Hackers Circle As Individual Investors Pour Money Into Crypto

[ad_1]

Rosa Maguina invested a large chunk of her savings in cryptocurrency earlier this year, joining other individual investors trying to strike while bitcoin was hot. The funds disappeared after a hacker hijacked his phone number for just two hours.

Ms Maguina, who runs an event logistics business with her husband in Doral, Fla., Said she was about to fall asleep on July 5 when she noticed her phone had lost its signal. By the time Ms Maguinas’ service was restored, she said, an unauthorized user had changed their passwords for the Binance and Coinbase trading platforms and initiated transactions that emptied their crypto accounts of worth about $ 80,000 at the time.

It was as if someone was walking in through the window or the back door of your house, Ms. Maguina said. You feel like there is nothing you can do.

Criminals have a habit of stealing money from wealthy or well-known crypto investors through SIM card exchanges, or passing a phone number from one subscriber identity module to another. . But the crypto boom among family investors has led hackers to increasingly surround targets like Ms Maguina, according to cybersecurity experts, lawyers and law enforcement officials.

Newsletter Sign-Up

WSJ Pro Cybersecurity

Cyber ​​security news, analysis and insight from the WSJ’s global team of journalists and editors.

Attacks on small investors have sparked legal battles with mobile carriers, led customers to change their plans and prompted some carriers to change security measures. Law enforcement agencies are trying to team up in all jurisdictions in response to a growing number of potential victims. The Federal Communications Commission is fine-tuning rules for wireless carriers to limit SIM swap fraud, proposing more stringent restrictions on how they change numbers between devices and carriers.

Some cell phone companies say federal rules could make things worse for consumers.

AT&T Inc. said on Monday that the agency’s proposed regulations could give hackers a plan of attack and add friction for legitimate customers who need to switch devices or carriers. AT&T said customers make hundreds of thousands of such requests per month. A fraction of 1% of them, potentially totaling thousands, are fraudulent, the company said.

Carriers must be nimble and innovative in the fight against fraud and must not be anchored in prescriptive requirements related to specific technologies or methods, AT&T said.

The company has warned of some measures initiated by the FCC, such as notifying phone users of SIM swap requests and potential 24-hour delays in executing them.

Customers perform SIM card swaps when they transfer their numbers to new phones, while the related act of transferring the numbers to different carriers. Hackers can impersonate phone users with various types of account information or personal data, said Kevin Lee, lead author of a 2020 Princeton University study on SIM card exchanges.

The process can’t take more than 10 minutes, with the exception of the customer’s music on hold and stuff like that, said Lee, whose team was able to leverage the permissions metrics for prepaid plans offered by AT&T, T-Mobile US Inc. and Verizon Communications. Inc. Mr. Lee said most business customers, which dominate the domestic wireless market, have postpaid plans that may have different security measures.

AT&T told the FCC it uses data analysis tools to assess the risk of postpaid customer SIM swap requests. A spokesperson for Verizon said postpaid customers must use a one-time passcode when attempting to switch to another carrier. T-Mobile allows customers requesting SIM swaps over the phone to use their account PIN, one-time password or two-factor authentication, a representative said. The company stopped using logs showing recent inbound or outbound numbers in its authentication process following the Princeton study.

US Mobile, a new York-based operator with around 150,000 customers, has banned SIM card exchanges over the phone and directs customers to its app, where it can verify their Internet Protocol addresses and biometric data, the director said. General Ahmed Khattak.

Many of these hacks happen because of social engineering, he added, referring to hackers cheating or co-opting wireless employees.

Criminals use hacked phone numbers to gain access to victims’ financial accounts or social networks, often fooling multi-factor authentication measures based on text messages. A Briton in 2019 allegedly stole $ 784,000 from a crypto-infrastructure firm in New York using a SIM swap, according to an indictment unsealed this month. The man allegedly took an executive’s phone number, accessed internal computer systems and transferred funds from a client’s digital wallet.

Ahmed Khattak, CEO and Founder of US Mobile. Photo: American mobile

The apparent shift from hackers to individual investors added a layer of complexity to the investigations that followed, said David Berry, agent of the React Task Force, a Bay Area investigative group focused on cybercrime.

If you come to [prosecutors] with a loss of a million dollars, you will get their attention, he said. If you come up with them with a loss of $ 10,000 or $ 20,000, you might not do it.

However, such losses can be huge for investors like Richard Harris, an independent entrepreneur in Philadelphia.

It was like someone had taken my 401 (k) or social security, he said.

Mr Harris sued T-Mobile in July, alleging that the company’s practices did not meet federal standards and allowed a hacker to take back his phone number in 2020 and steal bitcoin worth almost $ 15,000 back then, and more now.

T-Mobile declined to comment on the lawsuit, but offered to submit the case to arbitration. Like Verizon and AT&T, the company needs arbitration to resolve disputes over its terms of service, often leading to settlements behind closed doors.

“If you come to [prosecutors] with a loss of $ 1 million, you will get their attention. If you come up with them with a loss of $ 10,000 or $ 20,000, you might not do it. ”

David Berry, agent of React Task Force, an investigative group specializing in cybercrime

Amid growing complaints, the FCC in September proposed regulations requiring wireless companies to verify user passwords or send one-time passcodes. The rules would also require companies to tighten procedures for changing lost or stolen passwords and restrict what data employees could disclose over the phone or in stores.

An FCC official, who warns that consumer data breaches can provide fraudsters with the information they need for SIM card trades, said rules could take several months to develop.

Wireless industry trade group CTIA called for flexibility in regulation and urged financial institutions and social media companies to similarly strengthen the way they verify users.

Coinbase, the largest U.S.-based cryptocurrency exchange, uses machine learning models to predict risks for users requesting password changes, restricting transactions on suspicious accounts, said a responsible for the company. Real-time SIM card exchange data from operators would help Coinbases’ filtering process, the official added, but not all providers share information quickly. He refused to name them.

The official said the Coinbases account takeover rate has remained constant as the platform has gained users, refusing to provide detailed numbers. Binance, the world’s largest crypto exchange, did not respond to a request for comment.

Since Ms Maguinas’ phone number was taken over on July 5, the price of bitcoin has climbed more than 70% to around $ 59,000 a coin on Saturday.

I’m not anymore, the 53-year-old said. I don’t need to do any worse than it is.

Write to David Uberti at [email protected]

Copyright 2021 Dow Jones & Company, Inc. All rights reserved. 87990cbe856818d5eddac44c7b1cdeb8

Sources

1/ https://Google.com/

2/ https://www.wsj.com/articles/hackers-circle-as-individual-investors-pour-cash-into-crypto-11637499603

The mention sources can contact us to remove/changing this article

[ad_2]

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts