Multi-factor authentication (MFA) has become more common to secure our digital lives, and one of the most convenient methods is using your cell phone number for that second factor. You log in to a website or app with a (hopefully strong!) password, and then you get a code texted to you to use to prove it’s actually you. Once you enter that code, you can proceed with your login.
As always, scammers and bad guys are looking for ways to commit identity theft, and SIM swapping is a rising issue. Subscriber Identity Modules (SIM) is how your cell phone service provider allows you on their network. An adversary, if they know some of your private information such as home address or birthdate, can initiate a SIM swap, which basically takes your SIM data and puts in their phone, which has multiple ripple effects on you.
For one thing, your cell phone won’t work anymore; you won’t be able to make calls or texts. The adversary now has complete control over your phone number, and they can use that to get into your important accounts, like your bank or your car loan. The MFA confirmation text now goes to them. With newer models of cell phones, there are now e-SIMs which can make it even easier for adversaries to perform a SIM swap, since the physical card is no longer needed.
You can protect yourself by using code-generating authenticators instead of using your phone number to get a texted code. Apps such as Microsoft Authenticator generate codes for MFA, and they aren’t tied to your cell phone, so if you do become a victim of a SIM swap, you’ll still have control over your important accounts. Another way to protect yourself is by keeping your personal information off of social media, such as your birthday, what your first car was, etc.
UCCS recommends using the Microsoft Authenticator as your MFA app, as it easily ties into your UCCS account. More information on how to set this up is located here.
For more information, the Cybersecurity & Infrastructure Security Agency (CISA) has a great fact sheet found here.