Looking Forward – Fraudsters’ Growing Use of Call Forwarding
Blog

Looking Forward – Fraudsters’ Growing Use of Call Forwarding

Introduction

  • Fraudsters are increasingly resorting to call forwarding to receive one-time passcodes (OTP) as part of their persistent endeavors to gain online access to and take over bank and other financial accounts.
  • Call forwarding allows the fraudster to redirect incoming calls from the victim’s phone to a phone number in the fraudster’s possession.
  • Unlike SIM swapping, where the fraudster gains full control of the victim’s cellular service, malicious use of call forwarding only temporarily pauses incoming calls to the victim’s phone but otherwise the service is not interrupted.
  • The simultaneous ring function offers similar opportunities to fraudsters without impacting the victim’s ability to receive calls. In this technique, multiple phones can be reached by dialing the victim’s phone number1.
  • The use of call forwarding to receive OTP codes appears to be attracting interest from fraudsters when attempting to access compromised online bank accounts.
  • Chatter surrounding compromised online bank accounts advertised with call forwarding access increased by 226% in 2024 vs. 2023.
  • As we will discuss below, Telegram chatter reveals several strategies for activating call forwarding on a victim’s phone, including the use of insiders at phone companies, obtaining the victim’s wireless account credentials, and social engineering.

Enabling Call Forwarding

Once a fraudster has acquired a victim’s online account credentials (e.g., online banking, brokerage, treasury services), there are a few techniques for using call forwarding to bypass MFA.

Insiders

The first method of initiating call forwarding on a victim’s account is to use an insider employed at a telecommunication company (e.g., Verizon, AT&T). On Dark Web forums and communities, fraudsters often seek or share such information when advertising compromised accounts for sale. A fraudster can instruct an insider to forward the victim’s calls to a separate phone. Once completed, the fraudster can begin receiving the OTP codes to their device.

Fraudster searching for an insider to assist with enabling call forwarding.
Fraudster searching for an insider to assist with enabling call forwarding.
A fraudster advertising compromised online banking credentials that includes call forwarding for T-Mobile.
A fraudster advertising compromised online banking credentials that includes call forwarding for T-Mobile.

Wireless Account Credentials

Another method to initiate call forwarding involves unauthorized access into online wireless account management portals. In this way, fraudsters obtain the victim’s credentials to their online wireless account (e.g., https://www.att.com/log-in/ or www.verizonwireless.com/login) that have been harvested by malware on the victim’s device. The fraudsters login to those accounts and activate call forwarding. In this method, the fraudster acquires both the victim’s online banking and wireless account credentials, eliminating the need for an insider.

A fraudster using a thumbs up to confirm that they are in possession of the victim’s wireless account credentials that were collected by malware.
A fraudster using a thumbs up to confirm that they are in possession of the victim’s wireless account credentials that were collected by malware.
Fraudster acknowledging the use of a victim’s credentials to activate call forwarding.
Fraudster acknowledging the use of a victim’s credentials to activate call forwarding.

Social Engineering

By impersonating telecommunication companies’ customer service representatives2, fraudsters can trick victims into enabling call forwarding. Mobile carrier websites often provide instructions for activating call forwarding, inadvertently furnishing fraudsters with the opportunity to exploit this feature. For example, for Verizon, an unsuspecting individual could be instructed to dial *723 plus another phone number that is provided by the fraudster, thereby setting up call forwarding4.

Looking Forward

Fraudsters are continually exploring innovative strategies for bypassing MFA. Companies have attempted to mitigate the threat of OTP bots through website banners and messages informing customers that they will never ask for this information and instructing them not to share their OTP codes. SIM swapping has been a popular option among fraudsters, and as mentioned, this technique gives the cybercriminal full control over the victim’s phone service. Call forwarding is the latest approach to circumventing MFA that is gaining steam amongst fraudsters, and it provides fraudsters with a simpler, less complicated option compared to SIM swapping. We expect that call forwarding will continue to grow in popularity and that fraudsters will continue to search for new means of bypassing MFA.