ZeroHour
Ars Technica · Securitypublished ()ingested

The FCC says new rules will curb SIM swapping. I’m pessimistic

lowPolicy & legalimportance 30
Full article349 words · extracted from arstechnica.com · click to collapse

After years of inaction, the FCC this week said that it’s finally going to protect consumers against a scam that takes control of their cell phone numbers by deceiving employees who work for mobile carriers. While commissioners congratulated themselves for the move, there’s little reason yet to believe it will stop a practice that has been all too common over the past decade.

The scams, known as “SIM swapping” and “port-out fraud,” both have the same objective: to wrest control of a cell phone number away from its rightful owner by tricking the employees of the carrier that services it. SIM swapping occurs when crooks hold themselves out as someone else and request that the victim’s number be transferred to a new SIM card—usually under the pretense that the victim has just obtained a new phone. In port-out scams, crooks do much the same thing, except they trick the carrier employee into transferring the target number to a new carrier.

This class of attack has existed for well over a decade, and it became more commonplace amid the irrational exuberance that drove up the price of Bitcoin and other crypto currencies. People storing large sums of digital coin have been frequent targets. Once crooks take control of a phone number, they trigger password resets that work by clicking on links sent in text messages. The crooks then drain cryptocurrency and traditional bank accounts.

The practice has become so common that an entire SIM-swap-as-a-service industry has cropped up. More recently, these scams have been used by threat actors to target and in some cases successfully breach enterprise networks belonging to some of the world’s biggest organizations.

The crooks pursuing these scams are surprisingly adept in the art of the confidence game. Lapsus$, a threat group composed mostly of teens, has repeatedly used SIM swaps and other forms of social engineering with a confounding level of success. From there, members use commandeered numbers to breach other targets. Just last month, Microsoft profiled a previously unknown group that regularly uses SIM swaps to ensnare companies that provide mobile telecommunications processing services.

Text extracted automatically; images, tables and formatting may be missing. Original: https://arstechnica.com/security/2023/11/the-fcc-says-new-rules-will-curb-sim-swapping-im-pessimistic/