HomeSecurityGoogle Fi: Data Breach Allows SIM Swapping Attacks

Google Fi: Data breach allows SIM swapping attacks

Google Fi, the telecommunications and mobile Internet service provided by Google to U.S. residents, recently warned its users that their personal data was exposed due to a breach at one of its main network providers. Google Fi customers were also informed of potential SIM swapping attacks as a result of the data breach.

SIM swapping

Google sent notifications to Google Fi customers informing them of the data breach that resulted in the numbers phone, SIM card serial numbers, account status (active or inactive), account activation date, and mobile service plan details.

Google assured that the systems that were attacked did not store sensitive personal information such as names, email addresses , payment card details, social security numbers, tax numbers, ID numbers, passwords or phone/SMS conversations.

See also: InTheBox: Over 1,800 malicious phishing forms available

“ The incident response team conducted an investigation, determined that unauthorized access had occurred, and worked with our primary network provider to identify and implement data security measures on this third-party system, as well as notify anyone who may have been affected ,” the customer notification states

"There was no access to Google systems or systems overseen by Google," the company added.

Although Google has yet to clarify which network provider was breached, many believe it to be T-Mobile.

Last month, T-Mobile revealed that a data breach occurred in November 2022, exposing the personal information of approximately 37 million customers.

Google Fi Data Breach

Google Fi users are exposed to SIM swapping attacks

Unfortunately, the exposed SIM data allowed malicious actors to launch SIM swapping attacks on Google Fi customers. One customer reported that hackers gained access to Authy MFA account .

SIM swapping attacks are a form of cybercrime in which perpetrators convince telecommunications companies to transfer their victims' phone numbers to SIM cards they control, thereby gaining access to the victim's information.

See also: LockBit Green ransomware: New version is based on Conti's source code

These attacks are carried out using social engineering, where the threat actor impersonates the customer and requests that the number be ported to a new device. To convince the mobile provider that they are the customer, they provide personal information obtained through phishing attacks and data.

Since the Google Fi data breach involved phone numbers, which can easily be linked to a customer's name and SIM card serial number, scammers could become even more persuasive when speaking to a mobile customer support representative over the phone.

Once the number is ported, attackers will have access to the victim's messages, including MFA codes, allowing them to gain access to accounts and services.

Google sent a separate notice to customers affected by SIM swapping attacks, revealing that the attackers managed to transfer their numbers to another SIM for a short period of time.

“On January 1, 2023, for approximately 1 hour and 48 minutes, your mobile phone service was transferred from your SIM card to another SIM card. During this temporary transfer, unauthorized access could include using your phone number to send and receive phone calls and messages . Despite the SIM transfer, your voicemail was not accessible. We have restored Google Fi service to your SIM card,” Google said.

See also: Hackers use IceBreaker malware to compromise gaming companies

Google Fi: Data breach allows SIM swapping attacks

A victim customer shared his experience on Reddit, saying that a hacker made the change to the SIM and was able to gain access to his primary email, a financial account, and the Authy Authenticator app, after being able to receive the SMS with the code for 2FA.

Despite his attempts to stop it by updating Google Fi, he says he was ignored by customer support.

“I tried to report this to Google Fi repeatedly, including with detailed details, and their customer support reps didn’t believe me and didn’t follow up,” the customer said. “They thought it was a typical password breach or something, even though I could clearly see from the activity logs that the hacker was resetting my passwords instead of logging in and then changing them, and I could see in the Google Fi activity logs that I wasn’t receiving SMS messages but they were being received by someone to hack into my accounts.”

SIM swapping attacks are an increasingly common form of fraud used by criminals looking for ways to gain access to our personal information. By understanding what they are and taking steps to secure our personal data, we can protect ourselves from these types of attacks. Remember to always use strong passwords for all online accounts, be careful about the data you share online, enable two-factor authentication whenever possible, avoid clicking on suspicious links in emails or text messages, and be aware of any suspicious activity related to accounts associated with your phone number. Taking these precautions will go a long way in keeping our data safe!

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS