Hacker News new | ask | show | jobs
by Destitute 1768 days ago
There's not much you can confirm over the phone, except the account PIN and sometimes security hint. But an attacker can pretend to have forgotten it and press that the matter is urgent. If the attacker knows enough about the person, they might be able to convince an agent to make the swap so the agent can:

1) Get on with their day to maybe hit a support request quota 2) Make sure this person doesn't give them a bad customer satisfaction score

1 comments

You could require verifying your identity using your electronic ID if you want to simswap by calling the helpdesk.