In early March, news broke that telecom giant T-Mobile fell victim to a hostile cyber-breach. Unfortunately, in the coming days, weeks, and months, many of the reported 400 T-Mobile customers whose data was stolen will have to pay a high price for this security failure.
While the details of the T-Mobile cyber-breach remain a mystery, the playbook used by these cybercriminals is well-documented. Using a customer’s stolen PIN, cybercriminals tricked T-Mobile’s Customer Support Team into authorizing a SIM Swap, thereby diverting all text messages and calls to the cybercriminal’s phone.
With the newly compromised phone and the stolen customer data, the crook could easily pass through a Two-Factor SMS Verification process and gain entry into the victim’s online accounts. In fact, it only took few minutes for the fraudster to drain a lifetime’s worth of savings.
Tech journalist Matthew Miller recounted his harrowing experience of almost losing $25,000 after a cybercriminal “hijacked” his phone and attempted to purchase $25,000 worth of bitcoins from his family’s savings account. Luckily, the bank’s fraud department put a stop to the transaction.
In addition to stealing Miller’s money, the cybercriminal also deleted “decades of data” from his Google Drive and social media accounts.
Although economic data on SIM Swaps is scant, there is no doubt that the overall economic impact of fraud is immense. In 2020, the Federal Trade Commission reported that US consumers lost more than $3.3 billion to fraud. As e-commerce continues to grow, this number will likely rise.
Fortunately, banks and online businesses can now fortify their Two-Factor Verification process with the help of Prove’s Trust Score™—a real-time measure of a phone number’s reputation. This Trust Score™ identifies phone numbers that have been associated with a SIM swap or other suspicious activity, and it stops would-be scammers from bypassing the Two-Factor Verification process.
As cybercriminals grow more sophisticated, bolstering the Two-Factor Verification process is critical for both businesses and their consumers.