Sujet : Re: "'Scammers stole £40k after EDF gave out my number"
De : newyana (at) *nospam* invalid.nospam (Newyana2)
Groupes : comp.mobile.android uk.telecom.mobileDate : 16. Mar 2025, 04:30:31
Autres entêtes
Organisation : A noiseless patient Spider
Message-ID : <vr5git$t0ll$1@dont-email.me>
References : 1 2 3 4 5 6 7 8 9 10 11
User-Agent : Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:78.0) Gecko/20100101 Thunderbird/78.3.1
On 3/15/2025 1:53 PM, Java Jive wrote:
On 2025-03-15 12:35, Newyana2 wrote:
On 3/15/2025 7:46 AM, Java Jive wrote:
On 2025-03-14 18:49, Theo wrote:
>
Speculating, I would guess they started with the SIM swap.
>
The original report suggests that they started with an email hack, and used that to facilitate the SIM swap.
>
That's not what it said.
Look back directly up thread to my post of 2025-03-06 19:53, where I quote the single sentence in the original report that stated that an email hack had occurred before the SIM-swap scam was done.
You read it wrong.
"O2 Virgin Media confirmed the scammer telephoned its call centre requesting a new Sim and had hacked Stephen's emails."
Both things happened. Nowhere does it say or imply that
hacking the email preceded the SIM swap. That wouldn't
make sense.
"
EDF explained the fraudster had his name and email address and had asked EDF to give them his mobile number, which the company did. ... The call from the fraudster to EDF happened three hours before O2 received a request to move his number in the Sim-swap scam. ...
"
So they called EDF with name and email, asking for their phone
number. With that they called O2 and asked to swap SIMs.
Once the SIM was swapped they could log in to email and say
the lost their password. They then have a password change
link sent via email or text... which they now control.
As the article then states: "Criminals do it to bypass two-factor
authentication to change passwords and access anything else
you need a code from a text message for."
Hacking his email wouldn't have got the scammers a way to
bypass 2FA via cellphone, but a SIM swap would. So if the man
had not been using 2FA it's unlikely that he could have been
scammed.