SIM attacks

Ability of an attacker to gain unauthorized access to a DFS user's SIM card.

Affected entity: MNO

Risk: SIM takeover and unauthorized transactions

  • Vulnerability: Inadequate controls for user identification and verification before SIM swap and SIM recycling (SD: Authentication)

  • Vulnerability: Inadequate controls for user identification and verification before SIM swap and SIM recycling (SD: Authentication)

Risk: Unauthorized access to user's mobile DFS data o

  • Vulnerability: Mobile device theft (SD: data confidentiality)

Risk: Loss of access to accounts or reputational damage.

  • Vulnerability: Inadequacies in SIM swap and recycling process[ii] (SD: data integrity)

Last updated