{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-sim-swap-at-an-at-t-store-enabled-the-400m-ftx-drain-on-bankruptcy-night"},"incident":{"title":"SIM swap at an AT&T store enabled the $400M FTX drain on bankruptcy night","date":"2022-11-11","date_precision":"day","victim_org":"FTX (referred to as 'Victim 1' in the indictment)","sector":"Cryptocurrency","country":"United States","primary_vector":"SIM Swap","secondary_vectors":["Physical Pretexting"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported; the impersonation used a physical fake ID at a retail store.","outcomes":["Cryptocurrency Theft","Identity Theft","Wire Fraud / Financial Loss"],"loss_usd":400000000,"loss_note":"The DOJ indictment concerns a theft of roughly $400 million. FTX administrators reported $413 million in unauthorised transfers, and Elliptic valued the outflow at $477 million. Prosecutors have not officially named FTX as the victim.","records_affected":null,"threat_actor":"Robert Powell ('ElSwapo1', the 'Powell SIM Swapping Crew'), Emily Hernandez, Carter Rohn","summary":"On the night FTX filed for bankruptcy, roughly $400 million in cryptocurrency left its wallets. In February 2024 the DOJ indicted three people over a SIM-swapping conspiracy running from March 2021 to April 2023, including a November 2022 swap against an unnamed 'Victim 1'. Investigators and blockchain analysts concluded from the date, amount and transaction pattern that the victim was FTX.","how_it_worked":"A member of the crew walked into an AT&T retail location carrying a counterfeit ID in the target's name and asked staff to move the number to a new device. The store employee, following normal identity-check procedure against a document that looked genuine, completed the port. From that point every SMS one-time code and password-reset link for the target's accounts arrived on the attackers' handset. The crew used those codes to reach account credentials and then initiated the transfers out of FTX wallets, timed to a night when the company was in bankruptcy chaos and unusual outflows were least likely to be challenged.","lessons":"Enterprise-controlled authentication that never touches a consumer mobile number, combined with number-lock and in-person ID escalation at carrier retail, closes the pathway a physical fake ID otherwise opens.","confidence":"Reported","sources":[{"title":"Arrests in $400M SIM-Swap Tied to Heist at FTX?","url":"https://krebsonsecurity.com/2024/02/arrests-in-400m-sim-swap-tied-to-heist-at-ftx/","publisher":"Krebs on Security"}],"entry_type":"incident","slug":"2022-sim-swap-at-an-at-t-store-enabled-the-400m-ftx-drain-on-bankruptcy-night","year":2022,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-sim-swap-at-an-at-t-store-enabled-the-400m-ftx-drain-on-bankruptcy-night"}}