2FA – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Fri, 20 Jun 2025 02:47:45 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 2FA – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Brothers-in-Law Steal $794,000 From Elderly Victims After Porting Phone Numbers To Override Mobile 2FA: DOJ https://earlybirdsinvest.com/brothers-in-law-steal-794000-from-elderly-victims-after-porting-phone-numbers-to-override-mobile-2fa-doj/ https://earlybirdsinvest.com/brothers-in-law-steal-794000-from-elderly-victims-after-porting-phone-numbers-to-override-mobile-2fa-doj/#respond Fri, 20 Jun 2025 02:47:44 +0000 https://earlybirdsinvest.com/brothers-in-law-steal-794000-from-elderly-victims-after-porting-phone-numbers-to-override-mobile-2fa-doj/

Two California men face up to 30 years in jail for allegedly operating a scheme that fraudulently accessed the bank accounts of elderly victims and stole their funds.

According to the U.S. Attorney’s Office, Eastern District of California, a 17-count indictment unsealed on Tuesday charges brothers-in-law Ayman Alaaraj and Ahmad Nassar with bank fraud and aggravated identity theft.

Court documents show that in May 2023, Nassar took over several bank accounts belonging to two elderly victims at two separate banks using sophisticated techniques, such as porting over the phone number belonging to one of the victims.

The method enabled Nassar to access the accounts and bypass the banks’ two-factor authentication protection. Nassar, occasionally assisted by Alaaraj, then drained the accounts and ran up unpaid credit card debits, causing more than $794,000 in losses to the victims.

The two men then moved the stolen money through the pass-through accounts created under the victim’s names, as well as funneled $100,000 through Alaaraj’s businesses.

The defendants eventually transferred the money to themselves using ATM cash withdrawals, personal checks, Western Union transactions and Zelle transactions. They also used the stolen funds to pay credit cards, engage in online gambling and buy a Mercedes.

If found guilty, the two men face up to 30 years of jail time and a $1 million fine for each count of bank fraud. They also face a mandatory prison term of two years and a fine of up to $250,000, or twice the gross gain or gross loss, for the aggravated identity theft count.

Follow us on X, Facebook and Telegram

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Surf The Daily Hodl Mix

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: Midjourney

]]>
https://earlybirdsinvest.com/brothers-in-law-steal-794000-from-elderly-victims-after-porting-phone-numbers-to-override-mobile-2fa-doj/feed/ 0 43031
Coinbase fixes 2FA log error making people think they were hacked https://earlybirdsinvest.com/coinbase-fixes-2fa-log-error-making-people-think-they-were-hacked/ https://earlybirdsinvest.com/coinbase-fixes-2fa-log-error-making-people-think-they-were-hacked/#respond Mon, 28 Apr 2025 06:40:10 +0000 https://earlybirdsinvest.com/coinbase-fixes-2fa-log-error-making-people-think-they-were-hacked/

Coinbase

Coinbase has fixed a confusing bug in its account activity logs that caused users to think their credentials were compromised.

As BleepingComputer first reported earlier this month, Coinbase had mistakenly labeled failed login attempts with incorrect passwords as two-factor authentication failures in the Account Activity logs.

When a threat actor attempted to access someone’s account and used the wrong password, error messages stating “second_factor_failure” or “2-step verification failed” would be shown instead.

These entries imply that a valid username and password were entered, but the login was blocked by 2-factor authentication, such as entering the wrong one-time passcode from an authenticator app.

Numerous Coinbase users contacted BleepingComputer with concerns that Coinbase had been breached, as their passwords were unique to the site, there was no sign of malware, and no other accounts were affected.

Incorrect 2FA error message in Coinbase Account Activity logs
Incorrect 2FA error message in Coinbase Account Activity logs

However, Coinbase confirmed to BleepingComputer that its logging system was incorrectly attributing login attempts with incorrect passwords as “2FA failures,” even though the attackers had not successfully reached the 2FA stage.

Coinbase has now pushed an update to fix this incorrect labeling so that “Password attempt failed” logs are shown in Account Activity instead.

Bugs like this are essential to fix as they cause unnecessary panic, with users telling BleepingComputer that they had reset all their passwords and spent hours trying to determine if their devices were compromised due to this bug.

These mislabeled entries could have also been used in social engineering attacks to convince users their account credentials were compromised, potentially allowing threat actors to gain sensitive information.

Threat actors commonly target Coinbase customers in social engineering attacks to access their accounts and drain the stored cryptocurrency.

BleepingComputer was told that threat actors used these mislabeled error messages as part of such attacks, but could not independently verify if that was true.

However, ongoing campaigns use automated SMS phishing (smishing) attacks and voice calls to impersonate Coinbase and attempt to steal 2FA tokens or credentials, so all users should be wary.

Coinbase has said in the past that they will never call customers or send text messages requesting they change passwords or reset two-factor authentication, and that customers should treat all such messages as scams.

]]>
https://earlybirdsinvest.com/coinbase-fixes-2fa-log-error-making-people-think-they-were-hacked/feed/ 0 33214