SIM card hijack
2019-06-20 22:28:10.210631+00 by Dan Lyke 1 comments
Around noon, Charlene and I were off in the hinterlands for an appointment with her knee, and when we got back in phone range, my phone beeped to tell me that my SIM card was inactive. We quickly drove to a place with good cell coverage, called T-Mobile from her phone, and confirmed that, indeed, someone was attempting a SIM card hijacking.
So we corrected that, and I'm now back in front of a computer, and it looks like someone's cleaned out my DomainMonger account. (It also, as I was changing passwords, looks like USAA has a password length limit... that's a smell for bad things...).
At any rate, your reminder that SMS as 2FA weakens security...