, , , , , , ,

Google Fi hack victim had Coinbase, 2FA app hijacked by hackers

On January 1, a technologist who goes by the nickname regexer received an email saying he had successfully reset his account at the crypto exchange Coinbase.

Unfortunately — and worryingly — he had actually not requested a password reset. Regexer, who asked to be referred to by his online moniker for fear of being targeted by hackers again, quickly realized he was being hacked, and his attempts to log into his Coinbase to regain control were unsuccessful.

Soon after, he noticed he had no cell phone service. Then, his two-factor app, Authy, notified him that a new device was added to his account. After the hackers took control of regexer’s cell phone service, the hackers were able to reset the passwords on his accounts and intercept two-factor SMS messages. That allowed the hackers to take control of Authy, giving them the ability to use the 2FA codes created by the app, according to regexer.

This gave them a chance to break into even more accounts owned by regexer.

“Now I don’t know what the hell is going on. I am totally owned,” regexer told TechCrunch, recalling the incident.

Unsure what to do, regexer started changing passwords on his other important accounts that had apparently not been compromised yet. Then, on a whim, he started turning airplane mode on and off on his iPhone. Somehow, after a few attempts, his cellphone service was restored.

Regexer isn’t sure if turning airplane mode on and off is what stopped the attack but he is glad that happened.

For weeks, regexer had no idea how he had been hacked. Then, on Monday, he received an email from his cell phone provider, Google Fi, informing him and all other customers that hackers had stolen some customers’ information, likely connected to the recent breach at T-Mobile.

Unlike for other customers, the email regexer received contained more detailed information about the hack he suffered weeks prior.

“Other data related to your Google Fi account also may have been accessed without authorization, such as a zip code, and the service/emergency address associated with your account,” read the email, which regexer shared with TechCrunch. “Additionally, on January 1, 2023 for about 1 hour 48 minutes, your mobile phone service was transferred from your SIM card to another SIM card. During the time of this temporary transfer, the unauthorized access could have involved the use of your phone number to send and receive phone calls and text messages. Despite the SIM transfer, your voicemail could not have been accessed. We have restored Google Fi service to your SIM card.”

Regexer said he has talked to two Google Fi customer representatives trying to figure out more details about what happened, but neither of them told him anything. And, interestingly, regexer didn’t see any evidence that his Google account, which is tied to the Google Fi account, was compromised. It’s unclear how the hackers were able to perform the SIM swap.

Google has not responded to a request for comment. And it’s not yet known if there were other people, or how many, specifically targeted by hackers the way regexer was.

Once he regained control of this online life, regexer investigated the hack and found out the hackers had also taken over his Outlook email account, and — smartly — in an effort to hide their actions, deleted the emails informing of the password reset.

Even though nothing else happened since January 1, regexer is still worried and is calling on Google to disclose more information.

“The main thing I’d like to know is whether I and others are still vulnerable, and if there’s anything we can do to protect ourselves. I’d love to know more details about the mechanisms that were used for the phone number takeover because that will shed light on the level of ongoing vulnerability and methods for defense, as well as whether SMS two-factor remains better than no two-factor at all. (I can replace SMS for some online accounts, but not all. Many banks and others only allow two-factor via SMS.) I’d also love to know how many people had their phone numbers hijacked in connection with the breach, and, if it was a small subset, was there any reason that we in particular were targeted,” regexer said.

“So unless Google sheds more light on the attack there is a big open question about how vulnerable people’s phone numbers now are.”


Are you a Google Fi subscriber that was also a victim of a similar attack? Did you also get a personalized notification from the company about the hack against you? We’d love to hear from you. You can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Wickr, Telegram and Wire @lorenzofb, or email lorenzo@techcrunch.com.

Google Fi hack victim had Coinbase, 2FA app hijacked by hackers by Lorenzo Franceschi-Bicchierai originally published on TechCrunch

https://techcrunch.com/2023/02/01/google-fi-hack-victim-had-coinbase-2fa-app-hijacked-by-hackers/


October 2024
M T W T F S S
 123456
78910111213
14151617181920
21222324252627
28293031  

About Us

Welcome to encircle News! We are a cutting-edge technology news company that is dedicated to bringing you the latest and greatest in everything tech. From automobiles to drones, software to hardware, we’ve got you covered.

At encircle News, we believe that technology is more than just a tool, it’s a way of life. And we’re here to help you stay on top of all the latest trends and developments in this ever-evolving field. We know that technology is constantly changing, and that can be overwhelming, but we’re here to make it easy for you to keep up.

We’re a team of tech enthusiasts who are passionate about everything tech and love to share our knowledge with others. We believe that technology should be accessible to everyone, and we’re here to make sure it is. Our mission is to provide you with fun, engaging, and informative content that helps you to understand and embrace the latest technologies.

From the newest cars on the road to the latest drones taking to the skies, we’ve got you covered. We also dive deep into the world of software and hardware, bringing you the latest updates on everything from operating systems to processors.

So whether you’re a tech enthusiast, a business professional, or just someone who wants to stay up-to-date on the latest advancements in technology, encircle News is the place for you. Join us on this exciting journey and be a part of shaping the future.

Podcasts

TWiT 999: Bananas and Browsers – CA AI Bill Veto, Meta's Orion, FTC Vs. Fake Reviews This Week in Tech (Audio)

CA AI Bill Veto, Meta's Orion, FTC Vs. Fake Reviews Sam Altman's AI Manifesto News from Meta Connect Gavin Newsom vetoes sweeping AI safety bill, siding with Silicon Valley The Panel discusses CoPilot The Panel debates AGI James Cameron Joins Board of Stability AI in Coup for Tech Firm SAG-AFTRA Calls Strike Against 'League of Legends' Rabbit says only 5,000 people use the R1 daily Orion: True AR Glasses Have Arrived AI smackdown: How a new FTC ruling just protected the free press DoNotPay has to pay $193K for falsely touting untested AI lawyer, FTC says Firefox Review Checker – Ensure review authenticity in your online shopping New California law requires one-click subscription cancellations The DOJ sues Visa for locking out rival payment platforms NIST proposes barring some of the most nonsensical password rules Some Mad Genius Put ChatGPT on a TI-84 Graphing Calculator 23andMe troubles, company recently settled data insecurity suit for $30 mil Host: Leo Laporte Guests: Denise Howell, Parmy Olson, Daniel Rubino, and Henry Laporte Download or subscribe to this show at https://twit.tv/shows/this-week-in-tech Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit Sponsors: lookout.com 1password.com/twit shopify.com/twit veeam.com flashpoint.io
  1. TWiT 999: Bananas and Browsers – CA AI Bill Veto, Meta's Orion, FTC Vs. Fake Reviews
  2. TWiT 998: Artisanal Locally-Sourced Dopamine – Amazon Returns to Office, CA AI Bill, Elon Backs Down
  3. TWiT 997: Put an OLED on it – iPhone Event 2024, $700 PS5, AI in AU
  4. TWiT 996: The Quiet Office Crackdown – Starlink Backtracks, AI Royalty Heist
  5. TWiT 995: The Story of Us – AnandTech Shuts Down, Brazil Bans X, Alexa Revamp