Identity Thieves Hijack Cellphone Accounts to Go After Virtual Currency
nytimes.com
nytimes.com
I got hacked a week ago in this exact fashion (I haven't tried to keep it a secret that I was involved in Bitcoin earlyish-on). I don't think they were able to get anything (largely because I am mostly out of the crypto space) but please remove cellphone 2FA from all your online dealings and add something like Google Authenticator instead (don't forget to print out, or at least encrypt a PDF of, the backup codes!)
My mistake was LEAVING cellphone 2FA in there on my main Google account even after I had activated Google Authenticator.
That was a mistake, because you can actually remove cellphone 2FA after adding GA 2FA. Which you should do!
My 2nd mistake was using a dumb PIN on my cellphone account.
The cellphone companies could prevent this attack entirely by requiring in-person (with ID) transfers of cellphone numbers to new hardware, at the store. Given the infrequency that I would have to do that, the extra inconvenience is acceptable.
After getting hacked and trying to move most of my online affairs to another account still under my control, I noticed that Facebook has a "name 5 trusted friends" feature which helps you regain access to an account after it's compromised, which might be useful to others... only issue being that once my private messaging and files are discovered (google drive :( ), the damage is already done.
The same password recovery vulnurability was present on Facebook for some time as well
Fake IDs are cheap. This would not prevent a motivated attacker.
I use an electrum wallet on my desktop, and use one of the addresses in that multi address hd wallet as my hot wallet. I load that address on my android electrum install. That way if i ever lose my phone, there isn't much on it, and i can always move the funds using my desktop wallet if required.
But it does suck that it happened. Sorry to hear it.
https://blog.kraken.com/post/219/security-advisory-mobile-ph...
The simple fact is that I don't own my mobile number; the mobile operator does. As such I should not use it as 2fa.
https://blog.kraken.com/post/219/security-advisory-mobile-ph...
Of course the real fix would be to have better trained people working at the call centers.
Cell phone account security issues are among my top personal "getting hacked" fears.
I lucked into some compelling evidence I'd like to share with any security experts that would be able to help me.
It would be nice to have a similar system for all kind of 2FA solutions involving cell phones.
Ah, I see.