Declan Harrington, a Massachusetts man charged two years ago for his alleged involvement in a series of SIM swapping attacks, pleaded guilty to stealing cryptocurrency from multiple victims and hijacking the Instagram account of others.
SIM swapping (aka SIM hijacking) attacks make it possible for malicious actors to take control of their targets’ mobile phone numbers by tricking or bribing employees of mobile phone service providers to reassign the numbers to attacker-controlled SIM cards.
This allows the crooks to completely take control of victims’ phone numbers and use them to bypass SMS-based multi-factor authentication (MFA), steal credentials, and hijack online accounts.
Harrington was charged with Eric Meiggs in November 2019 for targeting the owners of high-value (‘OG’ or ‘Original Gangster’) Instagram and Tumblr accounts.
They also went after cryptocurrency companies’ executives and several other targets with significant quantities of cryptocurrency in their Coinbase or Block.io wallets.
In all, through multiple SIM swapping attacks and death threats, the two defendants stole more than $530,000 worth of cryptocurrency from at least ten victims across the US and took control of multiple OG social media accounts.
Also Read: Lessons from PDPC Incident and Undertaking: August 2021 Cases
According to court documents, tactics and methods allegedly used by the two defendants during their attacks included:
Meiggs, Harrington’s co-conspirator, also pleaded guilty on April 28, 2021, and is scheduled to be sentenced next year, on May 24. A sentencing date for Harrington is yet to be scheduled by the Court.
The US Federal Trade Commission (FTC) issued guidance on how to protect against SIM swapping attacks in October, listing the following list of protection measures:
The FBI issued a SIM swapping alert with guidance on defending against such attacks after warning of an increase in the number of SIM jacking attacks.
Also Read: Data Minimization; Why Bigger is Not Always Better
The FTC also provides detailed guidance on how to secure personal information on your phone and keep personal info secure online.