cancel
Showing results for 
Search instead for 
Did you mean: 

I've been SIM-Swapped! Now what?

frosty34
Good Citizen / Bon Citoyen

Hello all--

 

Turns out overnight I was SIM-Swapped.  I can't contact PM because they have no clear method to contact them and get them to de-activate the SIM.  I can't get to Wal-Mart to get a new SIM until they open in an hour and a half.  The hacker made a $800 purchase on my PayPal, so obviously I've got that to deal with as well.  Has this happened to anyone?  Can anyone help?  Assuming I will need to get a new SIM ASAP?

14 REPLIES 14

@frosty34 

if you would like some security I suggest following these instructions

 

create an email strictly for public mobile
change your name and address on your self serve account
don't use your personal email password for the pm website
don't use a password manager(chrome, safari, etc. browsers
don't use your cellphone number as a 2fa for banks, PayPal etc

 

Anonymous
Not applicable

 @frosty34 

I'm just going to add one piece from all of will13am's excellent replies....we've heard of people getting their original SIM re-instated by the mods. So no need to buy a new one. So when you're going through all this with them, be sure to ask for that too.

 

The rumour is that there was a data breach back in Feb so even with great passwords the crook would simply use that reference to log in.

 

I say all the cell companies participate in aiding and abetting fraud by not having final confirmations via text as a last line of defense. There should be one for porting and another for changing SIM.

It doesn't do anything for those that don't do texting but for most of us it would be the final piece of defense.

frosty34
Good Citizen / Bon Citoyen

Great info, @will13am , thanks so much!

@frosty34 , changing phone number is a good question.  Let me start by saying that your phone number is vulnerable to being ported by whoever jacked your account.  To port all that is required is name, phone number and account number.  Even after you switch SIM card, the perpetrator has all the necessary information to take over your number via porting.  The only way to change the account number is to start a new account which is a lot of work if you want to keep your phone number. Changing your phone number may have inconveniences that you have to decide if it's manageable.  One thing you can do in the self serve is to change your name.  Since this is a prepaid service, you don't have to be truthful with the name.  In fact, putting in a different name provides port protection security.  My understanding is that 2FA port protection is possibly coming back.  Not sure when.  Given all this you have to decide what's the best way forward. 

@frosty34 , it's absolutely essential to have a strong password on the cellular account.  It's the cornerstone to security for all accounts that have 2FA that's reliant on the cell number.  While on the topic of security, make sure your phone has a secure lock code in case you accidently lose it.  Also set the phone up for remote data wipe if needed.  

frosty34
Good Citizen / Bon Citoyen

One more question for you @will13am since you have been so helpful -- is there any value in also changing my phone number, or am I okay to keep it once I get my hands on a new SIM?

frosty34
Good Citizen / Bon Citoyen

Thank you @will13am that is very helpful.  This is a cautionary tale, because it is extremely easy to change SIM cards once logged into someone's PM self-serve account.  I feel like it is almost too easy.  Perhaps my password was too easily guessed, and that is my fault, but the moral of the story here is that we all need to have very strong and unique passwords for the PM self-service site.

@frosty34 , declaring the lost phone function will disable the current SIM card from being used.  You will need to get a new SIM card and then declare phone found, change SIM card to activate the new SIM card to restore normal service.  The SIM card you have on your phone right now is useless. 

frosty34
Good Citizen / Bon Citoyen

@will13amDo I need to purchase a new SIM and reassign it to my device?  Will that give me control of my device back?

 

I have not been able to get a response from a moderator as yet.

 

Thanks!

frosty34
Good Citizen / Bon Citoyen

Thanks for this!

 

Will this process restore control of my number to me?  That is, will this permanently prevent the hacker from receiving my texts/phone calls/etc?

Triguy
Mayor / Maire

You can log into your account to change your sim and phone#.  You can only change your phone# once every 30 days.

 

Once you receive your new SIM card, you can change the SIM card number on your account and reactivate your service via Self-Serve by following these steps:

  1. Log into your Self-Serve account
  2. Go to Plan and Add-ons > Change SIM card

Triguy_0-1603460663133.png

 

  1. Enter your new SIM card number into the field. Your SIM card number is found on the back of your SIM card, as outlined in the image below:

Triguy_1-1603460663163.png

 

  1. Go to Plan and Add-Ons > Lost/Stolen Phone
  2. Select Resume Service; all done!

https://www.publicmobile.ca/en/on/get-help/articles/change-your-phone-number

frosty34
Good Citizen / Bon Citoyen

Thanks!

 

Once that's done, what is the next step?  Do I need to get a new SIM?  I can get one relatively quickly.  Will I also need to change phone numbers, or will I be secured by reassigning the new SIM to me?

will13am
Oracle
Oracle

@frosty34 , you can secure self serve account by changing your password and applying the lost/stolen phone function.  This will immediately prevent anyone from using your number for 2FA.  If you need moderator team assistance with this, following the suggestion already provided.  Separately for all other accounts relying on 2FA that have been compromised, you need to work with them to prevent further damage and undo what has been done.  Good luck.  

Triguy
Mayor / Maire

If you can log into your self serve account then change your password and security questions.

Here is a previous thread.

https://productioncommunity.publicmobile.ca/t5/Using-Your-Service/SIM-Swap/m-p/600545#M122210

 

You can send a private message to a moderator.

https://productioncommunity.publicmobile.ca/t5/notes/composepage/note-to-user-id/22437

Need Help? Let's chat.