When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover
Real-world SIM swap attack exploits social engineering and SMS OTP weaknesses in carrier authentication.
Summary
A security professional experienced a coordinated SIM swap attack combining social engineering, identity impersonation, and stolen personal data to compromise a wireless services account. The attacker successfully obtained authentication codes and account credentials through manipulative customer service interactions but was ultimately detected when attempting concurrent session access. The incident highlights critical gaps in continuous identity verification, over-reliance on SMS-based authentication, and the need for phishing-resistant alternatives like FIDO2 and passkeys.
Full text
For years, organizations have encouraged users to enable multi-factor authentication (MFA), use one-time passwords (OTPs), and protect their accounts with passcodes. Those controls remain important. However, a recent attack against my own wireless services account demonstrated that point-in-time authentication is no longer sufficient against determined identity-focused adversaries. What began as a seemingly routine customer service call quickly evolved into a coordinated attack that combined social engineering, identity impersonation, stolen personal information, SIM swapping, session hijacking, and unauthorized account changes. Although the attackers ultimately failed to achieve full account takeover due to rapid detection and response, the incident exposed significant weaknesses in how organizations continue to treat identity as a one-time event rather than something that must be continuously evaluated throughout the customer journey. Attack Stage 1: Establishing Trust The attack began with an unsolicited call from someone claiming to represent my wireless carrier. The phone number was not flagged as suspicious, and the caller opened with a customer satisfaction survey and discussion of loyalty discounts. The conversation felt natural and personalized, demonstrating familiarity with my account before requesting any authentication information. Key learning: Modern social engineering relies on trust, personalization, and information gathered from previous breaches rather than urgency alone. Users should independently verify unexpected customer service calls before disclosing authentication information. Attack Stage 2: Exploiting SMS Authentication After establishing credibility, the caller asked me to read back a one-time passcode that had just been sent to my phone. Ironically, the text message explicitly stated that the carrier would never ask for the code. Yet similar requests are routinely made by both call center representatives and retail store employees. At that moment, I unknowingly approved an authentication request initiated by the attacker.Advertisement. Scroll to continue reading. Key learning: SMS-based OTPs prove possession of a phone number, not the identity of the person requesting access. Organizations should prioritize phishing-resistant authentication methods such as passkeys, FIDO2 security keys, or authenticator applications whenever possible. Attack Stage 3: Obtaining the Final Credential What I did not realize was that the attacker was not primarily interested in the OTP. By the time he called, he had already collected nearly everything needed to take over my account. The only missing piece was the account passcode I had established years earlier after a previous account compromise. Because the interaction still appeared legitimate, I disclosed it, unknowingly providing the final credential needed to access my account. Key learning: Security awareness training often emphasizes passwords while giving far less attention to secondary credentials such as carrier PINs, recovery codes, and account passcodes. These additional layers of protection can create enough friction to deter attackers and should be promoted more aggressively by service providers. Attack Stage 4: Session Hijacking As suspicion grew, I attempted to log into my own account. After successfully authenticating, I was unexpectedly logged out as the attacker authenticated into the same account. Key learning: Authentication should not be treated as a single event. Organizations should continuously monitor concurrent sessions, device reputation, IP intelligence, behavioral anomalies, and other contextual signals. Simultaneous logins from different environments should immediately increase risk and potentially suspend sensitive account activity. Attack Stage 5: Rapid Recovery Fortunately, I immediately initiated a password reset using an OTP delivered to my email rather than the compromised phone number. I regained access and changed the account password before the attacker could fully establish persistence. Key learning: Attackers operate within extremely short time windows. Organizations should provide streamlined recovery capabilities for legitimate users while requiring stronger verification before high-risk account changes become permanent. Attack Stage 6: Unauthorized Account Changes Although I recovered the account quickly, the attacker still managed to make several unauthorized modifications. Most notably, my mobile number was cancelled, an action that carrier store personnel later indicated normally cannot even be performed through retail channels. Additional profile changes suggested the attacker was attempting to establish long-term control. Key learning: High-risk administrative actions involving phone numbers, SIM assignments, recovery methods, email addresses, or authentication settings should require substantially stronger verification than routine account maintenance and should be evaluated using continuous identity risk signals. Attack Stage 7: Incident Response Reporting the attack proved almost as frustrating as the attack itself. Multiple transfers between customer service, technical support, and fraud departments delayed remediation while the compromise was still unfolding. The only formal reporting option was an online form that lacked sufficient fields to capture the incident details. My subsequent forensic analysis revealed that the attack had actually begun days before the phone call. The attacker had convinced the carrier to transfer my number to a different SIM card, enabling interception of calls and text messages. The account passcode was the only remaining obstacle preventing complete account takeover. Key learning: Organizations should assume customers experiencing active account compromise have very little time. Incident response should prioritize immediate containment and enable strong security controls by default rather than requiring customers to discover and activate them. SIM swaps have become a common tactic among groups such as Scattered Spider and ShinyHunters and should be treated accordingly. Identity Security Must Become Continuous The most important lesson from this incident is not that SIM swaps remain dangerous. It is that attackers increasingly chain together multiple identity attacks during a single engagement. Social engineering, credential theft, session hijacking, account manipulation, and recovery abuse are no longer isolated techniques. They are coordinated stages of a single identity attack campaign. Organizations can no longer rely on successful authentication as proof that trust should continue indefinitely. Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. Continuous identity threat detection provides a more resilient approach by correlating behavioral patterns, device intelligence, network characteristics, geolocation, historical activity, transaction context, and external threat intelligence to determine whether identity confidence is increasing or deteriorating in real time. The question is no longer whether users can authenticate successfully. The question is whether organizations can continuously determine that an authenticated identity remains trustworthy throughout the entire session. As identity attacks become increasingly sophisticated and AI-driven, that distinction may determine whether the next attack becomes a minor security event or a full-scale account takeover. Related: SIM Swaps Expose a Critical Flaw in Identity Security Related: Major U.S. Mobile Carriers Vulnerable to SIM Swapping Attacks Written By Torsten George Dr. Torsten George is an internationally recognized IT security expert, author, and speaker with more than 30 years of experience in the global IT security community. He regularly provides commentary and publishes articles on data breaches, insider threats, compliance frameworks, and IT security best practices. He