페이지를 넘기고 있습니다.
다음 장을 불러오고 있습니다…
잠깐… 나만의 읽기 환경을 만들어 보세요.
글꼴과 테마는 화면 설정에서 설정하세요. 눈의 편안함도 중요합니다.
다음 장을 불러오고 있습니다…
Attackers port your phone number to intercept SMS 2FA. Use app or hardware 2FA for exchanges.
브라우저의 읽어주기 지원을 확인하는 중…
이 읽기 자료는 현재 영어로 제공됩니다. 인터페이스에는 선택한 언어가 적용됩니다.
영어 원문 읽기 →A SIM swap attack (also known as port-out scam, SIM splitting, simjacking, and SIM swapping) is a type of account takeover fraud that generally targets a weakness in two-factor authentication and two-step verification in which the second factor or step is a text message (SMS) or call placed to a mobile telephone.
The fraud exploits a mobile phone service provider's ability to seamlessly port a phone number to a device containing a different subscriber identity module (SIM). This mobile number portability feature is normally used when a phone is lost or stolen, or a customer is switching service to a new phone.
The scam begins with a fraudster gathering personal details about the victim, either by use of phishing emails, by buying them from organised criminals, directly socially engineering the victim, or by retrieval from online data breaches.
Armed with these details, the fraudster contacts the victim's mobile telephone provider. The fraudster uses social engineering techniques to convince the telephone company employee to port the victim's phone number to the fraudster's SIM. This is done, for example, by impersonating the victim using personal details to appear authentic and claiming that they have lost their phone. Alternatively, fraudsters bribe telecom employees to port the victim's phone number to a new SIM.
In some countries, notably India and Nigeria, the fraudster will have to convince the victim to approve the SIM swap by pressing 1.
A number of high-profile hacks have occurred using SIM swapping, including some on the social media sites Instagram and Twitter. In 2019, Twitter CEO Jack Dorsey's Twitter account was hacked via this method.
In December 2018, digital currency investor Michael Terpin – the founder and chief executive officer of Transform Group – filed a lawsuit against Nicholas Truglia, and in May 2020 filed a second lawsuit against 18-year-old Irvington High School senior in Irvington, New York, Ellis Pinsky, accusing them and 20 co-conspirators of swindling $23.8 million in 2018 through the use of account information stolen from smartphones by SIM swaps. At the time, Truglia was 18 years old and Ellis was 15.
Truglia was sentenced to 18 months in prison and ordered to pay back $20 million, and Pinsky was ordered to pay back $22M but, as a minor, avoided prison.
The Microsoft Digital Defense Report 2024 stated that less than one-third of one percent of identity attacks use SIM swapping (compared to 99 percent for breach replay, password spray, and phishing).
다음 자료에서 선별하고 재구성했습니다: SIM swap attack, 기여자들이 작성했으며 적용 라이선스는 CC BY-SA 4.0. 개정판 1369252932. 섹션과 서식을 줄였습니다. 연결된 개정판에서 전체 맥락과 기여 기록을 확인할 수 있습니다. 이 참고 문서는 동일한 라이선스를 유지합니다. 추가 인용 링크는 해당 개정판에서 가져왔으며 여기서 별도로 확인하지 않았습니다.