A study by Princeton University researchers showed that five of the major US wireless carriers are susceptible to SIM swapping attacks. The five wireless carriers are AT&T, T-Mobile, Verizon, Tracfone, and US Mobile.
Brief detail about SIM swapping
SIM swapping, also known as port-out or SIM swap scams, has become a popular attack method for cybercriminals. A basic attack scenario involves attackers using social engineering to gain control of the target user’s phone number. From there, they can break into the victim’s banking, social media and other accounts that use the same phone number for multi-factor authentication.
What does the new study reveal about carrier providers?
What are the other findings?
The researchers also analyzed 145 websites - that use phone-based authentication - to understand the impact of SIM Swap scams. Out of these, researchers could easily compromise 17 websites with just a SIM swap.
How did the companies respond?
The wireless carriers have been notified about the shortcomings of their authentication procedures. T-Mobile has responded to the issue by discontinuing the use of call logs for customer authentication, says the study.Publisher