mastodon.gamedev.place is one of the many independent Mastodon servers you can use to participate in the fediverse.
Mastodon server focused on game development and related topics.

Server stats:

5.2K
active users

#sim

9 posts7 participants0 posts today

That's Not How A SIM Swap Attack Works

shkspr.mobi/blog/2025/04/thats

There's a disturbing article in The Guardian about a person who was on the receiving end of a successful cybersecurity attack.

EE texted to say they had processed my sim activation request, and the new sim would be active in 24 hours. I was told to contact them if I hadn’t requested this. I hadn’t, so I did so immediately. Twenty-four hours later, my mobile stopped working and money was withdrawn from my bank account.

With their alien sim, the ­fraudster infiltrated my handset and stole details for every account I had. Passwords and logins had been changed for my finance, retail and some social media accounts.

(Emphasis added.)

I realise it is in the consumer rights section of the newspaper, not the technology section, and I dare-say some editorialising has gone on, but that's nonsense.

Here's how a SIM swap works.

  1. Attacker convinces your phone company to reassign your telephone number to a new SIM.
  2. Attacker goes to a website where you have an account, and initiates a password reset.
  3. Website sends a verification code to your phone number, which is now in the hands of the attacker.
  4. Attacker supplies verification code and gets into your account.

Do you notice the missing step there?

At no point does the attacker "infiltrate" your handset. Your handset is still in your possession. The SIM is dead, but that doesn't give the attacker access to the phone itself. There is simply no way for someone to put a new SIM into their phone and automatically get access to your device.

Try it now. Take your SIM out of your phone and put it into a new one. Do all of your apps suddenly appear? Are your usernames and passwords visible to you? No.

There are ways to transfer your data from an iPhone or Android - but they require a lot more work than swapping a SIM.

So how did the attacker know which websites to target and what username to use?

What (Probably) Happened

Let's assume the person in the article didn't have malware on their device and hadn't handed over all their details to a cold caller.

The most obvious answer is that the attacker already knew the victim's email address. Maybe the victim gave out their phone number and email to some dodgy site, or they're listed on their contact page, or something like that.

The attacker now has two routes.

First is "hit and hope". They try the email address on hundreds of popular sites' password reset page until they get a match. That's time-consuming given the vast volume of websites.

Second is targetting your email. If the attacker can get into your email, they can see which sites you use, who your bank is, and where you shop. They can target those specific sites, perform a password reset, and get your details.

I strongly suspect it is the latter which has happened. The swapped SIM was used to reset the victim's email password. Once in the email, all the accounts were easily found. At no point was the handset broken into.

What can I do to protect myself?

It is important to realise that there's nothing you can do to prevent a SIM-swap attack! Your phone company is probably incompetent and their staff can easily be bribed. You do not control your phone number. If you get hit by a SIM swap, it almost certainly isn't your fault.

So here are some practical steps anyone can take to reduce the likelihood and effectiveness of this class of attack:

  • Remember that it's OK to lie to WiFi providers and other people who ask for your details. You don't need to give someone your email for a receipt. You don't need to hand over your real phone number on a survey. This is the most important thing you can do.
  • Try to hack yourself. How easy would it be for an attacker who had stolen your phone number to also steal your email address? Open up a private browser window and try to reset your email password. What do you notice? How could you secure yourself better?
  • Don't use SMS for two-factor authentication. If you are given a choice of 2FA methods, use a dedicated app. If the only option you're given is SMS - contact the company to complain, or leave for a different provider.
  • Don't rely on a setting a PIN for your SIM. The PIN only protects the physical SIM from being moved to a new device; it does nothing to stop your number being ported to a new SIM.
  • Finally, realise that professional criminals only need to be lucky once but you need to be lucky all the time.

Stay safe out there.

A padlock engraved into a circuit board.
Terence Eden’s Blog · That's Not How A SIM Swap Attack Works
More from Terence Eden

🆕 blog! “That's Not How A SIM Swap Attack Works”

There's a disturbing article in The Guardian about a person who was on the receiving end of a successful cybersecurity attack.

EE texted to say they had processed my sim activation request, and the new sim would be active in 24 hours. I was told to contact them if I hadn’t requested this. I hadn’t, so I did …

👀 Read more: shkspr.mobi/blog/2025/04/thats

#2fa #CyberSecurity #MFA #security #sim

A padlock engraved into a circuit board.
Terence Eden’s Blog · That's Not How A SIM Swap Attack Works
More from Terence Eden

Oh! Le jeu de relaxation et de photographie Lushfoil Photography Sim est dispo. Petite surprise d'Annapurna d'annoncer sa dispo dans la journée.

Décors photoréalistes, ambiances sonores, et DD multiples appareils photos à dompter pour une expérience qui semble unique.
Sur PC et consoles (Xbox Series et PlayStation 5)

Si j'ai l'énergie cette semaine, je proposerai une diffusion en direct spéciale découverte.

#photographie #jeuxvideo #sim

youtube.com/watch?v=bB3BR_T7gs

If you change your #phone #sim temporarily, i.e. use a new phone number, #Signal keeps working as before. #WhatsApp stops working if you change your sim i.e. phone number. Signal knocks the socks off whatsapp for staying in touch while travelling, when your normal sim and phone number have malfunctioned (my new #telekom cellular provider cancelled my old SIM & provider & sent me their new SIM for new contract: while I was abroad, without asking me if this date suits). Signal rocks. Use signal.

I found two amazing games (well, a game 'concept' or two). Joking with @skullvalanche about dating sims (NON x rated) with like, just realistic animals, and I actually FOUND two.

🐦 On The Fly is an endless runner/dating sim - two birds, their love forbidden by their families, escape down a river on a kettle.
sparrowhousegames.itch.io/on-t

🐬 Vaporwhale: Hot Date involves you being Leonard, an orca looking for love. You make a Fin-der account, meet Tiffany, a dolphin, and keep up with the conversation by collecting her talking bubbles on your first date.
mikeyren.itch.io/vaporwhale

😂 🔥

itch.ioOn The Fly by sparrowhousegamesA pair of birds elope down the river on a rusty old kettle.

Follower-Power:

Fürs @kuketzblog will ich mal Anbieter und Lösungen vergleichen, um sich regelmäßig, günstig und komfortabel mit einer #Wegwerf-Mobilnummer (#SIM oder #eSIM) zu versorgen.

- Maximal 20€, besser <=5€ pro Monat
- Nummernwechsel ohne erneuten ID-Nachweis.

Aktuell habe ich nur Spezial-/Profidienste im Rennen (seven.io, Sipgate, etravelsim.com). Die meisten Prepaid-Anbieter bieten wohl keinen bequemen Nummernwechsel-/Zubuchung, höchstens per Hotline und teuer.

Habt ihr Tipps?

Какая-то непонятная ситуация происходит: на номера +7910... (МТС - бывший "Скайлинк") и +7905... ("Билайн", но с +7905... "Теле2" пока всё хорошо), кажется перестали приходить SMS-коды зарубежных мессенджеров. Вчера знакомый из Рязани тестировал корпоративные SIM, будучи в Москве на работе.
Началось с того, что хотел себе на номер +7910... пробовал ставить #Signal Messenger (мануал в txt: u.to/eQk3Ig ) и когда ничего не получилось, начал проверять все #SIM, что было в офисе. Не хотелось бы никого пугать, но если имеете тел.номер на +7910... (МТС) и +7905... ("Билайн"), то проверить бы как там ставятся с нуля зарубежные мессенджеры, требующие активации через SMS-код. Наверное мало для кого секрет, но #WhatsApp с нуля регистрируется только с включенным VPN (по крайней мере, много где в РФ) - только тогда его сервер(а) получают Инет-запрос и отправляется SMS-код на телефон.
Информация требует проверки, но по-моему обозначается направление, как хотят бороться с запрещёнными зарубежными сервисами. По правде, давно такие мысли посещали и, наверное, не меня одного, чего они банят домены, когда можно просто перекрыть приход сомнительных #SMS , и вот, возможно, началось.
Не знал, стоит ли публиковать такую информацию, может это случайно так совпало, а может и нет.
#tech #РКН @ru @rf

Tonight (3/26/25 at 6pm EDT), I'm going to make a few different examples of how to create a kinetic wind sculpture. I'm referencing a video that my co-worker sent me. I'm going to try to make a few versions: purely procedural, driven by a pyro sim, and possibly a dynamic version.

#houdini#sidefx#vfx