HomeSecurityPopular US telecom companies vulnerable to SIM swapping attacks

Popular US telecom companies vulnerable to SIM swapping attacks

SIM swappingResearchers at Princeton University have published a report stating that five major US telecommunications companies are vulnerable to SIM swapping attacks.

In SIM swapping attacks, attackers call a company , trick the staff, and convince them to change the victim's number so that it is linked to a SIM card controlled by them (the attackers).

This allows resetting passwords and gaining access to the victim's personal accounts (email, inbox, e-banking portals, cryptocurrency systems, etc.).

The Princeton researchers conducted their research over a year. During that time, they examined five major U.S. telecommunications companies. Specifically , they wanted to see if they could trick call center employees into switching a user's phone number to another SIM without providing the correct credentials .

According to the research, popular carriers AT&T, T-Mobile, Tracfone, US Mobile, and Verizon Wireless use processes that attackers could use to carry out SIM swapping attacks.

The researchers also examined 140 online services and websitesto see which ones could be exploited by malicious hackers to compromise user accounts. 17 of the 140 websites were indeed vulnerable to this type of attack.

Research

For their research, the researchers worked with the five telecommunications companies (supposedly as customers) and tried to use the SIM cards (10 from each company) and make calls, in order to create a realistic call history.

Later, the researchers called the companies' customer service centers and requested a SIM card change, providing (intentionally) incorrect information about the PIN and account holder.

According to the procedures provided by the companies, if someone does not correctly provide the above information (PIN and account holder information), they will be required to provide details regarding the last two calls they made.

Popular US telecom companies vulnerable to SIM swapping attacks

The research team says that an attacker could trick a victim into calling specific numbers before performing the SIM swapping attack, in order to have the details of the last calls. For example, they could tell the victim: “You won a prize, call here. Sorry, wrong number, call here.” That way, they have the details of the last two calls (if the victim falls for the trap).

The Princeton researchers said they used this trick and managed to defraud all five American companies.

In the end, the researchers notified the companies of the security, but as of the report's publication a few days ago, four of the five carriers were still using the same procedures. Only T-Mobile changed its tactics after the investigation.

Services and websites

Regarding online services and websites (social media networks, email providers, websites, cryptocurrency sites and many more), the researchers examined the identity verification processes they used.

Once the researchers had carried out the SIM swapping attack and had control of the victim's number, they were able to gain access to the victims' accounts on 17 of these sites.

The account recovery process for these sites relied solely on SMS verification . Once the researchers (or attackers) control the victim's number, they also control the SMS. So they can gain access to the other accounts.

More details are provided in the paper entitled: “An Empirical Study of Wireless Carrier Authentication for SIM Swaps“.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS