Daily Mail PH

Monday, July 17, 2023

[New post] How easy is a SIM swap attack? Here’s how to prevent one

Site logo image admin posted: "Despite the rise of cybersecurity infrastructure, the online identity still faces many risks, including those related to the hacks of one's phone numbers.In early July, LayerZero CEO Bryan Pellegrino became one of the latest victims of a SIM swap attack, " Crypto Timeless

How easy is a SIM swap attack? Here's how to prevent one

admin

Jul 17

Despite the rise of cybersecurity infrastructure, the online identity still faces many risks, including those related to the hacks of one's phone numbers.

In early July, LayerZero CEO Bryan Pellegrino became one of the latest victims of a SIM swap attack, which allowed hackers to briefly take over his Twitter.

And... we're back in. This was basically my life for the past 24 hours. Luckily we saw hack immediately and the battle began pic.twitter.com/pjrkMfQ2vT

— Bryan Pellegrino (@PrimordialAA) July 5, 2023

"My guess is that somebody grabbed my badge out of the trash and somehow was able to trick a rep into using it as a form of ID for the SIM swap while I was leaving Collision," Pellegrino wrote soon after having his Twitter account back.

"It was 'Bryan Pellegrino — speaker' just your normal paper conference badge," Pellegrino told Cointelegraph.

The incident involving Pellegrino's mishap may lead to users assuming that performing a SIM swap hack is as easy as just grabbing someone's badge. Cointelegraph has reached out to some cryptocurrency security firms to find out whether that's the case.

What is a SIM swap hack? How big is it?

A SIM swap hack is a form of identity theft where attackers take over a victim's phone number, allowing them to gain access to bank accounts, credit cards or crypto accounts.

In 2021, the Federal Bureau of Investigation received more than 1,600 SIM swapping complaints involving losses of more than $68 million. This represented a 400% increase in the number of complaints received in the three prior years, indicating that SIM swapping is "definitely on the rise," CertiK's director of security operations Hugh Brooks told Cointelegraph.

"If there is no move away from SMS-based 2FA and telecommunications providers do not lift their security standards, we are likely to see attacks continue to grow," Brooks stated.

According to SlowMist chief information security officer (CISO) 23pds, SIM swapping is currently not too widespread, but it has a significant potential to rise further in the near future. He stated:

"As the popularity of Web3 grows and attracts more people into the industry, the likelihood of SIM swapping attacks also increases due to its relatively lower technical requirements."

23pds mentioned a few cases involving SIM swap hacks in crypto over the past few years. In October 2021, Coinbase officially disclosed that hackers stole crypto from at least 6,000 customers due to a 2FA breach. Previously, British Hacker Joseph O'Connor was indicted in 2019 for stealing roughly $800,000 in crypto via multiple SIM swap hacks.

How hard is it to perform a SIM swap hack?

According to CertiK's exec, SIM swap hacking can often be done with information that is publicly available or can be obtained through social engineering.

"Overall, SIM swapping might be seen as a lower barrier to entry for attackers when compared to the more technically demanding attacks like smart contract exploits or exchange hacks," Brooks said.

SlowMist's 23pds agreed that SIM swapping doesn't require high-level technical skills. He also noted that such SIM swaps are "prevalent even in the Web2 world," so it's "not surprising" to see it emerge in the Web3 environment as well.

"It is often easier to execute, with social engineering being used to deceive relevant operators or customer service personnel," 23pds said.

How to prevent SIM swapping hacks?

As SIM swap attacks are often seen as non-demanding in terms of hackers' technical skills, users must pay due diligence to their identity security to prevent such hacks.

The core protection measure from a SIM swap hack is to restrict the usage of SIM card-based methods for 2FA verification. Instead of relying on methods like SMS, one should better use apps like Google Authenticator or Authy, Hacken's Budorin noted.

SlowMist CISO 23pds also mentioned more strategies like multi-factor authentication and enhanced account verification like additional passwords. He also strongly recommended users to establish strong PIN or passwords for SIM cards or mobile phone accounts.

Related: Over $765K worth of NFTs stolen after SIM swap attack on Gutter Cat Gang

Another measure to avoid SIM swapping is to properly protect personal data like name, address, phone number and date of birth. SlowMist CISO also recommended scrutinizing online accounts for any anomalous activity.

Platforms should be also responsible for promoting safe 2FA practices, CertiK's Brooks stressed. For example, firms can require additional verification before allowing changes to account information and educate users about the risks of SIM swapping.

Additional reporting by Cointelegraph editor Felix Ng.

Magazine: Asia Express: China expands CBDC's tentacles, Malaysia is HK's new crypto rival

Comment

Unsubscribe to no longer receive posts from Crypto Timeless.
Change your email settings at manage subscriptions.

Trouble clicking? Copy and paste this URL into your browser:
https://cryptotimeless.com/2023/07/17/how-easy-is-a-sim-swap-attack-heres-how-to-prevent-one/

WordPress.com and Jetpack Logos

Get the Jetpack app to use Reader anywhere, anytime

Follow your favorite sites, save posts to read later, and get real-time notifications for likes and comments.

Download Jetpack on Google Play Download Jetpack from the App Store
WordPress.com on Twitter WordPress.com on Facebook WordPress.com on Instagram WordPress.com on YouTube
WordPress.com Logo and Wordmark title=

Automattic, Inc. - 60 29th St. #343, San Francisco, CA 94110  

at July 17, 2023
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest

No comments:

Post a Comment

Newer Post Older Post Home
Subscribe to: Post Comments (Atom)

CG BOSS Posts from Gargoyles Reboot thanks to creator kept it alive | CG BOSS Games for 04/26/2026

CG BOSS Blog Post Updates ...

  • [New post] 5 Key Technologies Streamlining the Crypto User Experience
    ...
  • CG BOSS Posts from Gargoyles Reboot thanks to creator kept it alive | CG BOSS Games for 04/26/2026
    CG BOSS Blog Post Updates ...
  • Why is Ninoy Aquino Day important to you? Join Rappler’s chat on August 21!
    Hi daily! Who is Ninoy Aquino to you? What lessons from his life still spea...

Search This Blog

  • Home

About Me

Daily Newsletters PH
View my complete profile

Report Abuse

Labels

  • Last Minute Online News

Blog Archive

  • April 2026 (1)
  • February 2026 (1)
  • January 2026 (7)
  • December 2025 (8)
  • November 2025 (4)
  • October 2025 (2)
  • September 2025 (1)
  • August 2025 (2)
  • July 2025 (5)
  • June 2025 (3)
  • May 2025 (2)
  • April 2025 (2)
  • February 2025 (2)
  • December 2024 (1)
  • October 2024 (2)
  • September 2024 (1459)
  • August 2024 (1360)
  • July 2024 (1614)
  • June 2024 (1394)
  • May 2024 (1376)
  • April 2024 (1440)
  • March 2024 (1688)
  • February 2024 (2833)
  • January 2024 (3130)
  • December 2023 (3057)
  • November 2023 (2826)
  • October 2023 (2228)
  • September 2023 (2118)
  • August 2023 (2611)
  • July 2023 (2736)
  • June 2023 (2844)
  • May 2023 (2749)
  • April 2023 (2407)
  • March 2023 (2810)
  • February 2023 (2508)
  • January 2023 (3052)
  • December 2022 (2844)
  • November 2022 (2673)
  • October 2022 (2196)
  • September 2022 (1973)
  • August 2022 (2306)
  • July 2022 (2294)
  • June 2022 (2363)
  • May 2022 (2299)
  • April 2022 (2233)
  • March 2022 (1993)
  • February 2022 (1358)
  • January 2022 (1323)
  • December 2021 (2064)
  • November 2021 (3141)
  • October 2021 (3240)
  • September 2021 (3135)
  • August 2021 (1782)
  • May 2021 (136)
  • April 2021 (294)
Simple theme. Powered by Blogger.