My Mom just had her phone number and email account stolen

Please verify my answer but you have to know the passcode or facial recognition to get into the phone. Before reset.
My Mom never lost her physical phone. It just stopped working when the number was stolen, and her number was added to a scammer's phone.
 
So an iPhone can't be factory reset ?
My Mom has an IPhone, so I don't think that's the solution.

I was asking: Could a bad person take an iPhone and reset it so they could then get phone calls and text without having to know the PIN / facial recognition.

I wasn't suggesting any solution.
 
Port out protection, aka sim lock or number lock appears to be executed at the account level not the physical phone level, my mistake. Also, there's a find my device feature on most phones it's very handy to set up and be familiar with. If my phone were suddenly stolen it would take me a few minutes to dig into my brain to figure out what to do, but I have set up the ability to literally walk and factory reset my phone and wipe all data. If I can do it fast enough I can prevent the phone from being taken offline which is usually the first thing someone does when they steal a phone. My goal is to actually have a second phone and keep it cloned to my original phone except for the number, in case my main phone is ever stolen I have the second phone for the true Factor authentication and such. I have a pretty scary months long story that I'll post later where my home PC was literally remotely taken over, most keyboard and all and I happen to catch it but I'm also a web designer and my server was packed, and I'm at the point where I'm getting attempted credit card openings about every 20 minutes around the clock for the last 90 days. I'll give you the rundown on all my efforts to batten down the hatches. It went from being here racing to kind of fun Believe it or not. I'm a little sick that way!
 
I'm sorry to hear about your mom's experience.

For some reason, this NYTimes article did not offer a gift link, but maybe they think it is important enough to make public. It's about passkeys:


Let me know if you hit a paywall, and I will see if I can find the gift link.
I was able to read the article - great info. I have been avoiding creating passkeys for the reasons noted in the article.

The hurdle I need to solve is creating a passkey on one device say my iPad, and then my DH wants to login to Amazon on his iPhone. The article notes some companies have multiple passkeys allowed for you. We used LastPass manager, need to learn if it stores multiple passkeys are allowed.

As the author notes the old memory bank of which companies have I created. Passkey on it another hurdle to jump.
 
I apologize if this is repetitive as I didn't read every post above. I believe you can protect your cell phone account with an extra passcode (which you should do) and separately there is a sim lock on your phone. My understanding is the sim lock on your phone comes with a default that each carrier has. So for example T-Mobile is 1234. You change that to 4 digits that you'll remember. However, key point don't forget it because when you turn your phone off and back on you'll need both your regular phone passcode AND your sim passcode. I am led to believe this is good protection but I am not an expert. Good luck to us all!
 
I apologize if this is repetitive as I didn't read every post above. I believe you can protect your cell phone account with an extra passcode (which you should do) and separately there is a sim lock on your phone. My understanding is the sim lock on your phone comes with a default that each carrier has. So for example T-Mobile is 1234. You change that to 4 digits that you'll remember. However, key point don't forget it because when you turn your phone off and back on you'll need both your regular phone passcode AND your sim passcode. I am led to believe this is good protection but I am not an expert. Good luck to us all!
We discussed it, but it can't be repeated enough. Everyone should do this, but you better remember it. Consumer Cellular has an extra "account PIN" which they do not publicize. If you turn it on, they won't talk to you if you can't produce it, and you have to talk to them to port out. Resetting it involves sending in something through US Mail or FAX. Highly resistant to SIM swap hackers.
 
So about those passkeys.

I'm flummoxed.

I guess I've been retired from tech too long. I don't get passkeys. I tried them, and it turned into a mess when trying to use my desktop. I like my desktop.

Passkeys seem very phone focused. I don't like to do my heavy lifting on the phone.

I'm going to let passkeys mature a bit more before I try them again. This attitude of mine may be a sign of the beginning of the end for me.
 
So about those passkeys.

I'm flummoxed.

I guess I've been retired from tech too long. I don't get passkeys. I tried them, and it turned into a mess when trying to use my desktop. I like my desktop.

Passkeys seem very phone focused. I don't like to do my heavy lifting on the phone.

I'm going to let passkeys mature a bit more before I try them again. This attitude of mine may be a sign of the beginning of the end for me.
They also work on tablets - iPads. I no longer have a desktop and haven’t since 2019. I do my work on the iPad where access is via my fingerprint.
 
They also work on tablets - iPads. I no longer have a desktop and haven’t since 2019. I do my work on the iPad where access is via my fingerprint.
I like my huge screen and tactile keyboard. Not a tablet fan, but that's OK, to each their own.

I'm thinking of adding an external fingerprint sensor to this machine and maybe start getting into the passkey world. I think eventually that will be forced on us all.
 
We discussed it, but it can't be repeated enough. Everyone should do this, but you better remember it. Consumer Cellular has an extra "account PIN" which they do not publicize. If you turn it on, they won't talk to you if you can't produce it, and you have to talk to them to port out. Resetting it involves sending in something through US Mail or FAX. Highly resistant to SIM swap hackers.
Is this the same as the 4 digit pin on my T-Mobile Android phone that I have to enter whenever I restart the phone?
 
I like my huge screen and tactile keyboard. Not a tablet fan, but that's OK, to each their own.

I'm thinking of adding an external fingerprint sensor to this machine and maybe start getting into the passkey world. I think eventually that will be forced on us all.
I don’t like to be tied to a spot. My desk is wherever my butt is.
 
Is this the same as the 4 digit pin on my T-Mobile Android phone that I have to enter whenever I restart the phone?
No. It is an extra level of security at the account level, specifically when you call them to discuss actions on your account such as changing plans or porting out. Or, if your carrier allows account changes over the web, it would be an extra question presented then.

Each carrier does this slightly differently.
 
I don’t like to be tied to a spot. My desk is wherever my butt is.
Even on the bike? :)
1779542490605.png
 
My Mom has an IPhone, so I don't think that's the solution.

I was asking: Could a bad person take an iPhone and reset it so they could then get phone calls and text without having to know the PIN / facial recognition.

I wasn't suggesting any solution.
Ok, thanks. I kind of thought you were talking about a different scenario. Thanks for the clarification
 
Port out protection, aka sim lock or number lock appears to be executed at the account level not the physical phone level, my mistake. Also, there's a find my device feature on most phones it's very handy to set up and be familiar with. If my phone were suddenly stolen it would take me a few minutes to dig into my brain to figure out what to do, but I have set up the ability to literally walk and factory reset my phone and wipe all data. If I can do it fast enough I can prevent the phone from being taken offline which is usually the first thing someone does when they steal a phone. My goal is to actually have a second phone and keep it cloned to my original phone except for the number, in case my main phone is ever stolen I have the second phone for the true Factor authentication and such. I have a pretty scary months long story that I'll post later where my home PC was literally remotely taken over, most keyboard and all and I happen to catch it but I'm also a web designer and my server was packed, and I'm at the point where I'm getting attempted credit card openings about every 20 minutes around the clock for the last 90 days. I'll give you the rundown on all my efforts to batten down the hatches. It went from being here racing to kind of fun Believe it or not. I'm a little sick that way!
If your stolen phone number is used for 2FA, resetting that phone remotely, does not remove that phone from being used for 2FA.
 
I called AT&T and they convinced me that I am covered. I'm on a family plan. They said they would send the port pin to one of the other 5 phone numbers on this account. Not to the phone that requested the port(ing). If I had an individual account, it would send the number to the alternate verification method (email or such). Therefore, I'm pretty safe that unauthorized porting would NOT occur.
 
My PayPal account was hacked and drained last year. I am very diligent with security: password manager with gazillion complicated passwords to everything (passkeys as of late), 2FA, different emails for everything and it still happened. I was travelling and never noticed PayPal emails alerting me to the activity that resulted in the hack: phone number was changed, email was changed, withdrawal happened etc...

The good news is that they did a quick investigation, admitted it happened and refunded my account but they were super evasive as to how was it even possible. I've poked around and found out that PayPall is susceptible to people calling in and claiming they have lost their phone and/or forgot their email and what not. Terrible security practices that they are aware of but don't change. Not sure why. And there seemingly is enough information about us out there for PayPay to be fooled and change emails or phone numbers on request.

I kept the account for those rare situations when I need it but I disconnected all the financial info from there. If you don't have to use it, don't.
 
My PayPal account was hacked and drained last year. I am very diligent with security: password manager with gazillion complicated passwords to everything (passkeys as of late), 2FA, different emails for everything and it still happened. I was travelling and never noticed PayPal emails alerting me to the activity that resulted in the hack: phone number was changed, email was changed, withdrawal happened etc...

The good news is that they did a quick investigation, admitted it happened and refunded my account but they were super evasive as to how was it even possible. I've poked around and found out that PayPall is susceptible to people calling in and claiming they have lost their phone and/or forgot their email and what not. Terrible security practices that they are aware of but don't change. Not sure why. And there seemingly is enough information about us out there for PayPay to be fooled and change emails or phone numbers on request.

I kept the account for those rare situations when I need it but I disconnected all the financial info from there. If you don't have to use it, don't.
Wow, sorry that happened, but thanks for sharing the details. Just shows that the scammers are taking advantage of everyone, even the most savvy. I'm nervous about everything now.
 
It sucks that it happened, but this was part of the issue.

“ I was travelling and never noticed PayPal emails alerting me to the activity that resulted in the hack”

All the security in the world doesn’t help if we don’t do our part too.

I am not blaming the victim, just pointing out where the collapse could/should have been caught.
 
Last edited:
I don't have any credit card or bank account info in my PayPal account. Once a transaction is done, or money is transferred out, I delete all the info. I do that with Venmo as well as to be transaction fee free, you need to use an Amex. Deleting any point of possible exposure to compromise can help you reduce risks.
 
My PayPal account was hacked and drained last year. I am very diligent with security: password manager with gazillion complicated passwords to everything (passkeys as of late), 2FA, different emails for everything and it still happened. I was travelling and never noticed PayPal emails alerting me to the activity that resulted in the hack: phone number was changed, email was changed, withdrawal happened etc...

The good news is that they did a quick investigation, admitted it happened and refunded my account but they were super evasive as to how was it even possible. I've poked around and found out that PayPall is susceptible to people calling in and claiming they have lost their phone and/or forgot their email and what not. Terrible security practices that they are aware of but don't change. Not sure why. And there seemingly is enough information about us out there for PayPay to be fooled and change emails or phone numbers on request.

I kept the account for those rare situations when I need it but I disconnected all the financial info from there. If you don't have to use it, don't.
Good info. I just logged in and removed my credit card. I can't remember the last time I used it anyway.
 
Sim passcodes (or locks) were implemented when it was discovered that cellular employees were being bribed by thieves to port a person’s cell number to a Sim that they controlled. It is not related to any security on your phone or the pin number you might use to get into your phone. Like using the same password on multiple sites, you can use the same pin number for your phone and your debit card.

It does create a new speed bump if you lose your phone or regularly change cell providers in search of the best deals.
 
It sucks that it happened, but this was part of the issue.

I was travelling and never noticed PayPal emails alerting me to the activity that resulted in the hack”

All the security in the world doesn’t help if we don’t do our part too.

I am not blaming the victim, just pointing out where the collapse could/should have been caught.
Which reminds me... don't tell the world you are traveling! (Not attacking you, tenant13, I speak in general.)

Don't mention it here. Don't mention it on Instagram, Facebook, X, Reddit, Bumble, Grinder, whatever. Even if you have an "anonymous" name.

But for goodness sake, don't mention it on Facebook where you likely have your real name. I'd even recommend you get off Facebook or really reduce your use of it.

Save the picture postings for later when you come back.

Paranoid? No. With the new A.I. tools, we all have profiles out there on the dark web. A scamster can set up a trigger to attack you when they notice you are traveling. This is a perfect time for them to attack. Going further, it is a good time to rob your house too, but that's too much work compared to letting an A.I. agent go off and do its thing.
 
Back
Top Bottom