SIM Swap & Account Takeover
Articles on SIM swap attacks, one-time password interception, account takeover techniques, and defensive measures for consumers and enterprises.
How Attackers Broke Dashlane’s 2FA — And Why Your Master Password Still Matters
Dashlane disclosed a coordinated campaign in which attackers abused device-registration API endpoints to brute-force one-time 2FA codes across thousands of user accounts simultaneously. The attack successfully generated valid tokens for fewer than 20 personal-plan customers, allowing encrypted vault downloads — though master passwords protected by Argon2 hashing likely remain secure.
One-Time Passwords Are No Longer Secure: How SIM Swaps Enable Account Takeovers and What to Do About It
SIM swap attacks are increasingly used to intercept one-time passwords and hijack accounts—exploiting trust in telecom infrastructure. A recent Polish law enforcement operation revealed how international cybercriminals steal millions in cryptocurrency via SIM swapping, highlighting gaps carriers still haven’t fixed.