[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fHeu495oVZoO-8NRgokQWIUvPX9mQewcN9a00V7Mm4nA":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":24,"created_at":25,"published_at":26,"article":27,"tags":31,"podcasts":50},"54f6d3f2-0e41-40e7-94e0-cb4ea6adc622","sim-swapping-gang-exploits-telecom-partners-to-steal-millions-in-crypto","08577782-9846-451a-a8d9-e2a63b7bab3a","SIM-Swapping Gang Exploits Telecom Partners to Steal Millions in Crypto","This case highlights how attackers exploited weak access controls within telecommunications partner ecosystems to hijack phone numbers and intercept authentication messages. By compromising telecom insiders or partner portals, the gang bypassed SMS-based multi-factor authentication — a widely trusted but inherently fragile security mechanism. The ability to redirect phone numbers gave attackers direct access to cryptocurrency exchange accounts, demonstrating that MFA is only as strong as the authentication channel it relies on. This matters because millions of users and businesses still depend on SMS-based 2FA to protect high-value accounts, making telecom supply chain security a critical but often overlooked attack surface.","**Immediate actions:**\n- Replace SMS-based multi-factor authentication on cryptocurrency and financial accounts with hardware security keys (FIDO2\u002FWebAuthn) or authenticator apps.\n- Audit and restrict third-party telecom partner access privileges, applying least-privilege principles to all partner portals.\n\n**Long-term improvements:**\n- Implement SIM-lock or port-freeze features offered by carriers to prevent unauthorized number transfers.\n- Establish rigorous vendor risk assessments for all telecommunications and identity-adjacent supply chain partners.\n- Require phishing-resistant MFA for all administrative access to telecom management systems.\n\n**Detection measures:**\n- Deploy real-time alerting on SIM change events, unexpected port-out requests, and email account login anomalies tied to account recovery flows.\n- Monitor for unusual cryptocurrency withdrawal patterns following recent account credential or phone number changes as an indicator of compromise.",[12,13,14,15,16,17,18,19,20,21,22,23],"CIS Control 5 – Account Management","CIS Control 6 – Access Control Management","CIS Control 15 – Service Provider Management","NIST SP 800-63B – Digital Identity Guidelines (AAL2\u002FAAL3 MFA)","NIST AC-2 – Account Management","NIST AC-17 – Remote Access","NIST SA-9 – External Information System Services (Supply Chain)","NIST IR-4 – Incident Handling","GDPR Article 32 – Security of Processing","GDPR Article 33 – Notification of Personal Data Breach","ITIL – Supplier Management Practice","FATF Recommendation 15 – New Technologies (Virtual Assets)","published","2026-06-26T00:20:22.316281+00:00","2026-06-26T00:20:22.185+00:00",{"id":7,"url":28,"slug":29,"title":30},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fpoland-busts-sim-swapping-gang-tied-to-millions-in-crypto-theft\u002F","poland-busts-sim-swapping-gang-tied-to-millions-in-crypto-theft-84c87a","Poland busts SIM-swapping gang tied to millions in crypto theft",[32,38,44],{"id":33,"name":34,"slug":35,"description":36,"color":37},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":39,"name":40,"slug":41,"description":42,"color":43},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":45,"name":46,"slug":47,"description":48,"color":49},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[51],{"id":52,"date":53,"edition":54,"title":55,"audio_url":56},"e343fcbd-c5e9-4c07-8654-903ff82126dd","2026-06-26","morning","ThreatNoir Morning Brief — June 26","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-06-26\u002Fthreatnoir-morning-brief-2026-06-26.mp3"]