News: 0158060931

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Verizon's TracFone Customers Complain of Attackers Stealing Their Phone Numbers (wsj.com)

(Wednesday January 26, 2022 @05:50PM (msmash) from the security-woes dept.)


Attackers have commandeered thousands of TracFone customers' phone numbers in recent weeks, forcing new owner Verizon Communications to improve safeguards less than two months after it took over the prepaid wireless provider. From a report:

> TracFone offers prepaid wireless service under several brands, including Straight Talk, Total Wireless and its namesake brand. Some customers of Straight Talk said they found their phone lines [1]suddenly disconnected around the December holidays . "We were recently made aware of bad actors gaining access to a limited number of customer accounts and, in some cases, fraudulently transferring, or porting out, mobile telephone numbers to other carriers," TracFone said in a notice posted on its website this month. In some cases, customers said they discovered their lines had been moved without their permission to Metro, a unit of T-Mobile US. A T-Mobile spokeswoman said the company investigated and found "no fraud or data breach of any sort" on its side. The company added that such unauthorized transfers "are unfortunately an industrywide issue."

>

> Verizon, which acquired TracFone in late November in a $6.25 billion deal, said it had added security protections to the recently acquired services to prevent such fraudulent transfers. For instance, the prepaid operators will now send customers a text message notification when a transfer request is made. A Verizon spokeswoman said the attack appeared to affect about 6,000 TracFone customers, a fraction of Verizon's roughly 24 million prepaid lines. "We have no reason to think that this was caused by anybody on the inside," the spokeswoman said. "You've got the bad actors out there constantly trying to find points of weakness," Matt Ellis, Verizon's finance chief, said Tuesday in an interview. "We've addressed that weakness."



[1] https://www.wsj.com/articles/tracfone-customers-complain-of-unwanted-phone-number-swaps-11643205624



Verizon PR (Score:3)

by freeze128 ( 544774 )

If Verizon has "added security protections to the recently acquired services to prevent such fraudulent transfers", then why are the fraudulent transfers still taking place?

Re: (Score:2)

by JackieBrown ( 987087 )

I think it was a tense error in the summary, It seems like this was added after the transfer.

Portout Pin is VM Password - VM PW is last 4 of # (Score:1)

by LovelessOhio ( 9270451 )

Tracfone's port out pin is the VM password. By default the VM PW is the last 4 digits of the phone number. Even if the VM pin is set to a custom value, unless the customer specifically enables the option to "always ask for password" - an attacker can just spoof his caller ID to match the target phone number and he will be dropped right into the voicemail system where he can than - change the VM and thus the Port Out Pin. ....the more you know

">So what is The Big Difference(tm) that make file streams
>so much better than directories and so much different?

I'll talk really slowly."

- Linus Torvalds