Sim Card Frauds - LC must escalate this

Read about how sim card frauds are happening. LC must escalate the need for a SIM password and email validation for sim card reassignment by operators.

This is how sim card frauds are taking place:

Hackers hijack SIM connections in three ways. The most prevalent one is called “SIM swapping over a call". In this case, they first gather information on targets—their full name, address, mobile number, date of birth, passcode or Aadhaar number — through phishing scams or leaked databases found on the dark web (that portion of the web that is not traceable by search engines).
Then they will call the target, pretending to be a customer care executive from the operator, in the name of upgrading to new services. They will ask the target to share their SIM card’s ICCID (integrated circuit card identifier) number—a 19-20 digit serial number specific to the SIM.

Once they have the details, they will call the operator, impersonating the actual user and use this information to pose as the user.
Once the SIM swap request is initiated, the operator sends an SMS for authentication and users have to acknowledge it by tapping a single key or a bunch. The hacker will tell users in advance about this SMS so the latter easily falls for it.
Once the SIM swap is complete, the original SIM will be deactivated and the number will be active on the duplicate SIM owned by the hacker.

The second method is “SIM swapping in person" and is likely to be used by small-time cybercriminals. In this case an impostor will visit an operator’s retail outlet with fake documents pretending to be the actual customer and try to get a duplicate SIM card issued.
Another way to take control over a person’s mobile number is through SIM cloning, but that requires the hacker to have physical access to the SIM card to break the encryption keys and extract the IMSI (international mobile subscriber identity) number—a unique 15 digit code that identifies the SIM to the GSM (global system for mobile communications) network. Unlike SIM swapping, in this case both the original SIM and cloned SIM remain active simultaneously.

SIM hijacking has recently become particularly popular because mobile numbers are being used by various applications, including popular social media platforms, as an identifier, and to enable account recovery and second factor of authentication via SMS confirmation. Therefore an attacker who successfully swaps the SIM card is able to take over an account that uses that phone number as an identifier and as an SMS recipient for the second factor of authentication. more  

View all 10 comments Below 10 comments
Thanks for the Infos. more  
Wonder as to how did you know of these techniques used by criminals? Have you got any personal experience or are these mere assumptions shared to scare readers? more  
Very useful more  
ICICI Lombard not honouring Claim even after premium for five years. Be careful. more  
Mobile design need to add buttons for inserting/ releasing sim and clear Memory. more  
Post a Comment

Related Posts

    • WEWELLCOM PATANJALI AYURVED's ACTION

      The Brompton cocktail, sometimes called Brompton mixture and most popularly known as Brompton cough mixture, was originally developed at a hospital specializing in chest diseases. This cough mixtur...

      By Jayakumar Daniel
      /
    • Milk price increase - Karnataka

      Basic milk price has been increased by ₹4 per litre in Karnataka. The govt says that it is not an increase. They have added another 50ml to the pouch and that this increase is for the addl volume. ...

      By Padmanabhan G
      /
    • What is wrong with Amazon Fresh service

      They are showing random MRPs just to show big discounts. No where in India tomato has MRP of 261/kg and look at these people. Please escalate this to consumer affairs department and essential commo...

      By Radha Puri
      /
    • Listerine mouthwash linked to cancer

      Is Listerine Mouth Wash Linked to Cancer? In another shocking news, scientists have found that the daily use of Listerine Cool Mint Mouthwash may be linked to an increased risk of colore...

      By Sneha Goyal
      /
    • New insurance renewal scam

      My health insurance policy is due for renewal and yesterday and i received a call from someone who claimed to be from ICICILombard . The agent confirmed my details and also my policy details which ...

      By Sanjit Jha
      /
    • Cigarette selling is permissible?

      If you go to cinema hall you will find lots of ads mentioning " smoking is injurious to health"... when govt. is displaying such ads., how they are allowing sell in the market...isn't contradictory...

      By SANDIP KUMAR BHADRA
      /
    • Is selling cigarettes online permissible

      See attached this Blinkit is selling cigarettes online. Is there an age check. What if young 15 year olds are ordering and consuming them. If amazon flipkart big basket dont sell such pr...

      By Amit Mishra
      /
    • Beware of calls from telecome dept

      Got a call from ‘Telecom Department’ that all phone numbers under my name will be blocked in 2 hours. And to press 9. Looks like a new scam

      By Sarita S
      /
    • Misleading by water purification cos

      Water Purifier industry is almost a semi scam Mis-selling, fear mongering by both trade and brands. And looting in the name of service Aquaguard, Kent, Pureit are all the sam...

      By Shivani Khiste
      /
    • gst on mediclaim

      abolition of gst on mediclaim is a long standing demand.for some reason if the govt.is unable to abolish the same they can reduce the rate,alternatively exempt the policies of senior citizens from ...

      By Suresh Dasarathy
      /
    • GST on health insurance policies

      Govt shows great effort to help sr citizens by listing in ayush maan bharat. PM talks of jan seva shops for cheaper medicines. Then why 18%GST is being levied on mediclaim installments.

      By Satyapal Singh
      /
Share
Enter your email and mobile number and we will send you the instructions

Note - The email can sometime gets delivered to the spam folder, so the instruction will be send to your mobile as well

All My Circles
Invite to
(Maximum 500 email ids allowed.)