We're aware that some users are experiencing technical issues which the team are working to resolve. See the Community Noticeboard for more info. Thank you for your patience.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

These SIM Swap scams....how worried should we be??

Options
123457»

Comments

  • Ant2112
    Ant2112 Posts: 2 Newbie
    So I work in Information Security and I think this is something to be worried about.



    We use our phones as a authentication factor, from a 2FA point of view its usually the "Something you have". if someone can get a new SIM then they have a clone of your phone. Yes they need to know all sorts of other info about you in order to access your cash, but as someone else said, pretty much everyone has had their data lost by some organisation or other over the last few years. Go check out a website called "Have I Been Powned" (Google it). This is run by a trusted security blogger and allows you to see if your email address has appeared in any of the thousands of data dumps of billions of records that have appeared on the internet and dark web over the last five or six years.

    I agree that having a cloned phone in isolation is of no real use. However, an attacker will attempt to gather information about their target from many sources. The YouTube video called "Amazing mind reader reveals his 'gift" that you should see if you search YouTube for "Mystic Dave" demonstrates this nicely. (Sorry, I cdan't post links in comments as a new forum user).

    A key concept of information security is "Defense in Depth" which means protect at every stage to ensure one failing doesn't expose an entire system. A corollary to this concept would be the "gather everything" approach that attackers take when targeting someone.



    Remember that successful attacks use social engineering, not just against you, but against the support center staff, the phone shop staff (for obtaining the SIM) and anyone else they need to con. Social Engineers (Con artists) are very convincing, they will spin a convincing tale and use advanced psychological techniques to manipulate people.


    Anyhow, sorry for the ramble, in short, yes you should be aware of this and make appropriate considerations depending on your overall position. I've recently requested separate physical 2FA devices from the financial institutions I use that support them specifically for this purpose.
  • DCFC79
    DCFC79 Posts: 40,641 Forumite
    Part of the Furniture 10,000 Posts Name Dropper
    Tara_M wrote: »
    Don't do online banking.... simples.

    Yet I do online banking and Ive not been sim swapped or anything fraudulant has happened.
  • Sea_Shell
    Sea_Shell Posts: 10,025 Forumite
    Tenth Anniversary 1,000 Posts Photogenic Name Dropper
    DCFC79 wrote: »
    Yet I do online banking and Ive not been sim swapped or anything fraudulant has happened.

    Ah but the big question is.....Is this by luck, or judgement!!??
    How's it going, AKA, Nutwatch? - 12 month spends to date = 2.60% of current retirement "pot" (as at end May 2025)
  • robatwork
    robatwork Posts: 7,266 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Photogenic
    Ant2112 wrote: »
    Go check out a website called "Have I Been Powned" (Google it).

    I agree that having a cloned phone in isolation is of no real use. However, an attacker will attempt to gather information about their target from many sources. The YouTube video called "Amazing mind reader reveals his 'gift" that you should see if you search YouTube for "Mystic Dave" demonstrates this nicely. (Sorry, I cdan't post links in comments as a new forum user).

    It's have I been pwned and is a good and genuine resource

    https://haveibeenpwned.com/

    The Mystic Dave on the other hand is in fact just an advert for a bank and has no business being in your diatribe, unless I am looking at the wrong video. It doesn't demonstrate anything other than the pretty obvious - people can see your facebook page.
  • Sea_Shell wrote: »
    Ah but the big question is.....Is this by luck, or judgement!!??

    It's by not responding to malicious phishing emails and text messages from scammers.
  • molerat
    molerat Posts: 34,578 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    !!! wrote: »
    It's by not responding to malicious phishing emails and text messages from scammers.
    Or by posting your details all over social media.
  • masonic
    masonic Posts: 27,210 Forumite
    Part of the Furniture 10,000 Posts Photogenic Name Dropper
    edited 30 May 2018 at 6:05PM
    !!! wrote: »
    It's by not responding to malicious phishing emails and text messages from scammers.
    ...or by not buying goods and services from any companies who have suffered a data breach.
  • Sea_Shell
    Sea_Shell Posts: 10,025 Forumite
    Tenth Anniversary 1,000 Posts Photogenic Name Dropper
    Well the good news is that my main "official" e-mail has not been pwned!!!8230;.so that's a start!!

    I have another which is showing 1 breach...but I don't have any financial connections to that one. And I do tend to give slightly false personal data to sites that use that one. Wrong DOB's and that sort of thing.
    How's it going, AKA, Nutwatch? - 12 month spends to date = 2.60% of current retirement "pot" (as at end May 2025)
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 351K Banking & Borrowing
  • 253.1K Reduce Debt & Boost Income
  • 453.6K Spending & Discounts
  • 244K Work, Benefits & Business
  • 598.9K Mortgages, Homes & Bills
  • 176.9K Life & Family
  • 257.3K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.