In a stark warning, F.A.C.C.T., a leading Russian cybersecurity firm, has raised alarm about the sinister use of eSIM technology by criminals to pilfer phone numbers, enabling access to sensitive bank accounts. The revelation, reported by Bleeping Computers, sheds light on a disturbing trend where eSIM, initially designed for convenience, are now being exploited as tools for nefarious activities.
eSIM, or electronic SIM card, represents a digital evolution of physical SIM, residing within mobile device chips and offering identical functionality with the added benefit of remote reprogramming capabilities. Users can seamlessly integrate an eSIM into their devices by scanning a provided QR code from their service provider. Widely embraced by smartphone manufacturers, this innovation eliminates the need for traditional SIM card slots and facilitates cellular connectivity even in compact wearables.
Also read: Google Gemini could expose sensitive information; researcher warns about the abuse of chatbot
However, cybercriminals have proven adept at exploiting the vulnerabilities inherent in eSIM technology. Since the autumn of 2023, analysts at F.A.C.C.T.'s Fraud Protection division have observed a surge in attempts to breach personal accounts within a prominent financial institution. These attackers, employing a technique known as SIM swapping, infiltrate users' mobile accounts using various means, including stolen or brute-forced credentials. Subsequently, they initiate the porting of victims' numbers to their own devices by generating QR codes through compromised accounts. This malicious manoeuvre effectively wrests control of the victim's phone number while deactivating their legitimate eSIM or physical SIM card.
Once in possession of a victim's mobile phone number, criminals gain unfettered access to a treasure trove of sensitive information according to the report. This includes obtaining access codes and circumventing two-factor authentication measures across a spectrum
Read more on tech.hindustantimes.com