logo

‘Got that boomer!’: How cybercriminals steal one-time passcodes for SIM swap attacks and raiding bank accounts

ID: 27548333-29fd-5784-8b92-e436866a920c

STIX ID: report--27548333-29fd-5784-8b92-e436866a920c

Feed Name: TechCrunch Security News

Threat Score
78/100

Date Published: 2024-05-13

Date Updated: 2026-04-23

Author: Zack Whittaker

...
...

TechCrunch revealed that a criminal service called "Estate" has automated thousands of phone-based social-engineering attacks since mid‑2023 to capture one-time passcodes (OTPs), enable account takeovers and conduct SIM swaps; a bug exposed Estate’s unencrypted backend database with line-by-line logs of more than 93,000 attacks, victim phone numbers, member details and attack scripts, highlighting large-scale abuse of telecom providers and weaknesses in MFA reliance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.