Your Smartphone Is the New Target for Fraudsters | Capital One (2024)

    February 28, 2019 |7 min read

    How to protect yourself (and your accounts) from a “SIM swap”

    February 28, 2019 |7 min read

      Protecting your various accounts from fraudsters and hackers is a necessity in an increasingly digital world. Complex passwords and password managers can help, but fraudsters are constantly developing new ways to steal your personal information. And one of the newest ways involves your smartphone’s SIM card.

      What is a SIM Card?

      Your SIM card is a small chip inside your phone that identifies you as the phone’s owner. It contains unique information that allows the device to communicate with the mobile network, and it tells your carrier that the phone belongs to you.

      Essentially, the SIM card is what makes your phone a phone, and not just a glorified media device. Without the SIM card, the device would still work, but you wouldn’t be able to make phone calls, send or receive text messages, or connect to your carrier’s data network.

      Why Your SIM Card Puts You at Risk

      Recently, a security control called two-factor authentication (sometimes shortened to 2FA) became the standard for safeguarding personal data. It typically works like this:

      1. You sign in to an account with your username and password.
      2. A text message with a one-time passcode is sent to your cellphone.
      3. You enter that code into your account to complete sign-in.

      Your SIM card is what allows two-factor authentication to work with your cellphone, because it ties you to your device. This process verifies that your login attempt is authentic by adding a second security check—connected to the device in your pocket.

      This was once considered the safest method of fraud protection. And it’s often safer than email verification because, in reality, a large percentage of people still use the same passwords across multiple accounts.

      The problem? Now that two-factor authentication commonly relies on cellphones, your phone number is a prime target for fraudsters.

      How Fraudsters Steal Your Phone Number: The “SIM Swap”

      Fraudsters attempting a SIM swap call your phone carrier, pretending to be you. They tell customer service that their phone was lost or damaged, and that they need the number associated with your SIM card transferred to a different SIM card—one in their possession.

      Wondering how a fraudster convinces someone they’re you? Ask yourself this: How hard is it to find your birthday on the internet right now? Or your phone number? Or even your home address? And how much information are you voluntarily sharing on social media?

      If they’re able to convince customer service they’re you, your number is transferred. It’s now linked to their device, not yours. You’ll stop receiving calls and texts, but other elements of your phone will still work. If you’re on Wi-Fi, you can still browse the internet—which might increase the time it takes to notice your phone is no longer connected to the mobile network.

      And How They Access Your Online Accounts

      Once the fraudster has access to your phone number, they can target your bank, credit card or any other account that may send a security code by text message during two-factor authentication. When they try to sign in to your account, the code is sent as a text to their device, not yours.

      Once the fraudster passes two-factor authentication and signs in, they have full access to your account—meaning they can transfer a balance or order a new credit card.

      While your credit card company or bank may take care of the fraudulent charges, you’ll still need to deal with the hassles and anxiety of reporting the fraud, getting new cards, and wondering whether other accounts are compromised.

      4 Steps to Protect Yourself from a SIM Swap

      SIM swapping is a serious concern, so taking the time to add extra security to your accounts is important. You can protect yourself with these simple steps:

      1. Set a passcode with your carrier. Fraudsters can’t use your (potentially compromised) personal information to verify your identity if they also need a passcode. Doing this is usually free and a no-brainer.
      2. Use other two-factor authentication options tied to your device. Not all two-factor authentication options rely on your phone number. For example, downloading the Capital One® Mobile app gives you the option to pass two-factor authentication simply by logging in.
      3. Contact your carrier if your phone stops receiving calls. This could be a sign of a SIM swap, so call your carrier as soon as possible. Also, check your financial accounts to make sure nothing has been compromised.
      4. Learn about fraud protection provided by your financial institutions. Many of them will work with you to resolve your claims or offer some sort of fraud liability guarantee. For example, Capital One offers $0 fraud liability on credit cards—so if your credit card or credit card number is lost or stolen, you won’t be on the hook for fraudulent charges.

      A SIM swap is a real threat to your financial life, but you can help protect yourself if you follow the steps outlined above. By taking a few simple measures, you can do your part to stop fraudsters in their tracks.

      Pranav Khanna, Vice President, Product Management

      Pranav Khanna leads a team that helps customers detect and recover from fraud on their credit card. His team also builds the technology infrastructure for machine learning-based fraud defenses. He has been with Capital One for 10 years and lives in the Washington, D.C., area with his wife and two children.

      We hope you found this helpful. Our content is not intended to provide legal, investment or financial advice or to indicate that a particular Capital One product or service is available or right for you. For specific advice about your unique circ*mstances, consider talking with a qualified professional.

      February 28, 2019 |7 min read

      Related Content

      article | September 20, 2022 | 8 min read

      article | October 8, 2019 | 7 min read

      article | October 28, 2018 | 4 min read

      Your Smartphone Is the New Target for Fraudsters | Capital One (2024)

      FAQs

      Who is 1 888 464 0727? ›

      If a transaction on your bank account doesn't look quite right and you confirmed it wasn't made by you or another authorized user on your account—contact us immediately by calling 1-888-464-0727.

      Why is Capital One asking me to verify my identity? ›

      Capital One takes security seriously and fights hard to prevent identity theft, which protects both of us. To confirm your identity, we need information from a number of sources. This sometimes means sharing your information (e.g. name, address) with limited third parties solely for fraud prevention services.

      How do I know if a text from Capital One is real? ›

      Verify the SMS texts or emails are coming from the usual Capital One email domain and short code (a 5 or 6 digit phone number that is used to send text messages at scale). Resist the pressure to act immediately.

      How to bypass Capital One phone verification? ›

      Capital One account — Registration process

      Providing most of this information is mandatory, and using fake information is not possible. If you're wondering how to verify a Capital One account without a phone number, it's not possible. The only true solution would be to use a virtual phone number to register.

      What number is 866 464 7761? ›

      Capital One "Customer Protection" direct line: 866-464-7761 or visit their website. Chime customer support: (844) 244-6363.

      Who is 800 227 4825? ›

      Otherwise, contact Capital One using the number on the back of your card or at: 1-800-227-4825.

      Is 227898 Capital One? ›

      You're all set! Start chatting with Eno by sending a text message to 227-898. Message and data rates may apply. For terms and privacy information, click here.

      Will Capital One ask for my Social Security number? ›

      Some issuers require a Social Security number (SSN) as proof of identity. An individual taxpayer identification number (ITIN) may also be accepted. Capital One asks for your full name, date of birth, SSN, physical address and estimated gross annual income.

      Why can't my identity be verified online? ›

      You did not enter a SSN on your form. You have a limited credit history. You are the victim of identity theft. You have a security freeze on your credit.

      Will Capital One ever text you? ›

      Add your mobile phone number to your account to automatically get alerts if Capital One notices potential suspicious activity on your account. Capital One will text you from the same number every time so you'll know it's not a fraudster.

      What happens if I lock my Capital One credit card? ›

      When you lock your Capital One credit card, most, but not all, purchases will be blocked. Locking your credit card will block any new or pending transactions, but it won't stop recurring or previously authorized charges from processing.

      Why does Capital One want access to my phone? ›

      This permission allows us to use unique phone information (SIM ID and phone number) to guard against unusual sign-in activity. It's a little extra security to help protect your money.

      Can I get a verification code without phone? ›

      Use online services: There are websites that provide temporary or disposable phone numbers that can be used for verification purposes. These numbers can be used to receive SMS verification codes. Some popular websites for this purpose include SMS-Man, freeSMSverification.com, felixmerchant.com, and more [2].

      Is the Capital One Mobile app secure? ›

      The Capital One Mobile app uses a number of security features to help protect your account. These security measures include two-step authentication, real-time fraud and purchase alerts and a card lock feature that allows you to block others from using your stolen or misplaced card.

      What is the 888 number spam? ›

      Answering an unknown 888 number could put you in contact with a legitimate company — but it could also open you up to serious risks like identity theft, financial fraud, and hacking. Some of the potential consequences of interacting with an 888 scam caller include: You could become the victim of identity theft.

      How can I check if a phone number is spam? ›

      One way to check if a number is potentially a scam is to use a reverse phone number lookup service. These websites and apps allow you to enter a number and see public information associated with it, such as the registered name, location, and carrier.

      How do I know who a number belongs to? ›

      There are many websites and apps that offer reverse phone lookup services. These services can help you identify the owner of a phone number, as well as their address, email address, and social media profiles. Some popular reverse phone lookup services include: Whitepages, AnyWho, Zaba, Truecaller, BeenVerified.

      Top Articles
      Latest Posts
      Article information

      Author: Lidia Grady

      Last Updated:

      Views: 5969

      Rating: 4.4 / 5 (45 voted)

      Reviews: 84% of readers found this page helpful

      Author information

      Name: Lidia Grady

      Birthday: 1992-01-22

      Address: Suite 493 356 Dale Fall, New Wanda, RI 52485

      Phone: +29914464387516

      Job: Customer Engineer

      Hobby: Cryptography, Writing, Dowsing, Stand-up comedy, Calligraphy, Web surfing, Ghost hunting

      Introduction: My name is Lidia Grady, I am a thankful, fine, glamorous, lucky, lively, pleasant, shiny person who loves writing and wants to share my knowledge and understanding with you.