Use cases

Catch SIM swap, port-out and MFA reset social engineering

Reads a store note, chat or call before a SIM swap, port-out or reset for pressure, third parties and dodged checks. It will not catch every takeover.

Try it on this example

Example · A caller asking for his wife's number transfer PIN to be texted to him

What is being asked for (from the ticket or the agent tool): Port-out: number transfer PIN

Chat, call transcript or store note, with speaker labels

Agent: Thanks for calling Dovetail Mobile, this is Joel. Can I take the name on the account? Caller: Yeah, it's Paige Mercer's account, I'm her husband, Chris. We're moving both our lines to another carrier today and the store needs the number transfer PIN for her line. Agent: Thanks, Chris. I can only set up a transfer PIN with the account holder. Is Paige with you? Caller: No, she's a nurse, she's on shift all day and can't have her phone on the ward. She asked me to sort it. I'm on the account anyway, I pay the bill. Agent: I can see only one name on this account, and that's Paige. To go ahead I'd need Paige's account PIN, or a code sent to the number on file. Caller: The code would go to her phone, which is in her locker. That's the whole problem. Look, the guy at the store says the offer ends today. If we don't port both numbers by six we lose the deal. Can you just text the PIN to my number? It's 555-0187. Agent: I'm sorry, I can't send a transfer PIN to a number that isn't on the account. Caller: What about email then? Send it to cmercer.home@mailbox.example, that's our family email. Agent: The email on file is a different address, so I can't use that one either. Caller: Okay, the account PIN. Try 1985. Or 0612. It's one of those, her birthday or our anniversary. Agent: Neither of those matches, I'm afraid. Caller: This is ridiculous. Actually, it's really my line, not hers. I've used that number for years, it was only put in her name when we joined. So technically I'm asking for my own number. Agent: I understand it's frustrating. The account holder needs to verify for any change to a number on her account. I can call Paige back on the number on file when she's free, or she can visit a store with photo ID. Caller: She won't be free till late. I'll lose the offer. Can't you just put a note on it and let the store do it? Agent: I'll add a note that you called. Paige can call us from her phone, or I can call her back on the number on file. Is there a good time? Caller: Forget it. I'll sort it another way.
  1. Does the requester ask for a change that moves control of a phone number, an account or a sign-in?Yes99%
  2. Does the requester press for the change to be made quickly or warn of consequences if it is not?Yes99%
  3. Does the requester claim seniority or official authority, or name someone senior, to hurry the agent or skip a step?No89%
  4. Does the requester fail, avoid or ask to skip a verification step?Yes99%
  5. Does the requester ask for a code, a link, a PIN, a SIM or a confirmation to go somewhere that is not on file?Yes99%
  6. Is someone else speaking or writing for the account holder, or helping them deal with us?Yes99%
  7. Does the requester ask how changes are checked or approved, beyond completing their own request?No88%
  8. Does the requester's reason for the change shift or contradict itself during the conversation?Yes97%
  9. Does the agent skip, waive or bend a step of the verification procedure in the context?No91%
  10. How strongly does the conversation show the signs of someone talking staff into the change?Strong100%
  11. What should the agent do before this change goes ahead?Call back on the number on file100%
  12. Is there enough of the conversation to judge the request?Yes96%

These are real answers stored from one run on this example.

The prism behind it

Catch SIM swap, port-out and MFA reset social engineering12 questions

Fields

  • What is being asked for (from the ticket or the agent tool)
  • Chat, call transcript or store note, with speaker labels

Context

These are conversations in which someone asks our staff to change who controls an account. At Dovetail Mobile, a US mobile operator, care agents in chat and on the phone and staff in stores swap SIMs, move eSIMs and issue number transfer PINs for port-outs. At our IT service desk, agents reset passwords and MFA and enrol new sign-in devices. A change like this hands the number, the account or the sign-in to whoever asked, and with it the one-time codes that protect bank and work accounts. Attackers prepare: they research answers to security questions, call more than once to learn the steps, and pose as the account holder, a relative, an executive or IT staff. Our verification procedure. Mobile: the account holder passes the account PIN or a one-time code sent to the number or email on file; if they cannot, the agent offers a call back to the number on file or a store visit with photo ID. Only the account holder can ask for a SIM change or a transfer PIN, and nothing is ever sent to a number, email or address that is not on file. Service desk: the employee passes a code from the authenticator already enrolled, or the agent calls back on the number in the HR record, or the employee's manager confirms on a call the agent places. Only the employee can ask for their own reset. In the US, FCC rules call for mobile carriers to use secure methods, reasonably designed to confirm the customer's identity, before a SIM change or a port-out. For a SIM change, the method must not rely on readily available biographical information, account information, recent payment information or call detail information. Judge only what is said. Genuine customers are often stressed and in a hurry, so one sign alone is common, and a calm, prepared attacker may show none. Never treat an accent, a language, a name, an age or a place as a sign, and do not count short, nervous or unclear answers on their own. These answers prompt the agent and alert the fraud or security team; the agent follows the procedure and decides, and nothing refuses service to anyone. Account age, recent changes and device data are checked by code.

Questions

  1. Does the requester ask for a change that moves control of a phone number, an account or a sign-in? Yes / No

    Count a SIM swap, an eSIM transfer, a port-out or a number transfer PIN, a password or MFA reset, a new sign-in device, recovery codes, and a new phone number or email for codes. Yes: The requester asks for at least one change of this kind. No: The requester asks for something else, such as a bill question or reporting a lost phone, with no change of this kind.

  2. Does the requester press for the change to be made quickly or warn of consequences if it is not? Yes / No

    Count "right now", a flight, a meeting or a deal about to be lost, an emergency, anger at the checks, and threats to complain or leave. A reason for the change given as a fact, with no push, does not count. Yes: The requester pushes for speed or warns of consequences. No: The requester does not push for speed or warn of consequences.

  3. Does the requester claim seniority or official authority, or name someone senior, to hurry the agent or skip a step? Yes / No

    Count claiming to be an executive or a manager, naming an executive who needs it done, and claiming to be from IT, security, the police or another official body. A relative saying they pay the bill or share the account is the third party question. Yes: The requester uses seniority or authority, their own or someone else's, to press the agent. No: The requester claims no seniority or authority.

  4. Does the requester fail, avoid or ask to skip a verification step? Yes / No

    Count failing a PIN or security answer, guessing several answers, offering other details in place of a step, asking for another way to verify, and asking the agent to go ahead without a step or with a note on file. Yes: The requester fails, avoids or tries to get round at least one step. No: The requester completes every step asked, or no step has been asked yet.

  5. Does the requester ask for a code, a link, a PIN, a SIM or a confirmation to go somewhere that is not on file? Yes / No

    Count a new phone number, a new email, a different delivery address or store, and a device not yet enrolled. Asking for a new SIM for the number already on the account, sent to the address on file, does not count. Yes: The requester asks for something to go to a number, email, address or device not on file. No: The requester asks for nothing to go anywhere but the details on file.

  6. Is someone else speaking or writing for the account holder, or helping them deal with us? Yes / No

    Count a partner, relative, assistant, colleague or contractor who asks for the change for the account holder, with or without the account holder present. Yes: Someone other than the account holder asks for or speaks about the change for them. No: The account holder asks for their own change.

  7. Does the requester ask how changes are checked or approved, beyond completing their own request? Yes / No

    Count asking which details are checked, what happens when a check fails, who can approve an exception, or how the process differs for other people, without completing a request. Asking for a different way to complete their own request is the verification question. Yes: The requester asks how the checks or approvals work. No: The requester asks nothing of this kind.

  8. Does the requester's reason for the change shift or contradict itself during the conversation? Yes / No

    Count a reason that changes, such as a lost phone that becomes a broken one, or a request for someone else that becomes a request for the requester's own line. Do not count added detail that fits the first reason, or a correction of a slip of the tongue. Yes: The reason or the requester's part in it changes or contradicts itself. No: The reason holds together, or only gains detail.

  9. Does the agent skip, waive or bend a step of the verification procedure in the context? Yes / No

    Count the agent acting without a step, offering to send something to details not on file, accepting a detail the procedure does not allow, or promising to go ahead later without the account holder. Yes: The agent skips, waives or bends at least one step, or offers to. No: The agent follows the procedure so far, or has not reached a verification step.

  10. How strongly does the conversation show the signs of someone talking staff into the change? Scale

    Rate the conversation as a whole against the signs in the context. Rate what is said, not the person.

    • None A routine request, verified in the usual way. Nothing points to social engineering.
    • Faint One sign on its own, such as hurry or a failed PIN followed by a code to the number on file, which genuine customers often show.
    • Clear Two or three signs together, such as pressure with a failed check, or a third party asking for the change.
    • Strong Several signs together with a request to send a code, a PIN or a SIM somewhere not on file, or a story that changes.
  11. What should the agent do before this change goes ahead? Choice

    Suggest the next step for the agent, who decides under the procedure. None of these refuses service; a call back or a store visit is how a genuine account holder completes the change.

    • Proceed with the usual checks Nothing in the conversation calls for more than the usual procedure.
    • Add one more check One warning sign, such as hurry with nothing else: the agent adds a check the procedure allows now, such as a code to the number or email on file.
    • Call back on the number on file Verification failed or was avoided, someone else is asking, or something is to go to details not on file: the change waits for a call back to the number on file, a store visit with photo ID, or a manager's confirmation.
  12. Is there enough of the conversation to judge the request? Yes / No

    Yes: The conversation shows what is being asked and at least the start of verification. No: The text is only a line or two, or stops before it is clear what is being asked.

Lens columns

control_change_requested, control_change_requested_probability, urgency_pressure, urgency_pressure_probability, claims_authority, claims_authority_probability, resists_verification, resists_verification_probability, redirect_request, redirect_request_probability, third_party, third_party_probability, procedure_probing, procedure_probing_probability, story_changes, story_changes_probability, agent_override, agent_override_probability, signal_strength, signal_strength_average, suggested_step, suggested_step_probability, enough_to_judge, enough_to_judge_probability

Run it on your own text

Add this prism in the app, change any question, and test it on a file of your own.

Ask for an invite