A hacker ripped me off. The scam turned out to be brilliant and terrifying
businessinsider.com
businessinsider.com
Well, if that was the key convincer to get the investigation moving, it's good job widespread voice impersonation isn't in the offing or anything.
This sounds reasonable enough, except they never actually verified the phone was lost, stolen or destroyed.
But how could they do that? At first I was thinking they could send a text to the phone number, and if you respond within 7 days, they will assume it's not stolen. But the problem with that is if the phone was stolen, then they would be letting the thief continue to use it, which ends up almost like the opposite scam (stealing the phone itself).
I'm not sure there are any great solutions to this, unless you're okay with opting into an extra-security category where you really are screwed if you actually lose your phone.
For traveling overseas I needed a different SIM card and bought one at a local store (to be repaid by my carrier). The clerk at the store did not need my password because I showed him my valid identification. Password was useless in this case.
Not counting fake IDs that get past clerks, a few years ago Krebs On Security noted that the normal bribe at a phone kiosk was $85 to do the SIM swap illegally.
There's a big gap between the high trust and low salary that companies give their frontline employees. And despite (or because of) that gap, they're not motivated to do extensive background checks.
But the average employee at the Verizon kiosk in the local mall is arguably handling more sensitive data than an employee at the passport office in the State Department.
https://www.usps.com/manage/informed-delivery.htm
The initial problem was that her mail got stolen by the mail person. USPS Informed Delivery would have told showed her the letter that she should have gotten since it came to the processing center nearest her local post office.
Informed Delivery also shows you tax mail (like W2s) that get mailed and are commonly stolen with informed delivery you know when they are mailed to you.
>But there was one last twist to the mystery. Sue Brennan, a spokesperson for the Postal Service, explained that my credit card was scanned at the processing center nearest to my local post office. Which means that the thieves stole it in New York City on July 16 and took it all the way back to Ohio in time for its big day of spending at the mall on July 22.
>Two months after my hack, on September 29, federal prosecutors in New York announced that they had busted up a scheme that sounded familiar. Three postal workers were charged with stealing credit cards out of the mail and passing them on to five "shoppers," who used them to buy luxury clothes and bags at stores like Chanel and Hermès that they could resell online.
Google also has notoriously nonexistent customer service. It does not instill confidence that anyone should rely on them for something as critical as identity management. The threat of them fucking you over when you need their help far outweighs the threat of hackers and scammers.
(Virtual money was supposed to be more secure than physical coin. That experiment didn't work so well either.)
Google Fi’s implementation of verification also seems more robust and secure: https://support.google.com/fi/answer/9834243?hl=en
I just never use any service that forces 2FA by SMS. If it not avoidable for some reason, I make this account completely isolated from the rest of my online identity (new email just for it, regularly change password).
If your bank/financial institution forces 2FA by SMS, it is time to change, most of the serious ones have their own app that handles 2FA. I'm yet to find one that allows to use your own OTP generators, so I'm usually forced to use their app for now.
They swapped the sim to get access to credit card fraud alerts, delivered via SMS.
I've experienced better banking apps which did use SMS at the initialization, but coupled it with other identifying factors (eg the phone IMEI or a code sent through postal services). If these app needed to be reinstalled the whole verification process would have to be redone.
1) HOW did the hackers get their mobile phone number once they had their card? Was it a dark web purchase based upon their name and address? A mailed CC should just have name and address, no email/phone number should be included in that physical mailing.
2) What are pros/cons of using a virtual phone number like Google Voice or Ooma for these type of financial services? Would that be an improvement? Though I know some do not support non-mobile carrier like GV.
What I'm curious about is how the scammer knew that the author was a Verizon subscriber and not a subscriber with ATT or T-Mobile or one of the dozen or so MVNOs.