{"success":true,"data":{"id":"fake-mobile-carrier-sim-swap-approval-lure","label":"Fake Verizon / AT&T / T-Mobile / Sprint / Cricket / Mint / Visible / Boost / Xfinity Mobile / Metro / US Cellular / Google Fi / Spectrum Mobile SIM-swap / port-out / eSIM-transfer approval lure — \"SIM swap request received, approve within 24 hours or confirm it wasn't you\" targeting 450M+ US mobile subscribers; \"Yes approve\" → attacker takes over SIM and harvests ALL SMS 2FA codes (bank + crypto + retail + email); \"No this wasn't me\" → credential harvester for account password + PIN enabling SIM swap by attacker (FBI IC3 2024: $48M+ direct + $200M+ crypto-linked losses via Chainalysis, +32% YoY; Verizon / AT&T / T-Mobile 2023 data-breach leaks now give attackers victim's carrier + plan + last-4 of SSN for plausible phish)","description":"Fake \"a SIM swap request / port-out request / eSIM transfer was received on your Verizon / AT&T / T-Mobile / Sprint / Cricket / Mint / Visible / Boost / Xfinity Mobile / Metro / US Cellular / Google Fi account — approve within 24 hours or confirm it wasn't you\" email targeting the 450M+ US mobile-subscriber base. The lure mimics real carrier security-notification templates and elicits one of two clicks: (1) \"Yes, approve\" → attacker takes over the SIM and harvests ALL SMS-based 2FA codes (bank logins, crypto exchange, retail, email); (2) \"No, this wasn't me\" → the link goes to a carrier-credential harvester where attacker collects the account password + account PIN to initiate the SIM swap themselves. Post-compromise = full bank / crypto / retail / email account takeover because SMS 2FA still underpins most US consumer finance authentication (Chase, Wells Fargo, Bank of America, credit unions, Schwab, Fidelity all default to SMS; Coinbase, Gemini, Kraken still allow SMS recovery in most configurations). FBI IC3 2024 report: $48M+ direct SIM-swap losses (+32% YoY); Chainalysis ties an additional $200M+ in crypto losses to SIM-swap-enabled account takeover. Verizon / AT&T / T-Mobile 2023 customer-data breaches leaked account info to attackers — they now know victim's carrier + plan + last 4 of SSN, which makes approval phish highly plausible and pass the users' plausibility check. Fires when body references Verizon / AT&T / T-Mobile / Sprint / Xfinity Mobile / Cricket / Mint Mobile / Visible / Boost / Metro / US Cellular / Google Fi / Spectrum Mobile / Straight Talk / TracFone / mobile carrier / wireless carrier AND contains SIM-swap / port-out / number-port / eSIM-transfer / approve-within / confirm-it-wasn't-you / 24-hour urgency. Excludes verizon.com, verizonwireless.com, att.com, att.net, t-mobile.com, tmobile.com, sprint.com, xfinity.com, xfinitymobile.com, comcast.com, cricketwireless.com, mintmobile.com, visible.com, boostmobile.com, metrobyt-mobile.com, metropcs.com, uscellular.com, googlefi.com, fi.google.com, spectrummobile.com, straighttalk.com, tracfone.com. Auto-classified as danger via the `-lure` suffix.","tier":"danger","category":"scam","isThin":false}}