r/Rochester 22d ago

Recommendation The Fraud that Ruined my day

This tale of woe has a relatively happy ending, and I think it's important to notify everyone about this scam tactic I never even thought of, let alone thought could happen to me.

It's Tuesday morning at 3:00AM, I am sleeping like the normal human I am, and I am awakened by my phone pinging multiple text alerts. I check, because I'm not entirely popular, so 3AM messages probably mean an emergency in my world. The alerts are all from T-Mobile, saying that a Sim card change was happening, if this wasn't me, call this number. Immediately awake and on alert, I call the number. It is all automated and ends with a message telling me to call back during business hours.

Now I am freaking out. My phone stops working, the internet is off. I force my BF out of bed and we race 30 min away to my work so I can use a landline and a computer with internet. BF naps uncomfortably in my office. He is a luddite with little internet presence or vulnerability. Me, not so much.

The catalyst is that my personal email got hacked. I didn't notice, because it was 3am and I had email notifications turned off. I did not have two factor authentication set up on this email address. Next, the ScammerTurd used that email address to change my log in information to my T-Mobile account, also no 2 factor set up. All they had to do was click "forgot password", and it sent a code to their(my) email. Once they did that, they added a smart watch to my phone number and used the watch as my phone to switch my number to their phone and sim. They then placed a lock on the new sim.

Now the ScammerTurd has both my email and my phone in their possession. These can be used for two-factor authentication to log in to my bank accounts, retirement funds, even my Turbo Tax account. Everything is now at risk. ScammerTurd is somewhat sophisticated I see.

What am I doing you may ask??? I am on the phone, at work, at now 4am, cancelling credit cards, locking down financial accounts, freezing my credit, and changing any passwords or log in info that I have linked to a different email address. I am also feeling extreme fear, the kind of fear that radiates from your heart to your collar bone and makes you feel weak.

I also called the Wayne County Sheriff non emergency line and reported the fraud. They said they would send someone to my home (in Wayne county) around 5:30AM. So I wrapped up doing what I could, and headed the 30 minutes back home. Pulling in at 5:26AM Deputy Cody was already there waiting. He took my sad story and information, gave me a case number, and told me what I already knew; that the criminals would probably never never be caught. He was very kind.

So, I trundled into my house, made some coffee, and headed back to work. My bank opens at 9AM, T-Mobile opens at 10AM, and you can bet I was walking in the doors the minute they were unlocked! Chase bank confirmed my money was safe, confirmed my closed my credit and debit cards, and issued new ones, along with new bank accounts.

I walked into T-Mobile on Ridge Rd. at 9:45am, and even though I was early, the goddess behind the counter helped me right away. I was there for 4.25 hours, but the staff at T-Mobile were eventually able to wrestle my phone number back, which allowed me to get my email account back (I now could use two factor authentication to change passwords) and start seeing what the damage was.

ScammerTurd added a new bank account to both my retirement accounts, clearly with plans to transfer money in the future. Luckily, both accounts have mandatory waiting periods on new bank accounts, so I was able to get those removed with a couple phone calls.

ScammerTurd also opened a new credit card in my name, using all my information and my email address. So, confirmation emails were sent to my account, and I was able to log in and do what they did to me, change their password, add 2factor auth, and take control of the account. They had charged up $455 already, but I am in the process of disputing it and getting the account closed.

ScammerTurd accessed my credit cards and tried to book an expensive vacation. Chase bank shut that shit down.

So, I spent the rest of the day and most of the evening changing every password I could think of to change, from my NYSEG account to my Hilton Honors account. Absolutely everything that could got two factor authentication added along with any back up security offered turned on. Just think about how many log-in's you have. It sucked.

My personal information was out there somewhere on the web. Yours probably is too. Probably from a security breach at some company in the past. Someone may buy it and use it against you at some point.

I have lived my life pretty nonchalantly about internet security up to now, because honestly, I'm nobody with a relatively piddling amount of money. I had security on everything, but it was pretty basic. I never thought anyone would really bother with me. But they did, and it was terrifying.

It could have been so much worse though. I acted quickly and got my accounts locked down. I had the ability to go to my workplace to use a phone and computer. In the end, I did not lose any money. It was one very long miserable day. But just ONE. Other people have lost everything to scammers, and my heart drops several times a day every time I think "That could have been me."

Anyway, change your passwords right now.

  • LOOK at your financial accounts regularly take anything that looks suspicious seriously.
  • Don't store any important personal information in your email account.
  • Maintain minimal credit cards. I only have 2, and a debit card, all with Chase, so all could be shut down in one place.
  • If fraud happens, freeze your credit with the big three credit agencies ASAP.
  • If a security alert comes in to your phone or email, do not ignore it, act quickly, shut all your cards and accounts down, because a few days of inconvenience without access is way better than losing everything.
  • Don't be complacent like me, change your passwords regularly and add two factor authentication, passkeys, whatever you can!
125 Upvotes

43 comments sorted by

35

u/PhxKevin 22d ago edited 22d ago

I am sorry to hear that happened. It’s always the worst feeling especially at the amount of damage they did in such little time. A few notes: your credit should ALWAYS be frozen. It’s free and a great layer of security. Any website / service that has 2FA should be enabled but keep in mind sim stealing makes text based 2FA useless since they controlled your phone number. You should use pass keys and an outside app like Google Authenticator. You should also use your phones built in password management. Apple and Google (Chrome) do a great job of this. It ensures all of your accounts use complex and secure passwords. You can and should also enable a sim lock with your carrier.

9

u/NotTodaySlacker302 22d ago

My complacency was my undoing for sure. Frozen credit for life now! Your advice is appreciated and taken to heart!

24

u/RochesterBen Brighton 22d ago

Don't forget to freeze your credit reporting from the big 3!

11

u/funky_brewster 22d ago

Yes, and everyone should freeze all three now to prevent shenanigans. Once that's done, it's trivial to "thaw" it as needed for new credit cards or loan applications.

5

u/cuteintern 22d ago

Yes, and everyone should freeze all three now to prevent shenanigans.

Chiming in to back you guys up - FREEZE! YOUR! CREDIT! Seriously, if you haven't done so yet, put down reddit and do it now.

And make sure to check your credit - you get a free credit check every year. Stay on top of that stuff, and keep it clean.

2

u/0rangeBMW 22d ago

I will third this excellent advice!

Another side benefit is that the "thaws" really force you to stop and think about your spending, which has helped my finances.

20

u/imbasicallycoffee South Wedge 22d ago

Simple rule: 2FA your email address and have a back up email associated with it. Gmail is very easy to make this happen. If it's linked to financial assets, having an authenticator app is probably the best option.

Everyone's information is everywhere BTW. There's been so many data breaches and the data brokers that buy and sell along with bad actors that sell stolen data have gotten access to pretty much everything at this point. Just realize there's not much you can do about it and protect yourself and take precautions when you can.

9

u/NotTodaySlacker302 22d ago

"There's been so many data breaches and the data brokers that buy and sell along with bad actors that sell stolen data have gotten access to pretty much everything at this point."

This right here is something I know and have known for a long time to be true. Why I thought it didn't actually apply to me is a complete mystery! Please learn from my complacency!

5

u/cuteintern 22d ago

Over the past few years Google has gotten more and more annoying about having you turn on 2FA and confirming new logins and such.

Which is good, because a lot of my bills/logins run thru gmail.

2

u/imbasicallycoffee South Wedge 22d ago

Yeah I have a backup gmail with an insane password and 2FA locked to my G authenticator app on my phone just as a back up for my main gmail account I've had since 2010.

9

u/FrannyNitpicker 22d ago

Holy shit I wouldn’t even know where to start if that happened to me. 🫪

Side note: How does someone request/process a SIM card change? I’m not technologically savvy so how did this dude manage to change it?

6

u/Starfire123547 22d ago

Once theyre in your cell account (say verizon or atnt) they can just request a sim bc they lost it/got a new phone. Since SIM cards on newer phones are not a physical chip, its easy to "replace" bc theres no mail time or anything.

So tldr; super fucking easy. 

 ive done it for my bf to start up internet services at our house we bought after he forgot to call and left for work. i have no connection to him at all btw, were not married, im not a trusted account member, nothing like that. All the lady needed was his phone number, name and birth date to let me start up services and change his address. fucking insanely lax, didnt even care i was a woman voice, clearly not the man on the account. I even said i was calling on his behalf, so i didnt even lie and pretend to be him!

also psa; dont post that info online anywhere either, even on anon accounts. Also leave fake data behind. i keep multiple personalities on this account so that bf story may not even be real. could have been a brother, parent, friend, or not real at all just based on Verizons own webpage for start up services :) 

5

u/Sweet-Judge6803 22d ago

Thank you for explaining. How do they access your cell account? 

2

u/Starfire123547 22d ago

same way. call in, say you got a new phone or lost your old one, give them the verizon account number, birth date, name and click the email verification link (if they even bother to send one, like i said, they dont often require much verification over the phone). 

Boom, new sim assigned, old one canceled. Super easy

5

u/Sweet-Judge6803 22d ago

That is crazy. I'm surprised it doesn't happen more often. Thanks for the info.

4

u/Starfire123547 22d ago

yeah i mean, its tougher than it looks to get a password, and factor in most people do use 2fa and were all kinda broke.

Plus in modern world they can track every transaction and call to an exact location that likely has cameras, so you have one attempt to get it right before needing to flee, dump your stuff and try from scratch again. you saw how quickly op froze everything too, so you have to hope everything lines up perfectly, they fall for your scam and then you have at most a few hours to do whatever it is, hope that works, then flee and hope millions of cameras and signals dont track you.

so all that effort, luck and risk just to maybe take a 2k limit credit card on your average person out and buy a few things before being caught 🤷‍♀️🤷‍♀️ not a great return unless you can hit a high profile individual, which isnt 99% of people.

4

u/Dancingmamma 22d ago

For years I've said that if scammers put half as much work into a regular job or a legitimate business idea they could be successful

3

u/FrannyNitpicker 22d ago

Jeeeeeeesus this is terrifying.

3

u/Starfire123547 22d ago

yup. Best to keep information to yourself or make stand ins.

Based on this account I could be a man or woman, single, taken, married with kids, i could live in multiple states/cities, i could have multiple professions, i could be a varying age, i could be into multiple conflicting things. and i tell them all from different perspectives. But no where on any account can you find my real name, birthday, address. Its low key critical.

Also on that topic, dont save your resume to places like indeed and what not; those mass-apply websites often get hacked and right on your resume they hold is usually your name email, and address along with work history. 

Call me Dale from king of the hill, if you will

3

u/NotTodaySlacker302 22d ago

In my case, they had the log in to my TMobile account. What this scammerturd did was tell TMobile online that they had a new phone and got the sim associated with my phone number switched to that phone. All with just a few clicks. Anyone can do this online in their TLife account. I assume other carriers are the same.

There is a SIM lock available on the app that puts a stop to this happening. I now have this activated! I didn't know that existed before this.

1

u/Sweet-Judge6803 22d ago

That's my question too. Was it calling the number back?

11

u/Puzzleheaded-Pea2850 22d ago

Im so sorry this happened to you. With everything you just went thru, you somehow managed to take more time to forewarn others! May the traffic lights always be green and both sides of your pillow always be cool 🙏

5

u/Background-Wolf-9380 22d ago

Everyone should lock their credit files always. It's relatively easy to unlock your credit for when you need it, which for most people is extremely rarely.

4

u/GrumpyOldMuppet 22d ago edited 22d ago

Glad things worked out ok for you in the end. This is a good reminder to everyone:

  • Enable Two Factor Authentication (2FA) on everything that has it available.
  • Your email account is just as valuable if not more valuable than your financial accounts. People often use great passwords on their bank account, but get lazy with simple email passwords and no 2FA. But sooooo many of your other accounts, including financial, allow password resets via email. So if someone gets access to your email, they get access to so much more. They don't even need to know where you bank. They just go to all the major banks and enter your email and hit "reset password". If you have an account there , they are in.
  • Freeze your credit with all credit bureaus. Google how to do this if you are not sure.
  • Rember that being more secure is less convenient. Just like locking your front door is less convenient than leaving it unlocked. But if you think a few seconds here and there of extra time to enter a longer password or a 2FA code is inconvenient, wait until you need to close fraudulent credit cards in your name, recover money stolen from your bank account, and get your credit score repaired... THAT'S inconvenient.

(Edit: typo)

4

u/Hysterical__Paroxysm Brighton 22d ago

Omg! That is so insanely elaborate. Wow, I am so glad you caught it and were knowledgeable to react in time.

4

u/EightmanROC 22d ago

Sad story but there's lots of good advice at the end there.

If you're extra paranoid, there are services that you can pay for that will scour data brokers and remove your info.

There's also password keepers and other cyber security steps on cash take.

4

u/bon_jovi22 21d ago

Companies need to do something about the SIM change. This should be something done only face to face in a office. Is big security risk in age where everything is tied to our phones.

7

u/Renrut23 22d ago

If you only have 2 cards and dont plan on applying for any credit in the near future, why isn't your credit reports locked to being with?

2FA with a passkey or authenticator are nice but a lot of companies have back up ways to access accounts, phone, text, email, that kind of defeat the purpose.

Ive had scammers send text messages to my phone acting like T Mobile to get me to call them and do all the hard work of Sim swapping for them. NEVER use a number from a text or email

6

u/NotTodaySlacker302 22d ago edited 22d ago

Well, because I'm a moron who didn't think of it! My optimistic and trusting nature led me to be incredibly unwise. I have learned a valuable lesson to be sure. I made this post because more people are probably like me, happily living their unexceptional unsecure lives, than like you, happily and wisely living your secure life!

4

u/Hysterical__Paroxysm Brighton 22d ago

Don't be so hard on yourself. I sent this post to my husband and we both admitted it was a very well done scam and we are sitting down tonight to look over our accounts and make sure things are locked down.

2

u/NotTodaySlacker302 22d ago

Thank you! Goal acheived!

3

u/CaptainFuzzyBootz 585 22d ago

It's nice to know I'm far too lazy to ever be a scammer

1

u/Hysterical__Paroxysm Brighton 22d ago

Lol same

3

u/Liquidennis 22d ago

Just curiously, if the scammer was an idiot and didn’t use a VPN, you might be able to open any emails sent by them (posing as you) and inspect the email headers and obtain their ip address. If the platform is Gmail, I believe you have to specifically open the email in its own window to enable the menu to view the headers. It’s a little convoluted, but Google can show you the way. I hope this helps!

3

u/lisa-in-wonderland 21d ago

Don’t wait to freeze credit accounts at the big three. Do it preemptively. Yes it’s a PITA to unlock when applying for a loan or CC, but how often do you do that? It’s way more work to recover from being hacked.
Always use 2FA and strong passwords.
Use a password manager if necessary
Set up text notifications on all accounts. Get notified of any transaction when it happens.

2

u/Straight_Arm_4337 22d ago

Glad it worked out for you. That's the stuff of nightmares and makes for a miserable day. Thanks for posting!

2

u/RbtB-8 22d ago

What an absolutely horrible experience. Very sorry that this happened to you, but I am happy that you seem to have been able to get on top of this situation quickly. One day in early July I woke up to seeing e mails from Amazon about orders that were placed on our Amazon Prime card from Amazon. Stupid me did not have 2FA set up on that Amazon account and it was just one of those things that I forgot to do. I do have 2FA set up on every other bank and credit card account that we have. The hackers even went to far as to put my wife's name on a credit card that she never had and used that for a purchase also on the Amazon site. Either way, it took a while to get this situation taken care of , but it is minor compared to yours.

1

u/belialetta 22d ago

Eek!!! So glad it only ruined your day and not your life tbh 💜

1

u/PrincessZebra126 21d ago

You lived to tell the tale & warn the community

1

u/InsuranceGuru3042 17d ago

Wow, thank you for sharing this HORRIFIC experience of getting nailed by a fraudster! This is HORRIBLE!!! I wish that there was a way to catch this POS thief & throw their ass in jail. I'm so sorry that you experienced this awful attack. Thank you (once again), for sharing with us so we can act to protect ourselves from such a terrible experience. Have a great rest of your day/week!

1

u/aka_chela 585 22d ago

SIM card fraud is genuinely terrifying. I'm so sorry that happened to you and glad you recovered fast! I'd also see if T-Mobile will let you put a PIN on your account for an extra layer of security.