SIM-Swapping Becoming a "Big Problem'

By Ray Birch

CHICAGO—Amid all the other fraud threats credit unions must defend against, there is another  growing tactic that needs attention, according to one cyber security expert.

Eder Ribeiro, senior cybersecurity program manager at TransUnion, told CUToday.info fraudsters are transferring victims' phone numbers to their own devices via a tactic called SIM-swapping. And he says it’s a “big problem.”

Armed with a stolen SIM, crooks can intercept one-time passcodes (OTPs), which is critical, since  OTP authentication is now used during 70% of new financial services account openings, he said.

thumbnail_Feature SIM Swap

“When a bad actor has your phone number, they can bypass two-factor authentication and access your bank accounts or open new ones in your name,” Ribeiro said. “There's a lot for credit unions to be worried about. From insider threats to all the classic cyber threats that we see every single day. The ransomware attacks. The business e-mail compromises. And now, SIM swapping.”

SIM swapping is a threat not not limited to financial services, Ribeiro explained.

“The reality is basically every phone over the last few years now uses a digital SIM instead of an old-school SIM card,” he said. “Before, at least, when you had a physical SIM car you could still be subjected to a swap attack, but it was more difficult.”

But no more. Ribeiro pointed out that phone SIMs now are all electronic, digitally stored on the phone.

“If you buy a new iPhone there's no actual little card in there, it's just a number issued to you by your phone provider,” he said.

A New Channel

SIM swapping is becoming more popular because it provides crooks with a new channel to begin the process of assuming someone’s identity, Ribeiro said.

Eder Ribeiro

Eder Ribeiro

“It allows a threat actor to start attempting to log in as you, choose your apps, websites…wherever it is that you may be wanting to log in,” Ribeiro said. “It can be as nefarious as your bank account, or benign as your Netflix account.”

Ribeiro emphasized there is a real threat to consumers’ financial accounts from SIM swapping.

“People are using their phones as their main device to access the Internet for everything, whether it's banking, whether it's working documents, and moreso over the recent years when people began working more from home,” he said.

How It Works

How are the crooks stealing the digital SIMs?

“There's quite a few ways, and, unfortunately, there is not just one way that it is done. SIM swaps can be the outcome of a bunch of different attack vectors,” Ribeiro said. “One of the most common examples would be phishing attacks. Everyone gets malicious text messages all the time. Whether it's somebody acting like they know you—‘Hey, here's an order number. Thanks for your recent order.’ But it doesn't say where it's coming from and it always includes a link. People need to stop clicking on links, because those links can bring you to a fraudulent website that often looks like a legitimate website.”

Ribeiro said the phishing link typically brings someone to a location that already has some sort of credential harvester or information theft software embedded.

“When they start to interact with that environment it's collecting cookies from their device, it's collecting metadata from their device, which can be used to escalate privileges,” he said. “Now, the fake site might also ask them to enter credentials. As you go through that process, your device is communicating with that entity, and part of the metadata that they're catching is device information, which can include SIM number and system information.”

Ribeiro stressed that credit unions should understand this threat is increasing.

“There's a few things that can be done,” he said. “As I mentioned, the number one way this tends to happen is via some sort of social engineering. Anytime we're talking about social engineering—phishing, smishing, whatever—those things mean targeting a human. You're not targeting a vulnerability in the operating system. You're not targeting some vulnerability in how data is being transferred. You're targeting a person.”

When you're targeting an individual there's only two ways to attempt to mitigate the threat, Ribeiro said.

“One, you make people less susceptible, which is usually going to come via some sort of training. Educate them on what these attacks are, what they do, what they look like, how to spot them,” Ribeiro said. “And, for those who fall victim to an attack, foster a culture where coming clean, for lack of a better term, is clearly seen as the right thing to do. It's not something that's going to result in some penalty. A lot of people get nervous about coming clean because they clicked on a link or something. They're afraid of consequences.”

Protocalls in Place

Ribeiro also advised CUs to ensure new protocols are in place, like having multi-factor authentication.

“I say this, for literally every account—from Facebook to banking—if multi-factor authentication is available, you should be using it,” he said.

In addition to being able to intercept OTPs and harm consumers, when criminals steal SIMs from employees’ phones they may begin executing attacks on the credit union’s network, such as installing ransomware.

“If it's a company-issued device, then that's a company asset that is now potentially compromised. If it's a personal device, does that person do any work from home that is now potentially compromised because that person is using that device?” Ribeiro asked. “Through the SIM swap the threat actor now has eyesight into a person’s Internet use and the credentials they are pushing out of their device. Depending on how malicious and how sophisticated the threat actor is, a SIM swap is a first step in landing malware in the device.”

Bring Your Threat to Work Day

If employees do any work related to the credit union on compromised devices, that's a problem, added Ribeiro.

“And if the malware is entrenched in that device that's also an overall network problem for the credit union,” he said. “Because if your phone is compromised and now you go to work and you hook up to the work Wi-Fi, now you're creating a possibility where the threat actor might be able to jump and move laterally from your device to another node or another device on the network. That gives threat actors that first step within the network. Once they step into your network, they now have the credentials to escalate their privileges to become more nefarious.”

Ribeiro noted there are tools, such as TransUnion’s power Scam Blocker, that protect devices from reaching unsafe and dangerous sites.

Section: Standard
Word Count: 1360
Copyright Holder: CUToday.info
Copyright Year: 2026
Is Based On:
URL: https://cuto.flux5.ccplatform.net/THE-feature/SIM-Swapping-Becoming-a-Big-Problem