Researchers at Princeton University have published a report stating that five major US telecommunications companies are vulnerable to SIM swapping attacks.
In SIM swapping attacks, attackers call a company , trick the staff, and convince them to change the victim's number so that it is linked to a SIM card controlled by them (the attackers).
This allows resetting passwords and gaining access to the victim's personal accounts (email, inbox, e-banking portals, cryptocurrency systems, etc.).
The Princeton researchers conducted their research over a year. During that time, they examined five major U.S. telecommunications companies. Specifically , they wanted to see if they could trick call center employees into switching a user's phone number to another SIM without providing the correct credentials .
According to the research, popular carriers AT&T, T-Mobile, Tracfone, US Mobile, and Verizon Wireless use processes that attackers could use to carry out SIM swapping attacks.
The researchers also examined 140 online services and websitesto see which ones could be exploited by malicious hackers to compromise user accounts. 17 of the 140 websites were indeed vulnerable to this type of attack.
Research
For their research, the researchers worked with the five telecommunications companies (supposedly as customers) and tried to use the SIM cards (10 from each company) and make calls, in order to create a realistic call history.
Later, the researchers called the companies' customer service centers and requested a SIM card change, providing (intentionally) incorrect information about the PIN and account holder.
According to the procedures provided by the companies, if someone does not correctly provide the above information (PIN and account holder information), they will be required to provide details regarding the last two calls they made.

The research team says that an attacker could trick a victim into calling specific numbers before performing the SIM swapping attack, in order to have the details of the last calls. For example, they could tell the victim: “You won a prize, call here. Sorry, wrong number, call here.” That way, they have the details of the last two calls (if the victim falls for the trap).
The Princeton researchers said they used this trick and managed to defraud all five American companies.
In the end, the researchers notified the companies of the security, but as of the report's publication a few days ago, four of the five carriers were still using the same procedures. Only T-Mobile changed its tactics after the investigation.
Services and websites
Regarding online services and websites (social media networks, email providers, websites, cryptocurrency sites and many more), the researchers examined the identity verification processes they used.
Once the researchers had carried out the SIM swapping attack and had control of the victim's number, they were able to gain access to the victims' accounts on 17 of these sites.
The account recovery process for these sites relied solely on SMS verification . Once the researchers (or attackers) control the victim's number, they also control the SMS. So they can gain access to the other accounts.
More details are provided in the paper entitled: “An Empirical Study of Wireless Carrier Authentication for SIM Swaps“.
