HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

SIM Swapping Attacks Remain Unchecked by Default; Enable Carrier SIM Protection Settings

SIM‑swap fraud is on the rise, letting attackers seize phone numbers and intercept SMS‑based two‑factor codes. Major carriers offer optional SIM‑protection features that are off by default, creating a compliance gap for organizations that rely on SMS MFA. Enabling these settings aligns with SOC 2 access‑control requirements and provides audit‑ready evidence of mitigation.

LiveThreat™ Intelligence · 📅 August 08, 2026· 📰 zdnet.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
zdnet.com

Your Phone Doesn't Block SIM Swapping Attacks by Default: Turn on Carrier Settings Now

What Happened — SIM‑swap fraud has surged, allowing attackers to hijack a victim’s phone number, intercept SMS‑based two‑factor authentication (2FA) codes, and gain access to personal and corporate accounts. Major U.S. carriers (AT&T, T‑Mobile, Verizon) now offer optional “SIM Protection” or “Number Lock” settings that are off by default.

Why It Matters for Compliance & Audit Readiness

  • The scenario maps directly to SOC 2 CC6.1 (Logical Access) and CC6.2 (User Authentication) – controls designed to prevent unauthorized credential use.
  • Demonstrating that you’ve enforced carrier‑level SIM safeguards provides concrete, continuous evidence of due‑diligence for audit reviewers.
  • Incorporating these settings into your organization’s access‑control policy closes a common “out‑of‑band” attack vector that many compliance programs overlook.

Who Is Affected – Financial services, healthcare, SaaS providers, and any enterprise that relies on SMS‑based MFA for employee or customer authentication.

Recommended Actions

  • Enable carrier‑provided SIM protection (e.g., Verizon’s “SIM Protection” and “Number Lock”, AT&T’s “Account PIN”, T‑Mobile’s “SIM Card Lock”).
  • Update your access‑control policy to require carrier‑level SIM safeguards for all privileged accounts that use SMS 2FA.
  • Add SIM‑swap awareness to your security‑awareness training curriculum and test it in phishing simulations.

Source: ZDNet Security

Technical Notes – Attack vector: social engineering / stolen credentials; attackers convince carriers to re‑port numbers or bribe carrier staff. No CVE; the risk is procedural. Data at risk includes MFA tokens, personal identifiers, and any downstream systems that trust SMS 2FA. Source: same article

📰 Original Source
https://www.zdnet.com/article/your-phone-doesnt-block-sim-swapping-attacks-turn-on-carrier-settings/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Could you prove your access controls held up here?

Credential and access failures map directly to SOC 2 access-control criteria. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →