Credential Stuffing
Attackers are replaying massive stolen credential sets across business and consumer services to hijack accounts at scale.
Stat: 24B credentials available on dark web
Read Full BriefPhone number takeover still enables account resets, MFA interception, and financial fraud when carriers are socially engineered.
Threat alert
Get the CSM Weekly Threat Brief and updates when this threat profile changes.
Attackers convince or coerce carriers into moving a target phone number onto a new SIM.
That single move can unlock SMS-based MFA, password resets, brokerage accounts, and crypto wallets.
High-value targets include founders, executives, creators, and remote workers.
Executives with phone-based recovery settings
Crypto users
Consumers relying on SMS MFA as their main control
Brokerage passwords reset after phone takeover.
Business email accounts recovered via SMS.
Attackers taking over creator accounts tied to a single phone line.
Rapid account compromise across multiple services.
Identity recovery can take weeks even after the number is restored.
Victims often experience simultaneous financial and reputational harm.
Move critical accounts to app-based or hardware MFA.
Set carrier PINs and account locks where available.
Audit phone number as a recovery factor on key services.
Use identity monitoring for telecom and account changes.
Vendors
VaultKey
Identity & Access Management
MFA, privileged access, and passwordless identity workflows for growing businesses.
Find More Vendors for This ThreatSignal Fraud Ops
Financial Fraud Prevention
Wire fraud controls, anomaly detection, and finance-team verification workflows.
Find More Vendors for This ThreatMobile Sentry
Mobile Device Management
Device policy enforcement, inventory, and mobile security posture management.
Find More Vendors for This ThreatRelated
Attackers are replaying massive stolen credential sets across business and consumer services to hijack accounts at scale.
Stat: 24B credentials available on dark web
Read Full BriefSynthetic voice and video are being used to impersonate executives, bypass trust checks, and trigger sensitive actions.
Stat: Voice + video cloning now used in fraud
Read Full Brief