Simjacking is Still a Problem, British Food Writer Lost £5,000

Stu Sjouwerman | Oct 15, 2019

MonroeBritish food writer Jack Monroe lost £5,000 due to a simjacking attack, the BBC reports. In a series of tweets, Monroe said someone had taken over her phone number and used the access to steal months worth of earnings from her bank account. She added that her payment card details and PayPal information were apparently stolen during an online transaction.

Simjacking occurs when an attacker calls a mobile operator and impersonates a target in order to trick the operator into porting the target’s phone number to the attacker’s device. The attacker can then exploit anything the number grants them access to, and can bypass SMS-based two-factor authentication. In Monroe’s case, the attacker was able to trick the operator into switching the phone number by providing Monroe’s birth date, which is available on Wikipedia.

It’s worth noting that Monroe did have precautions in place. She stressed that she is “absurdly paranoid about security,” and says she uses two-factor authentication on everything, along with unique, complex passwords. Simjacking can bypass these safeguards however, since it doesn’t target the victim directly and takes advantage of a human employee at a mobile phone company.

As technical defenses improve, social engineering attacks will increase. Even if your organization has the most advanced defenses in place, your security posture is still severely lacking if one of your employees can be tricked into giving the attacker what they want. New-school security awareness training can ensure that your employees have the skills to resist these attacks. The BBC has the story: https://www.bbc.com/news/technology-50043230

Ready to Build a Security Culture That Lasts?

Stop treating training like a checkbox exercise. Using 15+ years of behavioral data, our AI-powered platform personalizes training for every user to significantly reduce human risk and stop attacks before they start.

Get a Quote

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.