[ad_1]
JOLIET, Ill. (CBS) – All of a Joliet man’s Bitcoin went poof, gone, disappeared, after a hacker broke into his accounts and emptied the cryptocurrency.
It all happened because the fraudster hijacked his phone number.
READ MORE: Unionized Cook County Health workers strike over wages and health benefits on Friday
CBS 2 morning insider Tim McNicholas demanded an explanation from the man’s supplier.
Cryptocurrency can be a bet. But it was a hand that Phil Michno really didn’t expect.
“I’ve always heard this stuff happen,” Michno said. “And of course you think. “Ah, it doesn’t – it’s going to happen to someone else. “
At the end of May, Phil noticed that his phone was not working. So he used another phone to call his provider, Boost Mobile.
“They tell me that, oh, we see you’ve been transferred to T-Mobile,” Michno said.
It was news for him. But then came another surprise – he couldn’t access his account with a cryptocurrency exchange called Coinbase.
The company would later tell him in an email, “The attackers were able to access your account via sim swap and steal his 3 bitcoins.
By the way, 3 bitcoin is worth over $ 100,000.
“Almost all of my friends and acquaintances say it couldn’t be done,” Michno said.
Not only can it be done, it has happened to dozens of other people in the exact same way. It turns out that a scammer somehow has enough personal information about Michno to convince Boost to change his phone number.
This allowed the villain even more information, like the security access codes used to log into banks – or in this case, a cryptocurrency exchange.
Other victims have inundated Reddit with their complaints and even sued Coinbase, but the company insists the breach is never over.
This leads Michno to his next question: “Why did boost mobile give out my phone number without my permission?” “
We asked Boost about this. They sent out a statement saying that “port out” scams are rare among their customers, but are an industry-wide problem and are taking action to prevent them.
“I’m happy to see that they are aware of this,” Michno said, “but they have to fix the problem.”
Michno said they should pay him back as well. But the company told us it was “not responsible” because the “fraud involves the hacking of a separate account, not affiliated with Boost.”
As for Michno, he replied: “This has been compromised due to the incompetence of the boost.”
He is considering settling the problem in court.
READ MORE: Chicago parking meters sued in Federal Court over alleged monopoly contract
Michno reported this to Joliet police and federal authorities, but unfortunately digital currency theft is often difficult to trace.
Here’s the full statement Boost sent us for this story:
“At Boost, ensuring the security of our customers’ data and personal information is a top priority. While Port-Out scams involving Boost customers are rare, our goal is to prevent them from happening. We know this has been very frustrating for Mr. Michno, and our team is committed to investigating this issue and finding out how the fraud happened.
“We are continually evaluating and improving our processes to prevent scams from happening. Recently, Boost implemented several procedures within our customer service operations to prevent fraudsters from tampering with the system. We thank Mr Michno for drawing our attention to this point and for sharing his experience with us. These “Port-Out” scams are an industry-wide problem and no operator is immune. We encourage all mobile users, whether they are Boost customers or one of our competitors, to learn how they can prevent these scams from affecting them. Our goal remains to offer an exceptional experience to our customers.
“Also, I wanted to share this FCC resource regarding these Port-Out scams. It’s a useful tool for explaining to consumers how it’s done and what customers can do to protect their information.
We had a few follow-up questions for Boost. Here are the questions and answers:
“You mention that Boost” has put in place several procedures … to prevent fraudsters from tampering with the system. Can you please explain what specific changes have been made to increase security? “
“These changes include an increase in the information we need from a customer if they need to make any changes to their account, including whether they want to request or reset their PIN.”
“You also say that you ‘appreciate Mr. Michno for bringing this to our attention.’ Did you know this kind of fraud happened before his case and why was his issue not investigated when he initially contacted Boost? “
“Boost is vigilant against fraud and strives to protect our customers while ensuring that they can legally access their account information when needed. Boost investigated this case and discovered that it was port-out fraud. More information on this type of fraud is available through the FCC.
“Is Boost responsible for the money that was stolen from his financial accounts because of this fraud?” “
“No, Boost is not responsible for any money that has been stolen from its financial accounts as financial fraud involves hacking into a separate non-Boost-affiliated account. Our customer service team encouraged the customer to continue to seek the return of their cryptocurrency through channels with proper oversight. Although Boost does not have control over a user’s Coinbase account, customers can find more information on securing their accounts through the site Coinbase Web, Available here.
T-Mobile also sent us a statement:
“Takeover account fraud is an industry-wide problem. These are criminal attacks on wireless clients and it is in everyone’s best interests to stop them. We can’t talk about the process of other companies, but each network has its own requirements for validating interoperator porting requests. When T-Mobile receives a complaint from an operator that a number has been transferred to our network without the customer’s permission, we work with that operator to resend the number.
“T-Mobile offers our customers a variety of options, including PIN codes, to help them protect their own information. T-Mobile accounts must have a 6 to 15 digit PIN code, and a T-Mobile number cannot be transferred without verification of this PIN code. We encourage customers to contact us to discuss the security measures available to them. If a customer feels their account has been changed against their will, they should contact us immediately and we will work directly with them to fix it.
Coinbase sent us this statement:
“Coinbase recognizes that compromising your personal information can lead to terrible crimes with significant impact on consumers. With more and more of our personal information available online, it is increasingly important for consumers to understand how to protect their personal email accounts and cell phones from unauthorized third parties. Once a third party accesses a consumer’s email or phone address, that consumer’s other online accounts may also be at risk. This is why Coinbase regularly strives to educate our customers on how to protect their personal email accounts and phones. This is the most important thing they can do to prevent unauthorized access to all of their online accounts, not just Coinbase. When a customer contacts us to report a potential breach of their account, we lock their account as soon as possible, so that no further unauthorized activity can take place.
“Coinbase is thoroughly investigating all incidents of unauthorized access to a Coinbase account, including Mr. Michno’s account. We are unable to provide specific details on the activity of Mr. Michno’s case. , due to customer privacy, but we can confirm that there has been no violation of the Coinbase platform or improper employee action.
MORE NEWS: City Council will meet again on Friday with Lake Shore Drive renaming on the agenda
“With increased interest in the crypto space, we are seeing an influx of support requests. We realize that many of our customers experience delays in our customer service response time, and we recognize that this is not the experience we want for our customers. Earlier this year, we shared the steps we have taken to support an increased volume of customer support requests, including the exponential increase in our support staff, improved self-service within the product itself and the creation of additional support channels such as live messaging.
[ad_2]
picture credit