It is not cyber warfare. It is a SIM swap

This URL still frames hijacking as cyber warfare and advanced infrastructure security. Keep it. Brian Krebs has spent years documenting the boring version: account takeovers, SIM swaps, helpdesks. The UK NCSC’s notes on phishing are enough. CISA on SIM swap attacks (if the URL moves, search their SIM swap guidance) is the threat model for a domain investor, not a nation-state deck.

I’m Mostapha. I buy and sell names from Morocco. Nobody needed a cyber command to take a name whose SMS 2FA lived on a cheap prepaid. Prevention is the mailbox: registrar email is the lock and the checklist. Incident: freeze first. Web3 does not sit the SIM: that costume.

How names actually leave

  • SMS 2FA. Attacker ports the number, resets mail, resets registrar.
  • Reused password, already in a dump: Have I Been Pwned.
  • A “hosting specialist” who wants the EPP code. That is not a migrate: don’t unlock.
  • A buyer who wants nameservers changed before escrow funds. That is not M&A: most sales are a push.

App-based or hardware 2FA on mail and registrar. Not SMS. Recovery codes on paper. Phone carrier PIN. Lookup after any scare: ICANN Lookup. If WHOIS or NS moved, freeze and ticket not a blog about APT groups.

cyber warfare

What you do not need

A threat-intel subscription for a leftover. An “infrastructure security program” on managed WordPress. If the letters fail the checker, do not militarise them. FAQ. A hacked site can still smear a good name: clean or park after the registrar is still.

Governance remains a drop list, not a war room: spreadsheet and drops.

Decision

  1. Kill SMS 2FA on anything that can move a domain.
  2. Mailbox you read, lock on, no auth codes in chat.
  3. If it moves: freeze, registrar, compliance. Then ask if the name was worth the night.

Keep the Google row. Cyber warfare was the old fog. The theft is a phone shop and a reused password.

Leave a Comment