cancel
Showing results for 
Search instead for 
Did you mean: 

SECURITY BREACH?

Mrbox
Good Citizen / Bon Citoyen

Okay so I am very concerned. While getting help for my own SIM-Jacking, I am seeing many other people having the same issue. What is going on!!! My wife is also a part of Public Mobile and now we are concerned and thinking of changing providers. 


We don't want to do this but it is very concerning to see so many people getting SIM-Jacked! 

 

Anyone know whats going on?!? 

42 REPLIES 42

mimmo
Retired Oracle / Oracle Retraité

@popping  or anyone else apart from using a password manager do you have any tips for creating unique passwords for every site that requires a password.?  I must have over 100 sites that require passwords and it's impossible to remember a unique password for each.

mimmo
Retired Oracle / Oracle Retraité

PM is aware of the various sim jacking threads

 

Is it a system issue?

 

Is it a user issue ie using same email pass on multiple places?

 

Socially engineering mods to change sims ( doubt it)

 

If you are absolutely concerned change your login email to an email alias ie name+123@gmail.com. Ensure you have a unique password and change your account name (add a spending error)

 

My biggest question on reading various threads is that hackers are lazy ie the manage to change the sim card number but not the account password.  

 

 

 

will13am
Oracle
Oracle

I have been with this service for over 4 years.  It is only recently I have seen cases of SIM jacking.  But then again, this is a new phenomena all over.  I have been trying to make sense of the incidents reported in the community.  There have been some case where the affected party have had their number used to reset passwords in other accounts, etc.  In many of the reports, nothing bad happened.  In all reported case, customer continue to be able to login to their self serve account and confirm the SIM card change.  I cannot make sense of why someone SIM jacking an account would stop at just doing the SIM swap and not change the self serve account password and take over the entire account.  What thief would not secure their crime scene?  

popping
Retired Oracle / Oracle Retraité

@softech wrote:

wonder if anyone who have sim-jacked ever try to report to Police..  Of course. a single case is nothing to the Police (.. they are only hire to catch big fish.. lol).. but if enough cases opened, maybe it will push them to do something too.. 

 

 


I think that we have to protect ourselves by not using the same password for more than one online accounts.  Otherwise, if a scammer gets hold of your password from one online account, all your other online accounts are at risk.

Jb456
Mayor / Maire

@Mrbox 

 

Part comes down to people being careless on the internet with their personal information. The other part comes down to some other website having a data breach and people using the same password for every single thing they sign up for. 

 

Put your email in on this link. See how many times it's been involved in a data breach or bin paste.

 

https://haveibeenpwned.com/

 

People have to remember these scammers are professionals and it's their 24/7 job. Hack n make money simple as that!.

 

It's rather simple to take someone's username Google with quotes and try to find similarities on other same usernames for other sites if it's the same person. Chances are (people that use specific usernames definately use the same on other sites) then you just start digging and digging. Before you know it you have the person Facebook info, email and physical address. The list goes on and on. Then even the security answer to "Forgot passwords" need to be very strong. Even different then what the real answer is would be best.

 

"What is my mother's maiden name?". Ok well this person has a wide open Facebook. Start digging through his pictures, likes and posts. Eventually you'll find something about the mother and their name. Voila I just hacked into your email. Now I'm in your email. Just continue to request forgot passwords from all kinds of sites and get into those as well.

 

It's pretty much endless if people don't take the first step in protecting themselves. 

 

Even in the Lounge on these forums I find people post to much personal stuff that opens up an opportunity for scammers.

 

Then personal pictures ain't good. You could reverse image search and see if the same image comes up somewhere else then start digging.

 

I've had my same original Hotmail email address since like 1998 and I get under 10 spam messages a month. I'm sure not many can say the same regarding spam emails. It's all about what and how you do things online.

 

I hope this message gives some type of understanding how easy it is for scammers to get your info and do a simjack. 

 

Won't go into Keyloggers and stuff as that would be a whole other category. 

 

Just stop the personal info online, different strong passwords for every site and be more cautious should help protecting you

popping
Retired Oracle / Oracle Retraité

@Mrbox wrote:

Yea that's what I am worried about. Like I caught it before any really bad happened but they did manage to get into my PayPal and order from Ebay. I am out $12 but could have been worse. They tired authorizing transactions for a total around $900. Like not cool. I am worried it is only a matter of time and my wife's phone will be hi-jacked. 

 

When I first lost service my wife tried to call me and someone picked up and hung up and now that is on my usage summary on my account and it says they picked up in Quebec. The eBay order is also supposed to be shipped to Quebec. I am wondering if it is all the same person getting our SIMs


You are using the password for more than 1 online account.

Start by changing your password for all your online accounts.  Do not reuse password over and over on all all your online accounts.  There are lots of scammers on the Internet.

wonder if anyone who have sim-jacked ever try to report to Police..  Of course. a single case is nothing to the Police (.. they are only hire to catch big fish.. lol).. but if enough cases opened, maybe it will push them to do something too.. 

 

 

popping
Retired Oracle / Oracle Retraité

@Mrbox wrote:

Okay so I am very concerned. While getting help for my own SIM-Jacking, I am seeing many other people having the same issue. What is going on!!! My wife is also a part of Public Mobile and now we are concerned and thinking of changing providers. 


We don't want to do this but it is very concerning to see so many people getting SIM-Jacked! 

 

Anyone know whats going on?!? 


Someone must be have access your password to your PM account.

Did you using the same password for more than 1 online accounts?

When a scammer get hold of your password on one of your account, they will try to login to as many online accounts and hoping to gain access to one or more online account which is useful for them. 

Mrbox
Good Citizen / Bon Citoyen

Yea that's what I am worried about. Like I caught it before any really bad happened but they did manage to get into my PayPal and order from Ebay. I am out $12 but could have been worse. They tired authorizing transactions for a total around $900. Like not cool. I am worried it is only a matter of time and my wife's phone will be hi-jacked. 

 

When I first lost service my wife tried to call me and someone picked up and hung up and now that is on my usage summary on my account and it says they picked up in Quebec. The eBay order is also supposed to be shipped to Quebec. I am wondering if it is all the same person getting our SIMs

softech
Oracle
Oracle

i was wondering if SIMjack is a common issue with PM, too..  Or maybe just I am following Community now more and see more people talks about it.  Either way, I think that mean PM should do more to fight against SimJack.. like more steps to change SIM..more verification questions or so. 

BearFBI
Deputy Mayor / Adjoint au Maire

Something's not right. On one of the PM accounts I manage had a text saying that someone wanted to send me these pictures to you. The someone that was mentioned was actually the name of a contact on the phone. Could it just be a coincidence ? Thats what i said and I shrugged it of and said its nothing just delete it. She thought she was getting hacked. 

 

Well now that I'm logged onto the forum I'm hearing people having their accounts stolen. What if there actually is a security breach ?

BearFBI
Deputy Mayor / Adjoint au Maire

I have no idea whats going on.

Need Help? Let's chat.