4 ms·
A year ago I was simjacked by someone who walked up to a T-Mobile kiosk in San Diego and acquired my phone number by simply claiming they were me. This bypasse
by kentbrew 5y ago
A year ago I was simjacked by someone who walked up to a T-Mobile kiosk in San Diego and acquired my phone number by simply claiming they were me. This bypasses every possible layer of protection you can set up with T-Mobile; an actual human employee just went ahead and gave my SIM away.
Fortunately my wife is primary on the account and is very much on the ball. She got texts that the SIM card had been changed and within minutes had them recover it and lock it back down. Besides "ditch T-Mobile," this might be the best piece of advice: don't be your own primary, and be sure your primary has your SIM card on extra-paranoid notify-me-instantly-if-it-changes mode.
Fortunately the first thing they were after was my Coinbase account, which they two-factored only to discover was empty. If they'd hung around a while and poked around I would have been well and truly pwned. So, second piece of advice, already said upstream: do whatever you can to avoid giving online services your phone number.
When I finally got in front of a support rep they confirmed the whole thing and (just because I was there, and large, and extremely pissed off) let me take as many photos as I wanted of the entire incident report right there on their kiosk. This by itself did not fill me with a strong sense of confidence in their opsec; third piece of advice is: anybody but T-Mobile.
- benrapscallion 5y agoWow, that is insane. And your advice is much valued! Thank you for sharing.