SIM swap, social engineering nearly hijack wireless account
An attacker used social engineering and a SIM swap to intercept one-time codes, hijack a session and change a wireless account before the owner regained access.
An attacker used social engineering and a SIM swap to intercept one-time passwords, hijack an active session and make unauthorized changes to a wireless account before the account owner regained access and restored some settings.
The incident began with an unsolicited call from someone claiming to be a carrier representative. The caller opened with a customer satisfaction survey and loyalty offers and referenced account details. During the call, the account owner was asked to read aloud a one-time passcode sent by SMS; the message itself warned that the carrier would never request the code.
By that time the attacker had collected much of the account owner’s personal information from prior breaches and other sources. The caller requested a long-standing account passcode; the account owner provided it and the attacker used that final credential to authenticate into the account.
When the account owner attempted to sign in, the attacker’s session took precedence and the owner was logged out. The owner regained access by using an email-delivered one-time code and changed the account password. The attacker had already cancelled the mobile number and altered profile information before some changes were rolled back.
A forensic review showed the compromise began days earlier. The attacker had persuaded the carrier to transfer the victim’s phone number to a different SIM, allowing interception of calls and text messages. That reassignment enabled the SMS-based steps and complicated recovery efforts.
The account owner recalled that “the text message explicitly stated that the carrier would never ask for the code.” The account owner added that “authentication should not be treated as a single event.”
When the owner contacted the carrier, multiple transfers among customer service, technical support and fraud teams delayed containment. The carrier’s only formal reporting option in this case was an online form that did not capture the incident’s full technical detail.
Store personnel later indicated that cancelling a number normally cannot be completed through retail channels, suggesting procedural gaps or elevated access were exploited. Recovery was possible because the account had an alternate email recovery route, but the attacker had a window to change settings.
SIM reassignment attacks have been used in recent campaigns to combine social engineering and credential theft and to bypass SMS-based one-time passwords. In this incident, social engineering, stolen personal data, SIM swapping, session hijacking and recovery abuse were used in sequence over a short period.








