authentication on all online accounts. You can visit https://tinyurl.com/y7r2fztd for more info on how we protect and secure your informatio…

I'm still looking at how to best communicate with my bank too, to get actual answers. :D Not this cookie cutter kind of support. No matter how precisely I describe the problem, I get copy paste or poorly thought out response. That's why I like smaller businesses, where there's still a connection between doers and support people, or where the doers are the support people.

I've been suffering from the same frustration, and have been thinking about switching to a smaller bank. There are apparently more than 7,000 FDIC insured institutions out there.
Post reply on HN