3 ms·
Google will not share how threat actors are pulling it off but it definitely is happening. (see the Terpin v. AT&T lawsuit for why they might not be disclosing
by buildbuildbuild 3y ago
Google will not share how threat actors are pulling it off but it definitely is happening. (see the Terpin v. AT&T lawsuit for why they might not be disclosing the vector)
There are "fingerprint" cookie marketplaces that sell tokens from malware-compromised computers and allow you to make HTTP requests from a victim's connection, this could be one approach. There are also scammer call centers that will call unsuspecting people pretending to be Google, Coinbase, AT&T, or whomever, and have them click buttons in user interfaces.
I've seen entire Google accounts deleted with no recourse due to this "suspicious activity" that victims had no control over. Computer says no, and it's near-impossible to get in touch with a human at Google.
(I agree with you on terminology but media reports tend to group number porting attacks in with "SIM swaps")
- Obscurity4340 3y agoIs there a reason that would-be hackers are not preempted by requiring a specific device, pins, etc with no kill-switch or social engineering available (like, you lose your credentials, there's nothing we can do, its gone)? It sometimes feels like the system is deliberately designed so certain "legitimate" actors have a backdoor into any given system...