Current:Home > StocksOne Tech Tip: Protecting yourself against SIM swapping -AssetVision
One Tech Tip: Protecting yourself against SIM swapping
View
Date:2025-04-13 05:46:45
NEW YORK (AP) — SIM-swapping is a growing form of identity theft that goes beyond hacking into an email or social media account. In this case, the thieves take over your phone number. Any calls or texts go to them, not to you.
Any protections consumers enabled to secure access to their financial accounts, such as two-factor authentication texts, now can aid attackers and lock out owners.
Experts say these scams will only increase and become more sophisticated, while the data show they are on the rise. The FBI Internet Crime Complaint Center reports that SIM-swapping complaints have increased more than 400% from 2018 to 2021, with associated personal losses estimated to be more than $68 million.
Rachel Tobac, CEO of online security company SocialProof Security, says the numbers are probably a vast underestimate because most identity thefts are not reported.
How does the scheme work?
Criminals use personal information about their victims — phone numbers, addresses, birthdays and Social Security numbers — obtained through data breaches, leaks, dark web purchases or phishing scams to impersonate the victims as they contact their mobile carriers.
They will claim the original phone and SIM card were damaged, lost or sold accidentally and ask for the number to be associated with a new SIM, or eSIM, card in their possession. Once this is done, the phone number belongs to the criminals, along with the ability to receive text messages or calls to verify accounts.
Prevention is the best form of protection, according to cybersecurity experts. The tricks and habits security experts say help prevent SIM-swapping are what they have long been recommending for online security in general. They include the following:
Better password habits
If your credentials are caught in a cyber breach, the hackers could try using the stolen passwords to get into other services to gather the personal data they need to pull off a SIM swap.
If you’ve been using the same or similar login information for multiple websites or online accounts, make sure to change it. If criminals pilfer your password from one service, they can try it on your other accounts and easily get into all of them. If you find it too hard to memorize your various credentials, consider a password manager.
Also use strong passwords that include letters, numbers and symbols. The longer they are, the better. Some experts say they should be 16 characters.
Multifactor authentication without texts
Add biometrics or multifactor authentication apps and devices that do not involve texting. These methods often use separate login methods and encryption that are not tied to your phone’s identity, making them more difficult for criminals to access.
AT&T also advises contacting your carrier to set up a unique passcode to prevent significant account changes such as porting phone numbers to another carrier. Your carrier may already have other protections in place to protect against SIM swapping, so it’s worth calling them to ask.
Watch out for phishing schemes (especially at work)
Criminals will use email or text messages to try to trick you into giving them your personal and financial information or to expose your workplace to possible attacks, and it’s incredibly effective.
In its annual State of the Phish report, the cybersecurity firm Proofpoint found a majority of data breaches across the world still center on human lapses.
If you suspect you have received a possible phishing message or email, report it. Most of the popular email platforms have buttons or functions specifically for reporting phishing attempts. If you’re at work, follow the advice from your company’s information security team.
Steps to take if you’re a victim
All major U.S. carriers have web pages advising victims how to report a SIM fraud.
But an Associated Press reporter, who recently was hit by such an attack, advises that victims should be diligent in working with the carrier to fix the issue. Filing complaints with the Federal Trade Commission, the Internet Crime Complaint Center or with their state attorneys general can possibly expedite recovery efforts.
If card payment numbers were stolen, inform your bank or credit card company, explaining that your card is at risk of fraud and asking the company to alert you to any suspicious activity.
You can also notify credit agencies, including the three main firms: Equifax, Experian and TransUnion. They can freeze your credit, which restricts access to your credit report and makes it hard to open new accounts or issue a fraud alert and will add a warning to your credit report encouraging lenders to contact you before lending money.
veryGood! (39255)
Related
- Mets have visions of grandeur, and a dynasty, with Juan Soto as major catalyst
- Tropical storm warnings issued on East Coast: What to expect
- New York pay transparency law drives change in job postings across U.S.
- New York pay transparency law drives change in job postings across U.S.
- Jamie Foxx reps say actor was hit in face by a glass at birthday dinner, needed stitches
- Parents, are you overindulging your kid? This 4-question test can help you find out
- Project Veritas, founded by James O'Keefe, is laying off workers and pausing fundraising
- U.N. General Assembly opens with world in crisis — but only 1 of the 5 key world powers attending
- Federal court filings allege official committed perjury in lawsuit tied to Louisiana grain terminal
- The world hopes to enact a pandemic treaty by May 2024. Will it succeed or flail?
Ranking
- Tarte Shape Tape Concealer Sells Once Every 4 Seconds: Get 50% Off Before It's Gone
- Astronaut Frank Rubio marks 1 year in space after breaking US mission record
- Biden says Norfolk Southern must be held accountable for Ohio derailment but won’t declare disaster
- The Era of Climate Migration Is Here, Leaders of Vulnerable Nations Say
- Could Bill Belichick, Robert Kraft reunite? Maybe in Pro Football Hall of Fame's 2026 class
- Some Fortnite players (and parents) can claim refunds after $245M settlement: How to apply
- 'The Continental from the World of John Wick' review: 1970s prequel is a killer misfire
- Tory Lanez begins 10-year prison sentence for shooting Megan Thee Stallion
Recommendation
South Korean president's party divided over defiant martial law speech
Rupert Murdoch, creator of Fox News, stepping down as head of News Corp. and Fox Corp.
Kapalua to host PGA Tour opener in January, 5 months after deadly wildfires on Maui
`Mama can still play': Julie Ertz leaves USWNT on her terms, leaves lasting impact on game
Realtor group picks top 10 housing hot spots for 2025: Did your city make the list?
Elon Musk's Neuralink chip is ready to embark on its first clinical trial. Here's how to sign up.
Pregnant Kourtney Kardashian and Miranda Kerr Look Inseparable While Baring Their Baby Bumps
Greek civil servants have stopped work in a 24-hour strike that is disrupting public transport