Does not naming the company suggest that it's not considered liable?
> indicate five victims
Over what time period? Did the company detect and halt this quickly, and was conscientious about referring it to law enforcement?
I'm willing to agree a store/carrier/brand should be given a pass in a particular instance, but the bar for protecting against SIM-swapping has to be pretty high, considering what an attractive vulnerability that is.
With poor technology and poor regulation around some big-ticket authentication problems right now, one mechanism we do have is brand reputation.
For example, if people seem to keep hearing about SIM swaps involving carrier X or store Y, then some people are going to start thinking that brand is sketchy, and more likely to get your bank account emptied or computer accounts hacked. So then all the brands would have more incentive to be very diligent about internal controls, very cautious about partners and outsourcing, etc.
But if it's always just an unnamed phone store SIM-swapping for an unnamed carrier, or an unnamed carrier's support call center, then that brand reputation mechanism is defeated.