Survey Call Led to SIM Swap Near-Takeover

Security Week Feed · High sophistication
Last updated July 30, 2026

An attacker called the victim pretending to be their mobile carrier, built trust with a “customer satisfaction survey,” then asked the victim to read back an SMS one-time passcode and a long-standing account passcode. The attacker had already initiated (and days earlier executed) a SIM swap, then used the collected details to log in, hijack the session, and make unauthorized account changes before the victim recovered access.

How the Attack Unfolded

This incident began with an unsolicited phone call from someone claiming to represent the victim's wireless carrier. The caller opened with a customer satisfaction survey and a discussion of loyalty discounts, a low-pressure pretext designed to build rapport before any sensitive request was made. Once trust was established, the caller asked the victim to read back a one-time passcode that had just been sent to their phone. Believing the interaction was routine, the victim complied, unknowingly approving an authentication request initiated by the attacker.

The caller then pursued a second, more damaging request: the account passcode the victim had set up years earlier. Because the call still felt legitimate at that point, the victim disclosed it, providing what the source describes as the final credential needed to access the account. Forensic review later showed the SIM swap enabling call and text interception had actually occurred days before this call took place.

Why the Social Engineering Worked

Several factors combined to make this attack effective:

  • The pretext layered a low-stakes survey and discount offer before ever asking for sensitive data, normalizing the request sequence.
  • The attacker already possessed personal account details, which made the call feel authentic and reduced the victim's suspicion.
  • Requesting the OTP and the passcode as two separate steps spread out the disclosure, so neither request alone seemed like a full account compromise.
  • The victim had no immediate way to distinguish a legitimate carrier support call from an impersonation attempt.

What to Watch For

Defenders and everyday mobile account holders should watch for a few consistent warning signs:

  • Unsolicited calls asking for authentication information, even when framed as a survey or benefit discussion.
  • Any request to read back a one-time passcode. Legitimate providers state they will never ask for this.
  • Callers who already know account specifics, which can indicate stolen or breached personal data being used to build credibility.
  • Being unexpectedly logged out shortly after authenticating, which can indicate a concurrent session opened by an attacker.

Building Resistance

The most reliable defense is to treat unexpected carrier support calls as suspicious by default: hang up and call back using the official number before sharing any account information. Never share SMS one-time passcodes with anyone who calls, regardless of how legitimate the conversation feels. Secondary credentials such as carrier PINs or account passcodes deserve the same protection as passwords, since they can serve as the final key to a takeover. Finally, because attackers operate within extremely short time windows and can make unauthorized changes quickly, such as canceling a mobile number, any suspected SIM swap or account compromise should be escalated immediately rather than addressed after normal business hours.

Key findings

  • Attack started as an unsolicited phone call impersonating the wireless carrier, using a satisfaction survey and loyalty discounts to build trust.
  • Attacker asked the victim to read back a one-time passcode sent via SMS, despite the message stating the carrier would never ask for it.
  • Attacker’s main goal was obtaining the account passcode/PIN; the victim disclosed it, providing the “final credential.”
  • Victim observed being logged out after authenticating, consistent with an attacker logging into the same account (session takeover/concurrent session).
  • After quick recovery via email-based OTP, attacker still made unauthorized account changes including canceling the mobile number.
  • Forensics indicated the SIM swap happened days before the call, enabling interception of calls/texts.

Who’s being targeted

  • Commonly targeted roles: Executives, All staff (personal mobile account risk), Customer service/call center teams, Fraud/incident response teams, IT/helpdesk (identity verification procedures).
  • Affected industries: Telecommunications, Any consumer-facing organization with call centers and account recovery flows.
  • Attack channels: vishing.
  • Impersonated: Wireless carrier customer service representative.

Red flags to watch for

  • Unsolicited call asking for authentication information
  • Request to share a one-time code that should never be shared
  • Caller relies on personalization/familiar account details to seem legitimate
  • Asking for an account passcode/PIN over an inbound/outbound call
  • Layering requests (survey → OTP → passcode) to normalize disclosure
  • Caller already knows account details, suggesting breached/stolen data use
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the attacker get the OTP?

The attacker posed as a wireless carrier representative, opened with a customer satisfaction survey and loyalty discount talk to build trust, then asked the victim to read back a one-time passcode sent via SMS.

What was the final credential the attacker needed?

After obtaining the OTP, the attacker still needed the account passcode the victim had set up years earlier, and the victim disclosed it because the call still seemed legitimate.

How was the SIM swap connected to the call?

Forensics showed the SIM swap had actually happened days before the call, which let the attacker intercept calls and texts and time the social engineering call to complete the takeover.

What should someone do if they suspect a SIM swap or account compromise?

Escalate immediately, since attackers operate within extremely short time windows and can make high-impact account changes such as canceling a mobile number very quickly.

Read the video transcript

“The attack began with an unsolicited call from someone claiming to represent my wireless carrier.” Sounds routine, right? It almost cost them their phone number. The caller opens with a ‘customer satisfaction survey’ and loyalty discounts, sounds helpful, then says: “I’m sending a verification code, just read it back to me.” The text clearly says, “We will never ask for this code,” but they do. Here’s the twist: days earlier, they’d already done a SIM swap in the background. This call is just to grab your account passcode, the “final credential.” As soon as you share it, you’re suddenly logged out while they log in, change settings, even cancel your number. Your move: if anyone calls about your mobile account and asks for a one-time code or your account PIN, hang up and call the number on your carrier’s website yourself.

Similar attacks

How Attackers Bypass MFA in the Real World

How Attackers Bypass MFA in the Real World

The article describes real-world ways attackers get around multifactor authentication (MFA), including “push bombing” (MFA fatigue), phishing pages that relay…

July 29, 2026