San Francisco Chronicle

Phone numbers let hackers get to wallets

- By Nathaniel Popper

“I got the cold sweat and was like, ‘OK, this is really serious.’ ” Chris Burniske, a virtual currency investor who lost control of his phone number last year

Hackers have discovered that one of the most central elements of online security — the mobile phone number — is also one of the easiest to steal.

In a growing number of online attacks, hackers have been calling up Verizon, TMobile, Sprint and AT&T and asking them to transfer control of a victim’s phone number to a device under the control of the hackers.

Once they get control, they can reset the passwords on every account that uses the phone number as a security backup — as services like Google, Twitter and Facebook suggest.

“My iPad restarted, my phone restarted and my computer restarted, and that’s when I got the cold sweat and was like, ‘OK, this is really serious,’ ” said Chris Burniske, a virtual currency investor who lost control of his phone number late last year.

A wide array of people have complained about being successful­ly targeted by this sort of attack, including a Black Lives Matter activist and the chief technologi­st of the Federal Trade Commission. The commission’s own data shows that the number of phone hijackings has been rising. In

January 2013, there were 1,038 such incidents reported; by January 2016, that number had increased to 2,658.

But a particular­ly concentrat­ed wave of attacks has hit those with the most obviously valuable online accounts: virtual currency fanatics like Burniske.

Within minutes of getting control of Burniske’s phone, his attackers had changed the password on his virtual currency wallet and drained the contents — some $150,000 at today’s values.

Most victims in the virtual currency community have not wanted to acknowledg­e it publicly for fear of provoking their adversarie­s. But in interviews, dozens of prominent people in the industry acknowledg­ed that they had been victimized in recent months.

“Everybody I know in the cryptocurr­ency space has gotten their phone number stolen,” said Joby Weeks, a bitcoin entreprene­ur.

Weeks lost his phone number and about $1 million worth of virtual currency late last year, despite having asked his mobile phone provider for additional security after his wife and parents lost control of their phone numbers.

The attackers appear to be focusing on anyone who talks on social media about owning virtual currencies or anyone who is known to invest in virtual currency companies, such as venture capitalist­s. And virtual currency transactio­ns are designed to be irreversib­le. Accounts with banks and brokerage firms are not as vulnerable to these attacks because these institutio­ns can usually reverse unintended or malicious transactio­ns if they are caught within a few days.

But the attacks are exposing a vulnerabil­ity that could be exploited against almost anyone with valuable emails or other digital files — including politician­s, activists and journalist­s.

Last year, hackers took over the Twitter account of DeRay Mckesson, a leader of the Black Lives Matter movement, by first getting his phone number.

In a number of cases involving digital money aficionado­s, the attackers have held email files for ransom — threatenin­g to release naked pictures in one case, and details of a victim’s sexual fetishes in another.

The vulnerabil­ity of even sophistica­ted programmer­s and security experts to these attacks sets an unsettling precedent for when the assailants go after less technologi­cally savvy victims. Security experts worry that these types of attacks will become more widespread if mobile phone operators do not make significan­t changes to their security procedures.

“It’s really highlighti­ng the insecurity of using any kind of telephone-based security,” said Michael Perklin, chief informatio­n security officer at the virtual currency exchange ShapeShift, which has seen many of its employees and customers attacked.

Mobile phone carriers have said they are taking steps to head off the attacks by making it possible to add more complex personal identifica­tion numbers, or PINs, to accounts, among other steps.

But these measures have not been enough to stop the spread and success of the culprits.

After a first wave of phone porting attacks on the virtual currency community last winter, which was reported by Forbes, their frequency appears to have ticked up, Perklin and other security experts said.

In several recent cases, the hackers have commandeer­ed phone numbers even when the victims knew they were under attack and alerted their cell phone provider.

Adam Pokornicky, a managing partner at Cryptochai­n Capital, asked Verizon to put extra security measures on his account after he learned that an attacker had called in 13 times trying to move his number to a new phone.

But just a day later, he said, the attacker persuaded a different Verizon agent to change Pokornicky’s number without requiring the new PIN.

A spokesman for Verizon, Richard Young, said that the company could not comment on specific cases, but that phone porting was not common.

“While we work diligently to ensure customer accounts remain secure, on occasion there are instances where automated processes or human performanc­e falls short,” he said. “We strive to correct these issues quickly and look for additional ways to improve security.”

Perklin and other people who have investigat­ed recent hacks said the assailants generally succeeded by delivering sob stories about an emergency that required the phone number to be moved to a new device — and by trying multiple times until a gullible agent was found.

“These guys will sit and call 600 times before they get through and get an agent on the line that’s an idiot,” Weeks said.

Coinbase, one of the most widely used bitcoin wallets, has encouraged customers to disconnect their mobile phones from their Coinbase accounts.

But some customers who have lost money have said the companies need to take more steps by doing things like delaying transfers from accounts on which the password was recently changed.

“Coinbase looks like a bank, stores millions of dollars like a bank, but you don’t realize how weak its default protection­s are until you are robbed of thousands of dollars in minutes,” said Cody Brown, a virtual reality developer who was hacked in May.

 ?? Matthew Staver / New York Times ?? Joby Weeks, a bitcoin entreprene­ur, lost his phone number and had about $1 million worth of virtual currency stolen last year.
Matthew Staver / New York Times Joby Weeks, a bitcoin entreprene­ur, lost his phone number and had about $1 million worth of virtual currency stolen last year.
 ?? Kevin Hagen / New York Times ?? Hackers swipe phone numbers, then reset passwords on accounts using that number as a security backup.
Kevin Hagen / New York Times Hackers swipe phone numbers, then reset passwords on accounts using that number as a security backup.

Newspapers in English

Newspapers from United States