
Fake Install Guides and Helpdesk Calls Drive Attacks
This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…
An attacker called the victim pretending to be their mobile carrier, built trust with a “customer satisfaction survey,” then asked the victim to read back an SMS one-time passcode and a long-standing account passcode. The attacker had already initiated (and days earlier executed) a SIM swap, then used the collected details to log in, hijack the session, and make unauthorized account changes before the victim recovered access.
This incident began with an unsolicited phone call from someone claiming to represent the victim's wireless carrier. The caller opened with a customer satisfaction survey and a discussion of loyalty discounts, a low-pressure pretext designed to build rapport before any sensitive request was made. Once trust was established, the caller asked the victim to read back a one-time passcode that had just been sent to their phone. Believing the interaction was routine, the victim complied, unknowingly approving an authentication request initiated by the attacker.
The caller then pursued a second, more damaging request: the account passcode the victim had set up years earlier. Because the call still felt legitimate at that point, the victim disclosed it, providing what the source describes as the final credential needed to access the account. Forensic review later showed the SIM swap enabling call and text interception had actually occurred days before this call took place.
Several factors combined to make this attack effective:
Defenders and everyday mobile account holders should watch for a few consistent warning signs:
The most reliable defense is to treat unexpected carrier support calls as suspicious by default: hang up and call back using the official number before sharing any account information. Never share SMS one-time passcodes with anyone who calls, regardless of how legitimate the conversation feels. Secondary credentials such as carrier PINs or account passcodes deserve the same protection as passwords, since they can serve as the final key to a takeover. Finally, because attackers operate within extremely short time windows and can make unauthorized changes quickly, such as canceling a mobile number, any suspected SIM swap or account compromise should be escalated immediately rather than addressed after normal business hours.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
The attacker posed as a wireless carrier representative, opened with a customer satisfaction survey and loyalty discount talk to build trust, then asked the victim to read back a one-time passcode sent via SMS.
After obtaining the OTP, the attacker still needed the account passcode the victim had set up years earlier, and the victim disclosed it because the call still seemed legitimate.
Forensics showed the SIM swap had actually happened days before the call, which let the attacker intercept calls and texts and time the social engineering call to complete the takeover.
Escalate immediately, since attackers operate within extremely short time windows and can make high-impact account changes such as canceling a mobile number very quickly.
“The attack began with an unsolicited call from someone claiming to represent my wireless carrier.” Sounds routine, right? It almost cost them their phone number. The caller opens with a ‘customer satisfaction survey’ and loyalty discounts, sounds helpful, then says: “I’m sending a verification code, just read it back to me.” The text clearly says, “We will never ask for this code,” but they do. Here’s the twist: days earlier, they’d already done a SIM swap in the background. This call is just to grab your account passcode, the “final credential.” As soon as you share it, you’re suddenly logged out while they log in, change settings, even cancel your number. Your move: if anyone calls about your mobile account and asks for a one-time code or your account PIN, hang up and call the number on your carrier’s website yourself.

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…

UK authorities said two Scattered Spider members accessed Transport for London (TfL) by buying partial employee credentials and then tricking TfL’s helpdesk…

Dutch police say the February 2026 breach at Dutch telecom Odido, where data on more than six million customers was stolen, was enabled by social engineering…

Researchers described a long-running fraud campaign where criminals clone real Russian company websites and replace contact and bank details to intercept…

Sophos reports a real Microsoft Teams voice-phishing campaign where attackers pretended to be IT support to convince employees to start remote-access sessions.…

The article describes real-world ways attackers get around multifactor authentication (MFA), including “push bombing” (MFA fatigue), phishing pages that relay…