Researchers: AT&T, T-Mobile, Tracfone, US Mobile, and Verizon use vulnerable procedures for customer support that put users at risk of SIM swapping attacks
Context & Ripple Effects
This report names the entry point behind a pattern the related coverage keeps circling: the customer-support channel itself. Earlier reporting found foreign carriers sharing real-time SIM swap data with banks while their US counterparts dragged their feet (US carriers lagging on SIM swap data sharing), leaving the human layer — support agents who can port a number after a few correct answers — as the weak link.
The consequences have since materialized: T-Mobile later confirmed a breach caused by SIM swap attacks on customers (T-Mobile's SIM swap breach), and by 2023 three SIM-swapping gangs claimed on Telegram to have phished T-Mobile staff repeatedly through 2022 (gangs claiming to phish T-Mobile staff). Naming five carriers at once reframes this from one carrier's lapse to an industry-wide procedure problem.
First-order effects
- Customers of AT&T, T-Mobile, Tracfone, US Mobile, and Verizon are exposed right now through support procedures that let attackers port their numbers using socially engineered calls, putting SMS-linked banking and email accounts within reach of thieves.
- The five named carriers face immediate pressure to re-verify their support authentication steps, since the finding targets process design rather than any single employee or system.
Second-order effects
- Banks and services that rely on phone numbers as an identity anchor absorb the fraud losses, sharpening the case for the real-time SIM swap data sharing with financial institutions that US carriers had resisted while foreign carriers adopted it.
- Carriers that harden support procedures first gain a security differentiator over rivals still running knowledge-based verification, turning account-takeover resistance into a competitive claim rather than a compliance cost.
Third-order effects
- If support-channel social engineering persists — as the gangs' repeated claims against T-Mobile staff suggest it did after this report — regulators and standards bodies face mounting grounds to mandate uniform SIM swap controls across US carriers instead of relying on voluntary fixes.
- Sustained SIM swap risk erodes the phone number's role as a trusted identity factor, pushing banks and platforms toward authenticator apps and hardware keys and reducing carriers' grip on the authentication market.
The trend: US carriers' account-security practices are being exposed as the systemic weak point in phone-number-based identity, with SIM swapping evolving from opportunistic fraud into a repeatable attack vector aimed at carrier staff themselves.