“Sim Swapping”: the spoofing of your cell phone number that puts your bank accounts and other data at risk



[ad_1]

In the face of the coronavirus pandemic, hundreds of procedures that could be carried out directly in offices are being carried out through the Internet. Directly from your cell phone. For this reason, cybersecurity has become even more relevant. The concern goes beyond a simple virus: scams and theft can result.

In this context, the Undersecretaries of Telecommunications, Pamela Gidi, and of Crime Prevention, Katherine Martorell, unveiled a little-known phenomenon: “Sim Swapping”. As they warned, there would be an increase in this type of crime in our country. The crime is related to your cell phone sim card.

What is “Sim Swapping”?

The authorities explained that the crime consists of impersonating the owner of a telecommunications account. Thus, they access the user’s number and also carry out bank scams. It is a crime that uses “social engineering”.

sim Getty

“What happens is that unscrupulous people make a sociodemographic profile of people. Then they go to the phone company and say they lost the simcard. So the company provides them with a new one. They install it on a different device and download applications from banks and retail houses, abusing their accounts, ”explained the undersecretary, Pamela Gidi.

According to the authorities, the criminals hire new telephone lines and buy high-end equipment charging the cost to the telephone bill.

Measures taken to stop the phenomenon

Faced with this situation, the undersecretaries indicated that all telecommunications companies were instructed to report on their security protocols. This, to avoid this mode of identity theft.

Gidi added that “it is very important that operators take all the safeguards to protect and verify the identity of the user and make sure that all the procedures requested by the client are identified.” Purchases made by the user must also have protocols that ensure your fidelity.

pdi Twitter POI

On the other hand, the Undersecretary for Crime Prevention, Katherine Martorell, said that work began in a joint table with the PDI to address this modus operandi. The national chief of the PDI’s Economic Crimes Investigative Brigade, Jaime Ansieta, called on the public to report these events. “Without complaints it is very difficult to set up causes,” he said. “Therefore, we need people, regardless of whether the account is restored to them, report them, “he said.

The details after the attack

According to Carolina Ortúzar, a computer engineer specialized in cybersecurity, “this phenomenon is accompanied by social engineering techniques.” “Since what criminals are looking for is to access the verification codes that companies and other entities usually send us to our mobile devices”, adds.

“Once the credentials are obtained, the criminals try to clone the victim’s SIM,” he explained. This, in order to receive verification codes by SMS (double authentication factor). “For that, cybercriminals take advantage of the few identity verification measures that some operators usually request,” he details. The phenomenon has been addressed by cybersecurity companies such as Eset in Europe.

sim Getty

Among the recommendations, some point to the user such as: not answering messages or emails of dubious origin with personal data (or the email signature that sometimes has that data). But above all, they aim for telecommunications companies to improve their user identification system. This, to request new SIMs or contract services.

And what do the telecommunications companies say?

The authorities noted that the security measures of the telephone companies are key. Along these lines, from Movistar Chile they indicated to Publimetro that since 1017 they have requested a simple power of attorney authorized before a notary.

Since 2018, they have reformed “authorizing this operation only to the holders who attended our branches in person”. That same year, they also included the use of a one-man web code. It is a mandatory requirement to perform a SIM Card replacement.

On the other hand, from Entel they point out that they are continuously “implementing improvements in our processes to strengthen security and service quality”. “Advancing in a digital culture plan is the best way to work together to mitigate risks, as is the case with sim swapping,” they state.



[ad_2]