The SecNews team is conducting an investigation into SIM Swap scams in Greece. The investigation will shed light on many questions surrounding the dangerous method of hacking into the bank accounts of Greek citizens.
Shortly afterthepublication of the SecNews teaser for the investigation, the Hellenic Banking Association issued the following announcement, which we are retransmitting:
Information and awareness about the typology of fraud "SIM Swapping"
The use of the mobile phone number as one of the main and basic elements for the strong and reliable identification of its owner/subscriber is an international practice used by organizations, companies and the public for the services they offer.
Banks are no exception to this practice, as they use their customers' mobile phone numbers as the means to send one-time passwords (OTPs) that enhance the security of electronic transactions (fund transfers, card purchases, etc.), send security alerts for transactions that have been executed, and remotely register them for new services.

What is SIM Swapping fraud ?
First of all, SIM card replacement/change (SIM Replace) is a completely legal service offered by mobile phone providers to their subscribers, so that the latter can keep their phone number in case of loss or theft of their device or due to the need to use a different size SIM card. Upon activation of the new SIM card, the old card is automatically deactivated and mobile phone services (calls, SMS, internet access) are now carried out by the new card that operates with the same number.
In cases of SIM Swapping fraud, perpetrators exploit the ability to change SIM cards and pretend to be either the owner of the SIM card or someone authorized by the legitimate subscriber, thus attempting to defraud mobile phone providers and obtain a new card to replace the one the legitimate owner has.
Once they activate the new card, the old one, which is in the possession of the legitimate subscriber, is deactivated and thus all services (calls, SMS, internet access) are received on the device in the possession of the defrauded perpetrator, enabling them to carry out illegal activities without the knowledge of the legitimate subscribers (e.g. receiving calls and messages intended for them, intercepting one-time codes or security verification messages, etc.).

But how can the perpetrators, by replacing/exchange the SIM card , access my e - Banking ?
Unauthorized replacement/exchange of the SIM card is usually the second part of the above illegal modus operandi. In the first part, the perpetrators have managed to steal e-Banking usually through a phishing email or through malicious software (trojan/malware) that they have installed on the victim's computer.

Useful Tips, What can I do?
- If your phone stops working for unusual reasons, contact your mobile carrier immediately. Sometimes you can lose signal due to broader issues affecting your mobile service. However, if you lose service in a location that usually has good coverage, it's safest to contact your network provider and confirm that your SIM card hasn't been deactivated.
- Do not reveal your mobile phone number on social media.
- Subscribe to the services of organizations that provide SMS and email notifications when your transactions are executed.
- Never respond to unknown messages or calls asking for your account information and registered mobile phone number.
- Do not follow links or open attachments that you may receive from unknown email senders. Check the sender carefully as perpetrators often pretend to be legitimate businesses and organizations.
- Do not share your e-banking codes (username and password) or card numbers with anyone or enter them on unknown websites. Confirm that you have visited the official website of your Bank and remember that banks will never ask you for your codes in any way.
- your computer and devices (tablets, smartphones) up-to-date with the latest operating system and application updates. Install and keep a reliable anti-malware program up-to-date.
- Check your account transactions frequently.
- If you have fallen victim to SIM Swapping fraud or have noticed transactions that do not have your approval, inform your Bank immediately.

What measures are banks taking?
Banks cannot know if a subscriber has fallen victim to SIM Swapping fraud, phishing, or if their computer has been infected with malware and their passwords have been intercepted.
Banks always aim to secure electronic transactions in accordance with current technical and technological developments,global best practices in the field of information security as well as applicable laws and regulations. In addition, great emphasis is placed on the user experience and speed of the services they provide to their Customers.

Electronic fraud is a broader problem and in order to deal with it, the cooperation of many parties involved is required in order to prevent or anticipate it. Especially during this period, when the use of electronic services has increased significantly worldwide due to the coronavirus, perpetrators are trying to exploit the special conditions with increased attempts to steal data. A special Committee for the Prevention and Combating of Fraud in Payment Means and Systems has been established within the Hellenic Association of Banks with the aim of monitoring, processing and providing guidance in this area. The Committee coordinates the cooperation with the Electronic Crime Prosecution of the Hellenic Police, the Bank of Greece and systematically cooperates with other competent bodies in Greece and abroad.
For more security tips as well as transaction protection measures at each bank, you can visit their official websites, the website of Europol and the Hellenic Banks Association.
