Skip to main content

Phone-based attacks

Recognising and avoiding phone-based attacks. How to spot calls and text messages impersonating Webot support, and why you should never share account credentials, verification codes or transfer funds on request.

What is a phone-based attack?

A phone-based attack (SIM-swap or phone-port attack) is when an attacker has their target's phone number transferred to a mobile device under the attacker's control. Fraudsters do this through various means, including identity theft and socially engineering mobile carrier customer-support representatives. This attack threatens all accounts using SMS-based 2-step verification and any account that can be recovered using phone-based authentication.

How can I prevent a phone-based attack?

To help protect your Webot account from this attack, we highly recommend using a stronger form of 2-factor authentication, such as a Time-based One Time Password (TOTP) with a mobile authenticator app like Google Authenticator.

Learn more about keeping your Webot account secure.

Did this answer your question?