SIM Swap is when the fraudster gets the SMS verification codes by transferring the number from the operator on behalf of the victim.
Attack Method
- The fraudster obtains the victim's identity information
- The operator goes to the store
- He says "My phone is lost, get a new SIM"
- The operator gives a new SIM with insufficient control
- The fraudster obtains the SMS verification codes takes over
- Takes over the bank/social media account
Operator Liability
- Inadequate identity check = operator responsibility
- BTK regulations require strict control
- Victim can recourse to the operator for bank loss
What the Victim Should Do
- Call the operator immediately (freezing new SIM)
- Bank account freezing
- Change all account passwords
- Public prosecutor's office + EGM
- BTK complaint
Prevention
- Have an "additional security password" defined by your operator
- Instead of SMS, application-based 2FA (Google Authenticator)
- Security questions are up to date in the bank
Supreme Court 11. HD
11. HD accepts that in SIM Swap cases, it is critical whether the "operator security procedure" is implemented or not, and that the operator will be held responsible for incomplete control.
Cyber crimes lawyer is recommended.