logo

SIM swappers hijacking phone numbers in eSIM attacks

ID: 419efa6c-12eb-5c3a-b96e-eb52f8c0bdf1

STIX ID: report--419efa6c-12eb-5c3a-b96e-eb52f8c0bdf1

Feed Name: Bleeping Computer

Threat Score
65/100

Date Published: 2024-03-14

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Researchers report a rising trend of SIM-swapping via eSIM provisioning: attackers who gain access to a victim's mobile account (through stolen, brute‑forced, or leaked credentials) generate activation QR codes or otherwise re-provision the victim's phone number onto an attacker-controlled eSIM, deactivating the victim's SIM and enabling account takeover of banking and messaging services. F.A.C.C.T. observed over a hundred attempts against one financial organization since fall 2023; recommended mitigations include strong unique passwords, two-factor authentication on carrier accounts, and using hardware tokens or authenticator apps for high-value services.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.