There is an insightful tweet [1] in Spanish that is translated as follows:
""" Well guys, the payoneer mystery is solved.
#PayoneerHacked
- The attacker compromised the gatway SMS used to send the 2fa to Movistar customers (the platforms use this to sneak the cost) - The attacker saw 2fa messages passing from Payonerr to a Movistar phone number but had the problem of not knowing the email of the Payoneer user to change the password and make the transactions. - The attacker, to discover what email was behind each phone, set up a phishing site to try to take ONLY THE EMAIL from there and with the email + the phone + the 2fa that accessed the compromised SMS gateway in real time, he was able to change the password, access the account and send money since I kept reading the 2fa that arrived on the Movistar phones. - That's why the victims saw several real SMS with 2fa coming during the night that emptied their account. - Even if Payoneer customers had fallen for phishing, they would only have had one 2fa stolen, and not all that is needed to log in, add an account and transfer. This need makes it evident that the commitment to the SMS gateway existed.
- The victims of this scam lost their money because the last mile of the security stack was compromised.
Be careful, because Facebook, Twitter and others share the same gateways to save money on SMS.
Here I leave a screenshot of the SMS that arrived during the early hours of the morning to a victim and that the victim was never able to share in any phishing and that were necessary to empty them.
(whatever you read in the media... fruit, lots of salad and little sauce. here's the post)
Thanks to everyone who cooperated. """
[1] https://twitter.com/julitolopez/status/1748440685743587811