{"id":4292,"date":"2020-03-19T18:25:50","date_gmt":"2020-03-19T06:25:50","guid":{"rendered":"https:\/\/kinetics.co.nz\/?p=4292"},"modified":"2020-03-19T18:25:50","modified_gmt":"2020-03-19T06:25:50","slug":"sim-swapping-hijacking-cybercrime-defeats-some-multifactor-authentication","status":"publish","type":"post","link":"https:\/\/new.kinetics.co.nz\/?p=4292","title":{"rendered":"SIM Swapping Hijacking Cybercrime defeats (some) Multifactor Authentication"},"content":{"rendered":"<p>[et_pb_section fb_built=&#8221;1&#8243; admin_label=&#8221;section&#8221; _builder_version=&#8221;3.22&#8243;][et_pb_row admin_label=&#8221;row&#8221; _builder_version=&#8221;3.25&#8243; background_size=&#8221;initial&#8221; background_position=&#8221;top_left&#8221; background_repeat=&#8221;repeat&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;3.25&#8243; custom_padding=&#8221;|||&#8221; custom_padding__hover=&#8221;|||&#8221;][et_pb_text admin_label=&#8221;Text&#8221; _builder_version=&#8221;4.9.1&#8243; background_size=&#8221;initial&#8221; background_position=&#8221;top_left&#8221; background_repeat=&#8221;repeat&#8221; hover_enabled=&#8221;0&#8243; sticky_enabled=&#8221;0&#8243;]<\/p>\n<p><a href=\"http:\/\/kinetics.co.nz\/wp-content\/uploads\/2020\/03\/smstheif.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-medium wp-image-4293\" src=\"http:\/\/kinetics.co.nz\/wp-content\/uploads\/2020\/03\/smstheif-300x238.png\" alt=\"\" width=\"300\" height=\"238\" \/><\/a>Today, its absolutely vital that you have multi-factor authentication on every key website you access, especially banking ones.<\/p>\n<p>In some cases, the multi-factor response is by way of a SMS text message sent to your phone, that you then enter into the website.<\/p>\n<p>Imagine if a cyber-criminal could intercept your SMS messages, and therefore gain access to your accounts?\u00a0\u00a0Turns out they might be able to. If they can call your cell provider and cook up a story, they might be able to get the provider to send your texts to them. I guess you\u2019d notice if you stopped getting text messages yourself.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Social Engineering<\/strong><\/p>\n<p>The story they use for the cell-provider is called social engineering. They use whatever hooks they can to trick the provider into thinking that the person calling them is you, not a crook. Sometimes those strange social media polls (like who was your favourite teacher at school, or the name of your first pet, are designed simply to gather information on you so they can guess your \u2018secret\u2019 questions with people like the social providers)<\/p>\n<p>That\u2019s the first thing you can do \u2013 stop answering those strange polls. Another technique we saw was to set up the \u2018secret questions\u2019 with different answers. Rather than name your favourite teacher, name the school.<\/p>\n<p>\u00a0<strong>So what&#8217;s the answer?<\/strong><br \/>Most importantly, wherever possible, use a phone app for MFA, not a text message<\/p>\n<p><strong>For more information<\/strong> : Check <a href=\"https:\/\/www.cert.govt.nz\/about\/quarterly-report\/quarter-four-report-2019\/\" target=\"_blank\" rel=\"noopener\">CERT NZ Q4 2019 Report<\/a> or check out <a href=\"https:\/\/www.nzherald.co.nz\/business\/news\/article.cfm?c_id=3&amp;objectid=12317887\" target=\"_blank\" rel=\"noopener\">The New Zealand Herald<\/a><\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Today, its absolutely vital that you have multi-factor authentication on every key website you access, especially banking ones. In some cases, the multi-factor response is by way of a SMS text message sent to your phone, that you then enter into the website. Imagine if a cyber-criminal could intercept your SMS messages, and therefore gain [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":4293,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"<a href=\"http:\/\/kinetics.co.nz\/wp-content\/uploads\/2020\/03\/smstheif.png\"><img class=\"alignright size-medium wp-image-4293\" src=\"http:\/\/kinetics.co.nz\/wp-content\/uploads\/2020\/03\/smstheif-300x238.png\" alt=\"\" width=\"300\" height=\"238\" \/><\/a>Today, its absolutely vital that you have multi-factor authentication on every key website you access, especially banking ones.\n\nIn some cases, the multi-factor response is by way of a SMS text message sent to your phone, that you then enter into the website.\n\nImagine if a cyber-criminal could intercept your SMS messages, and therefore gain access to your accounts?\u00a0\u00a0Turns out they might be able to. If they can call your cell provider and cook up a story, they might be able to get the provider to send your texts to them. I guess you\u2019d notice if you stopped getting text messages yourself.\n\n&nbsp;\n\n<strong>[wow_colorme]Social Engineering[\/wow_colorme]<\/strong>\n\nThe story they use for the cell-provider is called social engineering. They use whatever hooks they can to trick the provider into thinking that the person calling them is you, not a crook. Sometimes those strange social media polls (like who was your favourite teacher at school, or the name of your first pet, are designed simply to gather information on you so they can guess your \u2018secret\u2019 questions with people like the social providers)\n\nThat\u2019s the first thing you can do \u2013 stop answering those strange polls. Another technique we saw was to set up the \u2018secret questions\u2019 with different answers. Rather than name your favourite teacher, name the school.\n\n&nbsp;\n\n<strong>[wow_colorme]So what's the answer?[\/wow_colorme]<\/strong>\nMost importantly, wherever possible, use a phone app for MFA, not a text message\n\n<strong>For more information<\/strong> : Check [wow_colorme]<a href=\"https:\/\/www.cert.govt.nz\/about\/quarterly-report\/quarter-four-report-2019\/\" target=\"_blank\" rel=\"noopener\">CERT NZ Q4 2019 Report<\/a>[\/wow_colorme] or check out [wow_colorme]<a href=\"https:\/\/www.nzherald.co.nz\/business\/news\/article.cfm?c_id=3&amp;objectid=12317887\" target=\"_blank\" rel=\"noopener\">The New Zealand Herald<\/a>[\/wow_colorme]","_et_gb_content_width":"","footnotes":""},"categories":[4],"tags":[],"class_list":["post-4292","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"_links":{"self":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/4292","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4292"}],"version-history":[{"count":0,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/4292\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/"}],"wp:attachment":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4292"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4292"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4292"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}