SoatDev IT Consulting
SoatDev IT Consulting
  • About us
  • Expertise
  • Services
  • How it works
  • Contact Us
  • News
  • August 10, 2023
  • Rss Fetcher
An image of a hand holding a mouse against a multicolored background.
Photo by Amelia Holowaty Krales / The Verge

The US Cybersecurity and Infrastructure Security Agency (CISA) is calling for stricter SIM swapping protections and the transition to a passwordless future following last year’s Lapsus$ attacks. In a lengthy report released on Thursday, the agency details the teen hacking group’s key techniques and provides recommendations to prevent similar attacks going forward.

Lapsus$ made headlines last year after it took credit for the cyberattacks affecting major tech companies like Nvidia, Samsung, Ubisoft, T-Mobile, Uber, and Microsoft. The group also managed to steal and leak 90 videos containing gameplay footage from Rockstar’s upcoming Grand Theft Auto VI game. Seven teenagers connected to the group were arrested in London last year.

NEW: Today, DHS released the Cyber Safety Review Board’s (CSRB) report summarizing the findings of its review into the hacking activities of Lapsus$, a threat actor group. Read more: https://t.co/ye0vjZDiUK (1/2) pic.twitter.com/MNJ8WWs5pw

— Homeland Security (@DHSgov) August 10, 2023

CISA also asks that the Federal Trade Commission and Federal Communications Commission do more to protect consumers against SIM swapping attacks. Last month, the FCC proposed a new set of rules that would require wireless providers to “adopt secure methods of authenticating a customer” when performing SIM swaps.

“Lapsus$ was unique for its effectiveness, speed, creativity, and boldness; it operated in a way that gifted the Board a propitious lens through which we could see systemic issues in the digital ecosystem,” CISA writes. “Lapsus$ exploited, to great and wide effect, a playbook of effective techniques, which other threat actors can also use.”

Despite the scale of the Lapsus$ attacks, CISA says the group makes it clear “just how easy it was for its members (juveniles, in some instances) to infiltrate well-defended organizations.” One of the methods used by Lapsus$ is SIM swapping, or the act of gaining control of a target’s phone number through social engineering and other methods. This allows the bad actor to receive calls or texts from that number, including messages containing two-factor authentication codes connected with a victim’s sensitive accounts.

Because of this, CISA now recommends that companies move away from voice and SMS-based multifactor authentication in favor of passwordless solutions. It suggests that organizations use passkeys compliant with the FIDO2 standard instead, which allows users to sign in to their accounts using their fingerprint or a hardware-based security key. Many companies and password managers are already starting to support passwordless sign-in methods, including Google, 1Password, Microsoft, and Dashlane.

“Lapsus$ exploited, to great and wide effect, a playbook of effective techniques”

Additionally, CISA specifically calls on carriers to “implement more stringent authentication methods for SIM swapping.” That includes giving customers the ability to lock their accounts to prevent SIM swaps and requiring “strong identity verification” for SIM swaps as well as giving account holders a “detailed record” of when a SIM swap occurs.

Given that the majority of known Lapsus$ hackers are teenagers, CISA also suggests having Congress fund “juvenile cybercrime prevention programs” as well as “fostering interruption and redirection programs” to prevent young people from getting involved in cybercrime in the future.

Previous Post
Next Post

Recent Posts

  • Karat Financial is bringing business banking to creators
  • Odyssey’s new AI model streams 3D interactive worlds
  • Spotify amps up podcast discovery with new features
  • Google Photos debuts redesigned editor with new AI tools
  • Meta wants to open more retail stores

Categories

  • Industry News
  • Programming
  • RSS Fetched Articles
  • Uncategorized

Archives

  • May 2025
  • April 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023

Tap into the power of Microservices, MVC Architecture, Cloud, Containers, UML, and Scrum methodologies to bolster your project planning, execution, and application development processes.

Solutions

  • IT Consultation
  • Agile Transformation
  • Software Development
  • DevOps & CI/CD

Regions Covered

  • Montreal
  • New York
  • Paris
  • Mauritius
  • Abidjan
  • Dakar

Subscribe to Newsletter

Join our monthly newsletter subscribers to get the latest news and insights.

© Copyright 2023. All Rights Reserved by Soatdev IT Consulting Inc.