SecureWorld Webinar: Why Password Managers Fail to Secure and How You Can Take Back Control
Watch Now

MFA Cannot Stand Alone Series: The Risks of SIM Swapping

CTO & Co-Founder at Unixi

Multi-Factor Authentication (MFA) is widely recognized for enhancing security by requiring at least two forms of verification: usually something you know (such as a password) and something you have (typically a mobile device). This method undoubtedly complicates a hacker’s job by necessitating the breach of two security barriers instead of one. However, MFA is not foolproof. It inherently possesses vulnerabilities and can instill a false sense of security among users. This phenomenon is similar to the risk compensation behavior observed in individuals wearing safety helmets while cycling, they may take greater risks, assuming they are well-protected.

What Is SIM Swapping?

SIM swapping is an attack in which a hacker transfers a victim’s phone number to a SIM card the hacker controls, redirecting the victim’s SMS-based MFA codes straight to the attacker. It emerges as a significant threat by exploiting these vulnerabilities in MFA: once the transfer is complete, all MFA prompts intended for the victim go to the hacker instead, effectively bypassing MFA protections. There are three primary methods through which SIM swapping can be executed:

  • Social engineering to convince the provider to redirect mobile traffic.
  • Collusion with an insider within the mobile service provider.
  • Interception of SMS communications, which can be achieved through digital or physical means.

High-Profile Incidents: The Case of Lapsus$

The cybercriminal group Lapsus$ has notoriously utilized SIM swapping to penetrate the defenses of major corporations. Their sophisticated attacks have targeted companies like NVIDIA, Microsoft, and Okta, leading to significant data breaches and security lapses:

  • NVIDIA: Lapsus$ accessed internal systems and extracted 20 GB of sensitive data, including hardware schematics and employee credentials.
  • Microsoft: The group infiltrated Microsoft’s network, gaining access to vital source code.
  • Okta: By controlling a support engineer’s device through SIM swapping, Lapsus$ potentially compromised the data of numerous Okta customers.

These incidents highlight the critical need for robust security measures that extend beyond MFA to effectively counter attacks that circumvent MFA protection.

Enhancing Security with Unixi

To address these vulnerabilities, Unixi offers a comprehensive solution that integrates MFA with additional security layers, rendering a wide range of attacks obsolete. Unixi’s Universal Single Sign-On (USSO) not only implements MFA in a click of a button but also adds additional credential protection mechanisms, ensuring a higher level of security for applications. This approach not only mitigates the risks associated with SIM swapping but also enhances the overall security posture of companies, safeguarding sensitive data against sophisticated cyber threats.

In conclusion, while MFA is a valuable security tool, it cannot stand alone. The evolving tactics of cybercriminals, such as those employed by Lapsus$, necessitate a more integrated and robust approach to security. By adopting comprehensive solutions like Unixi’s USSO, organizations can protect themselves against the multifaceted threats posed by SIM swapping and other sophisticated cyber-attacks.

FAQs

What is SIM swapping and how does it bypass MFA?

SIM swapping is a scam where an attacker convinces or bribes a mobile carrier into transferring a victim's phone number to a SIM card the attacker controls. Once that's done, SMS-based MFA codes intended for the victim go straight to the attacker, letting them bypass that layer of authentication entirely.

How can hackers execute a SIM swap attack?

There are three common methods: social engineering a mobile carrier's support staff into approving the transfer, colluding with an insider at the carrier, or intercepting SMS traffic directly through technical or physical means.

Was SIM swapping the cause of the Lapsus$ breaches at NVIDIA, Microsoft, and Okta?

Not exactly. SIM swapping was one of several tactics Lapsus$ used across its campaigns - alongside stolen credentials, insider recruitment, and MFA-fatigue attacks, but it wasn't necessarily the specific method used in each of these three breaches. Here's what happened in each case:

  • NVIDIA: Employee credentials and proprietary data were stolen. Lapsus$ claimed to have taken 1TB of data and leaked a 20GB sample publicly.
  • Microsoft: Attackers gained access to internal source code.
  • Okta: The exposure didn't come from Okta directly, it came from a breach at a third-party support partner (Sitel), which gave Lapsus$ limited access to some Okta customer data.

The bigger takeaway: SIM swapping remains a real and effective way to defeat SMS-based MFA, even if it wasn't confirmed as the specific vector in all three of these headline cases.

Why is MFA not enough to stop SIM swapping and similar attacks?

MFA can create a false sense of security, similar to how helmet use can lead cyclists to take more risks. If SMS is the second factor, a successful SIM swap redirects that verification straight to the attacker, defeating MFA's core purpose without the user or often the company knowing.

How does Unixi help protect against MFA weaknesses like SIM swapping?

Unixi's Universal Single Sign-On (USSO) layers additional credential protection on top of MFA, rather than relying on SMS-based verification alone. This reduces exposure to SIM-swap-style attacks and other techniques that exploit MFA's inherent gaps.

Reuvein Vinokurov

CTO & Co-Founder at Unixi

Reuvein Vinokurov is the co-founder and CTO of Unixi, where he directs the platform’s core architectural vision and technical innovation. He brings deep enterprise engineering and offensive security expertise, having previously served as VP of Efficiency & Innovation at HUB Security and Offensive Security Team Leader at Comsec. With years of hands-on experience developing advanced automation tools and leading red-team simulations, Reuvein designed Unixi’s proprietary decentralized architecture to achieve 100% single sign-on coverage at the interaction layer. His mission is to dismantle the underlying mechanics of identity theft and credential exposure, turning unmanaged SaaS blind spots into ironclad enterprise security barriers.

Explore more