fbpx
Wikipedia

SIM swap scam

A SIM swap scam (also known as port-out scam, SIM splitting,[1] simjacking, and SIM swapping)[2] is a type of account takeover fraud that generally targets a weakness in two-factor authentication and two-step verification in which the second factor or step is a text message (SMS) or call placed to a mobile telephone.

Method edit

The fraud exploits a mobile phone service provider's ability to seamlessly port a phone number to a device containing a different subscriber identity module (SIM). This mobile number portability feature is normally used when a phone is lost or stolen, or a customer is switching service to a new phone.

The scam begins with a fraudster gathering personal details about the victim, either by use of phishing emails, by buying them from organised criminals,[3] or by directly socially engineering the victim.[4]

Armed with these details, the fraudster contacts the victim's mobile telephone provider.  The fraudster uses social engineering techniques to convince the telephone company to port the victim's phone number to the fraudster's SIM. This is done, for example, by impersonating the victim using personal details to appear authentic and claiming that they have lost their phone. In some countries, notably India and Nigeria, the fraudster will have to convince the victim to approve the SIM swap by pressing 1.[5][6][4]

In many cases, SIM numbers are changed directly by telecom company employees bribed by criminals.[7]

Once this happens, the victim's phone will lose connection to the network, and the fraudster will receive all the SMS and voice calls intended for the victim. This allows the fraudster to intercept any one-time passwords sent via text or telephone calls sent to the victim and thus allows them to circumvent many two-factor authentication methods of accounts (be it their bank accounts, social media accounts, etc.) that rely on text messages or telephone calls. Since so many services allow password resets with only access to a recovery phone number, the scam allows criminals to gain access to almost any account tied to the hijacked number. This may allow them to directly transfer funds from a bank account, extort the rightful owner, or sell accounts on the black market for identity theft.

Incidents edit

A number of high-profile hacks have occurred utilizing SIM swapping, including some on the social media sites Instagram and Twitter. In 2019, former Twitter CEO Jack Dorsey's Twitter account was hacked via this method.[8][9]

In May 2020, a lawsuit was filed against an 18 year old Irvington High School senior in Irvington, New York, Ellis Pinsky, who was accused with 20 co-conspirators of swindling digital currency investor Michael Terpin – the founder and chief executive officer of Transform Group – of $23.8 million in 2018, when the accused was 15 years old, through the use of data stolen from smartphones by SIM swaps. The lawsuit was filed in federal court in White Plains, New York and asked for triple damages.[10][11]

In early 2022, the US FBI reported a sharp increase in money losses to consumers in 2021, and continuing into 2022, from this type of fraud.[12][13] The losses in 2021 alone were five times larger than the three prior years summed: “The FBI says that victims lost $68 million to this SIM-card based scam in 2021, compared to just $12 million in the three-year period between 2018 and 2020.”[12] The FBI received 1,600 complaints about SIM-swapping in 2021, a sharp increase from the three previous years. The swaps happen quickly once the scammers have sufficient information to persuade a mobile phone carrier to assign a stolen phone number to their phone; the thefts of money happen when the thieves then receive the two-factor codes sent to the proper owner of the phone number.[13]

In South Korea, alleged incidents of SIM swapping attacks have been documented since the beginning of 2022. The common pattern includes victims facing abrupt disruptions in their mobile services, coupled with a notification suggesting a change. As a result, affected individuals discover that their bank and cryptocurrency accounts have been compromised.[14]

References edit

  1. ^ admin (2014-05-09). "Alert – how you can be scammed by a method called SIM Splitting". Action Fraud. Retrieved 2018-08-22.
  2. ^ "NPR Search : NPR". www.npr.org.
  3. ^ Tims, Anna (2015-09-26). "'Sim swap' gives fraudsters access-all-areas via your mobile phone". the Guardian. Retrieved 2018-08-22.
  4. ^ a b "Many Bengalureans lose cash to sim card swap fraud - Times of India". The Times of India. Retrieved 2018-08-22.
  5. ^ "Experts Finger Insiders in Telcos for Rising SIM Swap Fraud – Nigerian CommunicationWeek". nigeriacommunicationsweek.com.ng. 14 July 2018. Retrieved 2018-08-22.
  6. ^ "You will be requested to press 1 or authenticate this Swap | Gadgets Now". Gadget Now. Retrieved 2018-08-22.
  7. ^ Franceschi-Bicchierai, Lorenzo (2019-05-13). "AT&T Contractors and a Verizon Employee Charged With Helping SIM Swapping Criminal Ring". Vice News. Retrieved 2020-01-23. Among the alleged criminals were also two former AT&T contract employees and one former Verizon employee, who helped the alleged criminals by providing private customer information in exchange for bribes, according to court documents.
  8. ^ Barrett, Brian. "How to Protect Your Phone Against a SIM Swap Attack". Wired – via www.wired.com.
  9. ^ Brandom, Russell (August 31, 2019). "The frighteningly simple technique that hijacked Jack Dorsey's Twitter account". The Verge.
  10. ^ Stempel, Jonathan (7 May 2020). "U.S. cryptocurrency investor sues suburban NYC teen for $71.4 million over alleged swindle". Reuters. Retrieved 4 January 2021.
  11. ^ Nadeau, Barbie Latza (May 8, 2020) "15-Year-Old From Suburbs Led ‘Evil Computer Geniuses’ in $24M Cryptocurrency Heist: Lawsuit" Daily Beast
  12. ^ a b Winters, Mike (February 19, 2022). "This SIM card scam once fooled Jack Dorsey—here's how to avoid it". CNBC. Retrieved February 19, 2022.
  13. ^ a b Otis, Ginger Adams (February 18, 2022). "SIM-Swapping Attacks, Many Aimed at Crypto Accounts, Are on the Rise". The Wall Street Journal. Retrieved February 19, 2022.
  14. ^ Kim, Myounghoon; Suh, Joon; Kwon, Hunyeong (August 2022). "A Study of the Emerging Trends in SIM Swapping Crime and Effective Countermeasures". 2022 IEEE/ACIS 7th International Conference on Big Data, Cloud Computing, and Data Science (BCD). pp. 240–245. doi:10.1109/BCD54882.2022.9900510. ISBN 978-1-6654-6582-3. S2CID 252625262.

swap, scam, simjacking, redirects, here, browser, vulnerability, simjacker, also, known, port, scam, splitting, simjacking, swapping, type, account, takeover, fraud, that, generally, targets, weakness, factor, authentication, step, verification, which, second,. Simjacking redirects here For the S T Browser vulnerability see Simjacker A SIM swap scam also known as port out scam SIM splitting 1 simjacking and SIM swapping 2 is a type of account takeover fraud that generally targets a weakness in two factor authentication and two step verification in which the second factor or step is a text message SMS or call placed to a mobile telephone Method editThe fraud exploits a mobile phone service provider s ability to seamlessly port a phone number to a device containing a different subscriber identity module SIM This mobile number portability feature is normally used when a phone is lost or stolen or a customer is switching service to a new phone The scam begins with a fraudster gathering personal details about the victim either by use of phishing emails by buying them from organised criminals 3 or by directly socially engineering the victim 4 Armed with these details the fraudster contacts the victim s mobile telephone provider The fraudster uses social engineering techniques to convince the telephone company to port the victim s phone number to the fraudster s SIM This is done for example by impersonating the victim using personal details to appear authentic and claiming that they have lost their phone In some countries notably India and Nigeria the fraudster will have to convince the victim to approve the SIM swap by pressing 1 5 6 4 In many cases SIM numbers are changed directly by telecom company employees bribed by criminals 7 Once this happens the victim s phone will lose connection to the network and the fraudster will receive all the SMS and voice calls intended for the victim This allows the fraudster to intercept any one time passwords sent via text or telephone calls sent to the victim and thus allows them to circumvent many two factor authentication methods of accounts be it their bank accounts social media accounts etc that rely on text messages or telephone calls Since so many services allow password resets with only access to a recovery phone number the scam allows criminals to gain access to almost any account tied to the hijacked number This may allow them to directly transfer funds from a bank account extort the rightful owner or sell accounts on the black market for identity theft Incidents editA number of high profile hacks have occurred utilizing SIM swapping including some on the social media sites Instagram and Twitter In 2019 former Twitter CEO Jack Dorsey s Twitter account was hacked via this method 8 9 In May 2020 a lawsuit was filed against an 18 year old Irvington High School senior in Irvington New York Ellis Pinsky who was accused with 20 co conspirators of swindling digital currency investor Michael Terpin the founder and chief executive officer of Transform Group of 23 8 million in 2018 when the accused was 15 years old through the use of data stolen from smartphones by SIM swaps The lawsuit was filed in federal court in White Plains New York and asked for triple damages 10 11 In early 2022 the US FBI reported a sharp increase in money losses to consumers in 2021 and continuing into 2022 from this type of fraud 12 13 The losses in 2021 alone were five times larger than the three prior years summed The FBI says that victims lost 68 million to this SIM card based scam in 2021 compared to just 12 million in the three year period between 2018 and 2020 12 The FBI received 1 600 complaints about SIM swapping in 2021 a sharp increase from the three previous years The swaps happen quickly once the scammers have sufficient information to persuade a mobile phone carrier to assign a stolen phone number to their phone the thefts of money happen when the thieves then receive the two factor codes sent to the proper owner of the phone number 13 In South Korea alleged incidents of SIM swapping attacks have been documented since the beginning of 2022 The common pattern includes victims facing abrupt disruptions in their mobile services coupled with a notification suggesting a change As a result affected individuals discover that their bank and cryptocurrency accounts have been compromised 14 References edit admin 2014 05 09 Alert how you can be scammed by a method called SIM Splitting Action Fraud Retrieved 2018 08 22 NPR Search NPR www npr org Tims Anna 2015 09 26 Sim swap gives fraudsters access all areas via your mobile phone the Guardian Retrieved 2018 08 22 a b Many Bengalureans lose cash to sim card swap fraud Times of India The Times of India Retrieved 2018 08 22 Experts Finger Insiders in Telcos for Rising SIM Swap Fraud Nigerian CommunicationWeek nigeriacommunicationsweek com ng 14 July 2018 Retrieved 2018 08 22 You will be requested to press 1 or authenticate this Swap Gadgets Now Gadget Now Retrieved 2018 08 22 Franceschi Bicchierai Lorenzo 2019 05 13 AT amp T Contractors and a Verizon Employee Charged With Helping SIM Swapping Criminal Ring Vice News Retrieved 2020 01 23 Among the alleged criminals were also two former AT amp T contract employees and one former Verizon employee who helped the alleged criminals by providing private customer information in exchange for bribes according to court documents Barrett Brian How to Protect Your Phone Against a SIM Swap Attack Wired via www wired com Brandom Russell August 31 2019 The frighteningly simple technique that hijacked Jack Dorsey s Twitter account The Verge Stempel Jonathan 7 May 2020 U S cryptocurrency investor sues suburban NYC teen for 71 4 million over alleged swindle Reuters Retrieved 4 January 2021 Nadeau Barbie Latza May 8 2020 15 Year Old From Suburbs Led Evil Computer Geniuses in 24M Cryptocurrency Heist Lawsuit Daily Beast a b Winters Mike February 19 2022 This SIM card scam once fooled Jack Dorsey here s how to avoid it CNBC Retrieved February 19 2022 a b Otis Ginger Adams February 18 2022 SIM Swapping Attacks Many Aimed at Crypto Accounts Are on the Rise The Wall Street Journal Retrieved February 19 2022 Kim Myounghoon Suh Joon Kwon Hunyeong August 2022 A Study of the Emerging Trends in SIM Swapping Crime and Effective Countermeasures 2022 IEEE ACIS 7th International Conference on Big Data Cloud Computing and Data Science BCD pp 240 245 doi 10 1109 BCD54882 2022 9900510 ISBN 978 1 6654 6582 3 S2CID 252625262 Retrieved from https en wikipedia org w index php title SIM swap scam amp oldid 1212476594, wikipedia, wiki, book, books, library,

article

, read, download, free, free download, mp3, video, mp4, 3gp, jpg, jpeg, gif, png, picture, music, song, movie, book, game, games.