logo

Payoneer accounts in Argentina hacked in 2FA bypass attacks

ID: ff8e2d55-3431-5d01-b3fe-69aefa10e0b9

STIX ID: report--ff8e2d55-3431-5d01-b3fe-69aefa10e0b9

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-01-19

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Numerous Argentinian Payoneer users with SMS-based 2FA reported waking to account takeovers and losses of roughly $5,000–$60,000 after receiving approval/reset SMS messages; investigators and journalists cite phishing SMS, a leaked Movistar dataset, or an SMS provider compromise (or a Payoneer 2FA/process weakness) as possible causes while Payoneer and Movistar provide limited/partial responses and users are advised to withdraw funds or disable SMS 2FA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.