• Latest
CoinDesk Explains SIM Jacking – CoinDesk

CoinDesk Explains SIM Jacking – CoinDesk

Februar 26, 2020
6 Questions for Rene Reinsberg of Celo – Cointelegraph Magazine

6 Questions for Rene Reinsberg of Celo – Cointelegraph Magazine

März 31, 2023
Judge denies SEC motion to keep Hinman docs secret in Ripple case

Judge denies SEC motion to keep Hinman docs secret in Ripple case

März 31, 2023
The ultimate guide to Miami – Cointelegraph Magazine

The ultimate guide to Miami – Cointelegraph Magazine

März 31, 2023
Dr. Jane Thomason – Cointelegraph Magazine

Dr. Jane Thomason – Cointelegraph Magazine

März 31, 2023
1658007797 celsius is bankrupt with 12b balance sheet hole su zhu.jpg

Celsius is bankrupt with $1.2B balance sheet hole, Su Zhu returns to Twitter and OpenSea purges 20% of employees: Hodler’s Digest, July 10-16

März 31, 2023
6 Questions for Lisa Fridman of Quadrata – Cointelegraph Magazine

6 Questions for Lisa Fridman of Quadrata – Cointelegraph Magazine

März 31, 2023
Jed McCaleb empties XRP wallet after eight-year selloff

Jed McCaleb empties XRP wallet after eight-year selloff

März 31, 2023
Celsius has finally filed for bankruptcy: Law Decoded, July 18-25

Celsius has finally filed for bankruptcy: Law Decoded, July 18-25

März 31, 2023
The ‘godfather of crypto’ risked lifetime in jail, laying foundation for Bitcoin – Cointelegraph Magazine

The ‘godfather of crypto’ risked lifetime in jail, laying foundation for Bitcoin – Cointelegraph Magazine

März 31, 2023
SEC objects to XRP holders aiding Ripple defense

SEC objects to XRP holders aiding Ripple defense

März 31, 2023
Blockchain technology is transforming the real estate market – Cointelegraph Magazine

Blockchain technology is transforming the real estate market – Cointelegraph Magazine

März 31, 2023
1658612147 nfts banned in minecraft sec lists 9 tokens as securities.jpg

NFTs banned in Minecraft, SEC lists 9 tokens as securities and 3AC founder blames cockyness for company meltdown: Hodler’s Digest, July 17-23

März 31, 2023
  • Home
  • Coin Market Cap
  • Bitcoin
  • Ethereum
  • Ripple
  • Litecoin
  • Alt Coin
  • Business
  • Trading
  • Mining
CoinNewsDaily
  • Home
  • Coin Market Cap
  • Bitcoin
  • Ethereum
  • Ripple
  • Litecoin
  • Alt Coin
  • Business
  • Trading
  • Mining
No Result
View All Result
  • Home
  • Coin Market Cap
  • Bitcoin
  • Ethereum
  • Ripple
  • Litecoin
  • Alt Coin
  • Business
  • Trading
  • Mining
No Result
View All Result
CoinNewsDaily
No Result
View All Result
Home Business

CoinDesk Explains SIM Jacking – CoinDesk

coinnewsdaily by coinnewsdaily
Februar 26, 2020
in Business
0
CoinDesk Explains SIM Jacking – CoinDesk
190
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter

For early access before our regular noon Eastern time releases, subscribe with Apple Podcasts, Spotify, Pocketcasts, Google Podcasts, Castbox, Stitcher, RadioPublica or RSS.

In the pantheon of crypto hacks, “SIM jacking” is one of the worst. The hack, which is less a hack and more social engineering, is basically a form of identity theft, with the attacker swapping a victim’s SIM card remotely, usually with the help of your cell-phone carrier, and then breaking into that victim’s email, crypto, bank accounts, basically all the stuff you definitely don’t want someone to break into. And the consequences can be dire, it’s also netted attackers tens of millions in loot over the past few years.

Related articles

IoTeX’s MachineFi Lab challenges Big Tech by democratizing IoT to benefit users and businesses

IoTeX’s MachineFi Lab challenges Big Tech by democratizing IoT to benefit users and businesses

Juli 26, 2022
ygg sea surpasses 10,000 scholarships in just six months of launch

YGG SEA Surpasses 10,000 Scholarships in Just Six Months of Launch

Mai 6, 2022

It’s audacious but it’s also preventable, with a little awareness. 

In this episode of CoinDesk Explains, CoinDesk editors Adam B. Levine and John Biggs explain the attack, what it could mean for you, how it works and what you can do to prevent it in a way that even John could understand. Special thanks to security guru Ralph Echemendia for the advice in today’s podcast.

For early access before our regular noon Eastern time releases, subscribe with Apple Podcasts, Spotify, Pocketcasts, Google Podcasts, Castbox, Stitcher, RadioPublica or RSS.

Transcript

In the pantheon of crypto hacks, “SIM jacking” is one of the worst. The hack, which is less a hack and more social engineering, is basically a form of identity theft, with the attacker swapping a victim’s SIM card remotely, usually with the help of your cell-phone carrier, and then breaking into your email, crypto, bank accounts, basically all the stuff you definitely don’t want someone to break into. It’s audacious but it’s also preventable with a little awareness. And the consequences can be dire, it’s also netted attackers tens of millions in loot over the past few years.

Welcome to CoinDesk Explains, an occasional series from the Markets Daily team where we break down and explore the complex world of Blockchains and Cryptocurrencies like Bitcoin. I’m John Biggs…

…and I’m Adam B. Levine. In today’s tightly connected world it always sucks to lose your phone, but when you add “your money” to that sentence it’s even more painful.  

So this time we’re talking about how some people have lost their phones [and], with the help of some clever social engineering, sometimes tens of millions of dollars along with it.

So John, you experienced this firsthand, right?

Absolutely. Back in 2017  some jackass swapped their SIM card with mine, I guess by calling T-Mobile and pretending to be me.  They were like, “Hello, this is John Biggs, I upgraded my phone or something and need you to transfer service to my new phone.” Now, clearly this was not me calling, but T-Mobile must have believed them and made it happen.  

AND NOW A DRAMATIC RE-ENACTMENT, FEATURING JOHN BIGGS AS THE PHONE COMPANY REP AND ADAM B. LEVINE AS THE FAKE JOHN BIGGS.

Thanks for calling your phone company, how can I help you today?

Hi, yeah, I’m John Biggs and I need you to activate my new SIM card.

I’m happy to help you with that. Can you verify your account with your Social Security number, your blood type and your shoe size?

Actually no, I’m in a big hurry and just need you to help me out.

I’m sorry sir, I can’t help you if you can’t verify your account. 

Darn, OK, I’ll call back later.

Hello, this is another rep from your phone company. How can I help you?

Hi, I’m John Biggs and need you to activate my new phone.

Can you verify your account?

That’s fine, let me make that change now.

It’s pretty much that easy. The real trick is that if you don’t succeed with the first rep, you can call back basically an unlimited number of times until your phone company support slips up, forgets security protocol and agrees to make the change.  And these guys are really clever, with like crying baby sounds in the background and stuff.

That’s the social engineering part. Nobody is actually hacking or attacking your phone itself, they’re taking advantage of the fact that T-Mobile support wants to help you, or at least not get yelled at by you too much.  So when somebody calls up and pretends to be you, they can wind up helping someone trying to steal from you instead. So what happened?

Yeah, my carrier bought it alright, and helped them out by activating their new phone with my current number.  That, in turn, shut off network services to my phone and, moments later, allowed the hacker to change most of my Gmail passwords, my Facebook password and to text on my behalf. 

Ok, so now they have your cell phone, they get your phone calls, they get your text messages and you don’t. But how does that get them the ability to change all those passwords?

Just about every service out there from Gmail to Facebook to Coinbase to BYNANCE are concerned that you’re not going to do a good job of managing your passwords. So they did something even more insecure by adding two-factor authentication via text message. A lot of companies have stopped this, but it’s still a huge hole.

So when your phone became their phone, now they were the ones who could reset your password.

That’s right. All of the two-factor notifications went, by default, to my phone number, which was now their phone number, so I received none of the notifications and in about two minutes I was locked out of my digital life.

Yeah… I noticed all of this at about 10 p.m. and I was lucky. I knew what was happening and called T-Mobile. By 10:30 p.m. I reset my old SIM and began the process of changing all of my passwords and hardening my two-factor accounts and T-Mobile account.

So, this is a funny story. A week before I was talking to someone in crypto on Facebook. I forget what about. So a few days after that I got a message from that guy on Facebook Messenger saying, “Hey, I’m in a really bad financial situation and I can’t get to my crypto. Can you send me six bitcoin right and I’ll send you eight tomorrow?” 

And I’m like “Huh, that sounds like a good deal!”

Luckily, no, but that was the MO. When I was locked out of my accounts, the hackers pretended to be me and asked my friends to send them bitcoin. One of them texted one of my friends and said, “If I don’t get this crypto right now they’ll pull the plug on my dad at the hospital.” They had figured out my dad was sick. And the crypto friend was like “Uh, yeah, that’s not how hospitals work.”

There was also the case of Nicholas Truglia, a 21-year-old New Yorker who hijacked multiple phones and actually stole millions of dollars. According to court documents, Truglia is alleged to have stolen from his father and even a dead man.

Most notably, Truglia got Michael Terpin, a cryptocurrency investor. He used one of these socially engineered SIM swaps with Terpin’s phone to steal $24 million in crypto, which led to Terpin opening a $200 million lawsuit against his cell phone provider, AT&T. 

How much did this guy have? According to court documents, he had a number of Trezors. “One had over $40 million in cash value of various cryptos, and the other one had over $20 million cash value of various cryptos.” It’s nuts.

So how do you fight back?

My buddy Ralph, CEO of Seguru and Oliver Stone’s tech guy, has some ideas. I talked to him today about protecting yourself from SIM hacks.

So SIM locks and two-factor everything, but not with text messages.

Disclosure Read More

The leader in blockchain news, CoinDesk is a media outlet that strives for the highest journalistic standards and abides by a strict set of editorial policies. CoinDesk is an independent operating subsidiary of Digital Currency Group, which invests in cryptocurrencies and blockchain startups.

Credit: Source link

Tags: AdamBusinesscellular telephoneCryptoCrypto BusinessJohn Biggsmedia outletMissouri
Share76Tweet48
Previous Post

Compound Extends DeFi Ethos to Itself, Launches Governance Token

Next Post

Price Analysis Feb 26: BTC, ETH, XRP, BCH, BSV, LTC, EOS, BNB, XTZ, ADA

coinnewsdaily

coinnewsdaily

CoinNewsDaily.com is an online Crypto Coin News Website that aims to provide latest trendy news from market and around the world.

Related Posts

IoTeX’s MachineFi Lab challenges Big Tech by democratizing IoT to benefit users and businesses
Business

IoTeX’s MachineFi Lab challenges Big Tech by democratizing IoT to benefit users and businesses

Juli 26, 2022
ygg sea surpasses 10,000 scholarships in just six months of launch
Alt Coin

YGG SEA Surpasses 10,000 Scholarships in Just Six Months of Launch

Mai 6, 2022
5 projects enabling smart contract development on bitcoin
Alt Coin

5 Projects Enabling Smart Contract Development on Bitcoin

April 29, 2022
cross chain services play a crucial role in facilitating continued adoption of defi applications
Alt Coin

Cross-Chain Services Play a Crucial Role in Facilitating Continued Adoption of DeFi Applications

April 26, 2022
justin sun launches usdd, integrating the blockchain world and the real world with the decentralized stablecoin
Alt Coin

Justin Sun Launches USDD, Integrating the Blockchain World and the Real World with the Decentralized Stablecoin

April 25, 2022
what are wrapped tokens?
Bitcoin

What Are Wrapped Tokens?

April 23, 2022
Load More
Next Post
Price Analysis Feb 26: BTC, ETH, XRP, BCH, BSV, LTC, EOS, BNB, XTZ, ADA

Price Analysis Feb 26: BTC, ETH, XRP, BCH, BSV, LTC, EOS, BNB, XTZ, ADA

Kategorien

  • Alt Coin
  • Bitcoin
  • Business
  • Ethereum
  • ICO
  • Litecoin
  • Mining
  • NFT
  • Ripple
  • Tech
  • Trading

What New here?

  • 6 Questions for Rene Reinsberg of Celo – Cointelegraph Magazine
  • Judge denies SEC motion to keep Hinman docs secret in Ripple case
  • The ultimate guide to Miami – Cointelegraph Magazine
  • About Us
  • Contact Us
  • Privacy & Policy

© 2018-2021 CoinNewsDaily.com by CoinNewsDaily Inc. Crafted with Love by iFtiDev

Please enter CoinMarketCap Free Api Key to get this plugin works.
✕
No Result
View All Result
  • Home
  • Coin Market Cap
  • Bitcoin
  • Ethereum
  • Ripple
  • Litecoin
  • Alt Coin
  • Business
  • Trading
  • Mining

© 2018-2021 CoinNewsDaily.com by CoinNewsDaily Inc. Crafted with Love by iFtiDev