US 12,407,723 B2
System, device, and method of protecting users and online accounts against attacks that utilize SIM swap scams
Avi Turgeman, New York, NY (US); Kfir Yeshayahu, Tzur Yigal (IL); Guy Bauman, Brookline, MA (US); Yaron Dror, Brookline, MA (US); and Erez Zohar, Hoboken, NJ (US)
Assigned to IRONVEST, INC., New York, NY (US)
Filed by IRONVEST, INC., New York, NY (US)
Filed on Mar. 14, 2022, as Appl. No. 17/693,601.
Prior Publication US 2023/0291766 A1, Sep. 14, 2023
Int. Cl. H04L 29/00 (2006.01); H04L 9/40 (2022.01)
CPC H04L 63/1483 (2013.01) [H04L 63/1433 (2013.01); H04L 63/205 (2013.01)] 14 Claims
OG exemplary drawing
 
1. A method comprising:
(a) detecting that a user is requested to input a genuine phone number of the user into a phone number field of an account profile page or an account settings page of a computerized service;
(b) inserting, into said phone number field of said account profile page or said account settings page, a replacement phone number that replaces the genuine phone number of said user at said computerized service;
(c) automatically monitoring and handling, continuously at a remote server, incoming SMS text messages that arrive to said replacement phone number of said user and that request the user to perform an elevated-security operation or to reset user credentials for accessing said computerized service;
wherein the monitoring and handling of step (c) comprise:
(c1) at said remote server, performing analysis of an incoming SMS text message that arrives to said replacement phone number;
(c2) if the analysis indicates that said incoming SMS text message is not requesting from said user to perform an elevated-security operation or to reset user credentials, then: forwarding said incoming SMS text message from the replacement phone number to the genuine phone number of the user;
else, preventing delivery of said incoming SMS text message to the genuine phone number of the user, and instead performing: delivering to the user an indication that an incoming SMS text message, which is requesting from the user to perform an elevated-security operation or to reset user credentials, was received at said replacement phone number; and enabling the user to view said incoming SMS text message via a secure channel and not via regular access to SMS text messages on said genuine phone number.