[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fRk5gy9_j3uqRNsznY3BqmBpsrAZwJCL3_P-As3rGcR4":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":20,"created_at":21,"published_at":22,"article":23,"tags":27,"podcasts":40},"b644906a-677f-489c-bde5-8dacd6cd7475","sim-swap-attacks-render-sms-based-2fa-vulnerable-to-account-takeover","a5a99975-d7fb-44cb-999e-944a6b7bd0dd","SIM Swap Attacks Render SMS-Based 2FA Vulnerable to Account Takeover","SIM swap attacks allow threat actors to socially engineer mobile carriers into transferring a victim's phone number to an attacker-controlled SIM card, effectively intercepting all SMS messages including one-time passwords (OTPs). This exposes a critical weakness in SMS-based two-factor authentication (2FA), which many users and organizations mistakenly treat as a strong security control. The root issue is an over-reliance on a single, easily circumvented authentication factor combined with insufficient user awareness about stronger alternatives. Because phone numbers are tied to identity verification across banking, email, and social media platforms, a single successful SIM swap can cascade into full account takeover across multiple services.","**Immediate actions:**\n- Replace SMS-based OTP authentication with app-based authenticators (e.g., Google Authenticator, Authy) or hardware security keys (e.g., YubiKey) wherever possible.\n- Contact your mobile carrier to add a SIM lock or port freeze PIN to prevent unauthorized SIM transfers without in-person verification.\n\n**Long-term improvements:**\n- Adopt FIDO2\u002FWebAuthn-compliant phishing-resistant MFA as the organizational standard for all critical systems and user-facing applications.\n- Educate users regularly on social engineering tactics used in SIM swap fraud, including how attackers impersonate victims with carriers.\n- Audit all services that rely on phone numbers as a recovery or authentication mechanism and migrate them to more secure alternatives.\n\n**Detection measures:**\n- Set up real-time alerts for account logins from new devices or locations, especially immediately following any phone number change events.\n- Monitor for unexpected MFA method changes on user accounts and treat them as high-priority security incidents requiring immediate verification.",[12,13,14,15,16,17,18,19],"NIST SP 800-63B: AAL2\u002FAAL3 Authentication Assurance Levels","NIST AC-2: Account Management","NIST IA-5: Authenticator Management","CIS Control 6: Access Control Management","CIS Control 14: Security Awareness and Skills Training","FIDO2\u002FWebAuthn Standard (W3C)","GDPR Article 32: Security of Processing","ITIL Service Design: Information Security Management","published","2026-06-23T15:22:50.226367+00:00","2026-06-23T15:22:49.876+00:00",{"id":7,"url":24,"slug":25,"title":26},"https:\u002F\u002Fwww.darkreading.com\u002Fcyber-risk\u002Fhow-a-sim-swap-attack-led-to-a-near-account-takeover","he-thought-he-was-secure-his-phone-number-got-stolen-anyway-53c25d","He Thought He Was Secure; His Phone Number Got Stolen Anyway",[28,34],{"id":29,"name":30,"slug":31,"description":32,"color":33},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":35,"name":36,"slug":37,"description":38,"color":39},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",[]]