meta_pixel
Tapesearch Logo
Log in
Malicious Life

You Should Be Afraid of SIM Swaps

Malicious Life

Malicious Life

Technology

4.81K Ratings

🗓️ 23 January 2023

⏱️ 33 minutes

🧾️ Download transcript

Summary

You Should Be Afraid of SIM Swaps



Advertising Inquiries: https://redcircle.com/brands

Transcript

Click on a timestamp to play from that location

0:00.0

Hi, I'm Ryan Levy.

0:01.0

Welcome to Cyber reasons Malicious Life. If you live in the Minneapolis St Paul area and you're hungry you might order in from Tono, pizzeria and cheese sticks.

0:37.3

Get a pepperoni pie maybe, or if you don't mind the diabetes, a cheese steak with bacon on top over a bed of fries.

0:46.0

Tono has four locations in the city and there on Door Dash, which is where the problem began.

0:54.0

The way DoorDash works for merchants is that you're given access to an administrative portal.

0:59.8

Shaz Khan is the co-founder and owner of Tano.

1:04.0

And you're able to log in alongside any authorized users that you have on there

1:09.0

in order to see the metrics of your business.

1:15.0

And so what had happened was I went in there once and I noticed that there was an

1:19.0

obscure email address that I didn't know and I noticed that my role in the

1:26.7

organization had been switched from business owner to you know, account manager or something of a lesser access and this rogue email

1:39.9

was the one that had been given kind of the business admin access.

1:44.0

Shaz contacted customer service.

1:47.0

And after a series of painstaking phone calls with Dordash, come to find out that this is kind of a

1:55.1

known threat and known attack where I you know I'll say an attacker for lack of a

2:01.5

better term attempts to convince somebody on the

2:05.2

support team at Dordash that they are indeed an authorized administrator of

2:10.3

that particular merchant and to be given access to the account.

2:14.0

Customer service failed to suss out the unauthorized user,

2:21.0

but the app itself has measures to prevent the worst-case scenario.

2:26.0

Even as an admin in Tono's DoorDash account, the unauthorized user had no means of initiating transfer of money from the business to themselves.

2:37.0

However, access was given, visibility was given, and so in this case, you know, some, the couple digits of a bank account, the name of a bank,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from Malicious Life, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of Malicious Life and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.