Preventing SIM swap

X
Collapse
16 replies
455 views
 
  • Time
  • Show
Clear All
new posts
    Junior Member
    Many articles (for instance, the latest issue of Which Tech) recommend that in order to prevent SIM swap fraud one should set up a password that must be provided to approve any account changes over the phone or online.
    Of course, I have a login password to use to access my online account. But that does not help if Lebara allows SIM swap if a phone caller can provide enough details to convince a customer service personthat they are the genuine account holder.
    So does Lebara let one set up a password to prevent this? If so, how? I know that there have been cases in the past where a swap was allowed because a fraudster had got hold of a user's details. I am not VERY worried that this could happen to me, but cosidering how important my phone number is I would be pleased to avoid even the small risk.
    If Lebara doesn't do this (and the forum rules permit, which they may not), does anyone know of providers who can arrange this possibility.

    16 replies

  • #2
    Junior Member
    Joined specifically to reply to this! This happened to my partner at the weekend. The hackers hacked his email account and so received the OTP and swapped from his physical SIM to eSIM using social engineering on the chat with his phone provider. They had name, address, DOB from the hacked email account so the eSIM swap was approved. A PIN or code not visible on the online account or something would at least stop this happening. Failing that, the option to use an authenticator? I know this is difficult if people have lost their phone or it has been stolen but perhaps for this they would need to do the ID verification process to complete the move. SIM swap is on the rise and it’s devastating as he how has 5 loans/cards in his name … all thanks to taking over his phone number and email. Please Lebara do something to improve security to stop this happening. As my number was in the emails etc I am just waiting for me to be next.

    Comment

    • #3
      Community Manager 1
      danco34, Goosie that's for the question on this. I'll need to check in with the team to get a response on this. I'll drop the reply here once I hear back.
      Martin - Community Manager

      Comment

      • #4
        Community Manager 1
        danco34, Goosie I have good news! The SIM swap process has been updated with 2 steps verification process online and with customer support agents. This should avoid any fraudulent activity in relation to the SIM swap process.
        Martin - Community Manager

        Comment

        • #5
          Junior Member
          Oh my goodness! Thank you!!! Thank you so so much for listening!!! What will the two step process be? Just so we can understand what needs to be done and how this prevents someone impersonating the ID of someone ?

          Comment

          • #6
            Community Manager 1
            I'll get back to you with the detail on the 2 step process Goosie but it's good to know it's in place.
            Martin - Community Manager

            Comment

            • #7
              Junior Member
              Martin Great news. Looking forward to having the details

              Comment

              • #8
                Community Manager 1
                I'll update this thread as soon as I have the details danco34.
                Martin - Community Manager

                Comment

                • #9
                  Junior Member
                  Hi
                  I also joined specifically to address this concern. Can you get Lebara to expedite a response?


                  Comment

                  • #10
                    Community Manager 1
                    I'll update you all as soon as I have the details Waylander6969
                    Martin - Community Manager

                    Comment

                    • #11
                      Junior Member
                      Scammers still looking for more victims. They phoned my husband earlier explaining they are upgrading SIM cards because of complaints with signal. Husband let his guard down so they got his name, DOB and address. Hopefully not the lebara login as under my account.
                      Lebara need to alert customers to scam urgently.

                      Comment

                      • #12
                        Junior Member
                        I got an MS Meet invite last Friday. I have never used Meet before, and I thought I had to give my details to access the webinar on Meet. Sure enough, I have not been able to access my bank account or fill in any web forms that use my phone number to verify identity: "Phone number is invalid", nor have any of the unrecognised MMI fixes worked. I couldn't even contact my bank's fraud squad to access my bank account, because they think I'm a fraudster... It took me 4 DAYS before I knew what the problem was - only because Ms Meet was asking for a confirmation of my phone number I HAVE NEVER SEEN BEFORE. Unfortunately, I didn't think of taking a screenshot of it, not that I think it would be much use when it is so easy to buy new SIM cards and fake phone numbers, especially online.
                        Now I have to go through every website and change my password, probably from a different IP address!

                        Comment

                        • #13
                          Junior Member
                          On Lebara security or lack there of, I created this thread below requesting they add 2FA such as Google Authenticator API to the Lebara online account login as most other mobile phone operators offer this. Please add your voice to that thread and push Lebara to implement this. I am confused why it is taking so long as surely it must be a simple API as many smaller websites have this app based 2FA option. Getting into someone's online Lebara account is one significant step to impersonating them with Lebara customer service and performing a Sim Swap. With only a user name and password needed, this is trivial for an experienced hacker:

                          It's 2026 and Lebara has no "Two Factor Authentication" (2FA) on their account login, not even an SMS one (please note, SMS 2FA is not secure enough and not really acceptable in 2026 either). Other mobile operators have this on their account login and the best way is either using an app based one like Google

                          Last edited by LebaraUsers; 23-07-26, 09:31 PM.

                          Comment

                          • #14
                            Junior Member
                            OK, it is 2 months since Martin promised details about sim swap security and we have heard nothing.
                            Lebara are yet to implement 2 factor / multi factor authentication for login but periodically promise progress on security and never deliver.
                            I worry that security seems such a low priority and wish they would update us on this.

                            Comment

                            • #15
                              Junior Member
                              Yes, it screams of apathy towards security or maybe they just don't have the technical skills to implement these technological barriers such as basic 2FA on account login for example. I am not sure which concerns me more.

                              I think its time to move provider. Does anyone know of a leaderboard of information on which providers have the best security against Sim Swap? It's such a damaging fraud it has to be considered when selecting mobile providers, more than saving a few pounds sterling a month.
                              Last edited by LebaraUsers; 1 week ago.

                              Comment

                              Loading...