Content starts here
CLOSE ×
Search
Reply
Contributor

Feedback - SIM Swapping: Scammers Hijack Smartphones and Steal Thousands

Hello, guys! Thanks for a wonderful podcast; I really love the Perfect Scam podcast.

 

In this post I want to provide a bit of feedback, especially relevant for the "SIM Swapping: Scammers Hijack Smartphones and Steal Thousands" episode.

 

Especially for this episode and also for the podcast in general, I feel like there are not enough details provided on how the scam operates. I feel like the podcast focuses more on what victims were feeling, what their emotional struggle was like (which is, of course, important) but not enough details are provided about how the scam operates.

 

For the SIM Swapping, the host says that this victim had his phone number moved to a different eSIM and that this would not have been possible with a physical SIM. This is wrong, the telco can move numbers to other physical SIMs at free will.

 

Next, after having the phone number moved to another SIM, the attackers gain access to the victim's bank account by means of controlling the SMSes arriving on the phone number. What is not clear is how the attackers got the main authentication factor (password at the bank, security token, etc.). The SMS is used as MFA/2FA, but how did the attackers got access to the main authentication? weak password? We don't know.

 

Next, the victim says that the attackers gained access to the bank account and generated a virtual credit card. Next, they walked inside the bank and presented this virtual credit card as authentication. !!! How can someone present a virtual credit card???

 

Finally, we have no details on how the actual SIM swapping was possible. How did the attackers manage to switch the phone number to another SIM 4 times!!?? How come chargers were not pressed against the telco for allowing this and against the bank for allowing such huge money withdrawals, considering the history and pattern of the victim, who was always withdrawing/transferring small amounts?

 

I love the Perfect Scam podcast, but please add more details on HOW the scam operates. I am a technical guy, and I don't expect that you go into too low-level details; that is OK, but at least clearly explain how things happened and how the scam was possible. Thanks!

0 Kudos
156 Views
0
Report
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Users
Need to Know

"I downloaded AARP Perks to assist in staying connected and never missing out on a discount!" -LeeshaD341679

AARP Perks

More From AARP