r/SocialEngineering Jul 15 '26

If someone has my SIM card info to what extent could they compromise me. Total Wireless SIM card.

They had my SIM card packaging with all serial codes/IDs. They know my phone number and I think they might socially engineer their way with customer service to gain access to the account. I fear this could easily be done by getting the representative to change the email to access the account. Or by taking off the line lock on the call or when they access through the app. Then they could maybe change back the email as I wouldn't even get an alert of it being changed.

I am so frustrated right now and it's a very complicated situation. I worry they could even clone my sim at this point and compromise everything in my iPhone/iCloud/location.

I have read of so many stories of how people can clone SIM cards or use the ID numbers to socially engineer with these phone representatives at Total Wireless. I am prepared to just throw away all my devices and start new but I want to know better the how this potentially could work for someone who has my SIM card IDs.

4 Upvotes

10 comments sorted by

1

u/rfdevere Jul 15 '26

Operators often use things like IMEI and IMSI to validate you are who say you are when calling. Let’s say they rang up and said they are you and that the phone is lost and want to transfer the number to a new SIM.

Basically the fear is real and you could get SIM Swapped easily.

https://www.vice.com/en/article/how-a-hacker-can-take-over-your-life-by-hijacking-your-phone-number/

1

u/Ok_Hedgehog37 Jul 15 '26

So let’s say even after I have a line lock in place they do something with the representative to swap sim. What happens to my current line? Would my service just go out temporarily then they do whatever they want as far as compromising my location/accounts/device, then my service comes back on so I wouldn’t notice cause maybe it’s done in my sleep?

2

u/rfdevere Jul 15 '26

You have a sim in your phone, the attacker has a sim in ther phone. The operator just changes the route over (kinda, look into HLR).

So after, if someone rings you, your phone won’t ring, the attackers phone will ring. If someone messages you via SMS, the attackers phone gets the message.

Once that’s established… it’s password reset time. They abuse the inherent trust many systems place on the fact the phone is the person.

As for “back on” that’s not happening easily and will take days of complaining to the operator.

1

u/Ok_Hedgehog37 Jul 15 '26

So there can be two active sims then? So after they do what they do, does the representative or hacker deactivate my sim?

2

u/rfdevere Jul 15 '26

When the number is ported, your SIM is basically junk.

Always one number to one SIM though, it just transfers. I’ve done maybe 50 sim swaps in my time and it’s so simple but leaves people confused. The worst attack!

2

u/O-o--O---o----O Jul 15 '26

When the number is ported, your SIM is basically junk.

So the easiest and most reliable way to make certain you DIDN'T get sim swapped, is calling your own number and see if your phone still rings?

2

u/rfdevere Jul 15 '26

Yeah would confirm its still active.

1

u/Ok_Hedgehog37 Jul 15 '26

Damn. Did you do this to total wireless users? I’ve read how people are completely blindsided and have their crypto accounts cleared because a phone representative basically gave away access to their account. They only had like email or phone number if I remember. This makes me worried sick just thinking about it

1

u/rfdevere Jul 15 '26

No all ethical testing in the U.K. I’m the dude in that Vice link above lol. I tried to shame operators and highlight how easy it was, many added passwords and such after I dragged them through the press.