SIM swap
Moving a victim's phone number onto an attacker's SIM, usually by persuading or paying someone at the carrier. Every code sent to that number now arrives at the attacker instead.
Why it matters to you
SMS is a recovery channel as often as it is a second factor, and this defeats it as both. Where an account matters, bind the factor to a device rather than to a number.
Where we meet it
Carrier insiders are recruited in the open, by network and by country, in the same channels that recruit money mules. The recruitment is visible before the swaps are.
Connected terms
OTP bot
An automated calling service that impersonates a bank or provider to trick victims into reading out their one-time codes. MFA bypass, sold as a subscription.
Drop
A money or goods mule: the recruited (sometimes unwitting) person whose bank account or address launders the proceeds. Recruited openly, in "work" channels, at scale.
Fullz
A complete identity kit for one person (name, national ID, date of birth, address, banking details) packaged for fraud. Sold per record, priced by country and completeness.
Read elsewhere
Where this term stops being vocabulary
Dragnet is where you watch it happen to you
Knowing the word is the cheap half. The platform is the half where the term arrives attached to your domain, with a timestamp and the source it came from.
More from the playbook
Adversary-in-the-middle phishing
A phishing page that proxies the real login instead of imitating it. The victim authenticates against the genuine site through the attacker's server, completes multi-factor as normal, and the attacker keeps the resulting session cookie.
Business Email Compromise (BEC)
Fraud committed from inside a real mailbox: the attacker reads the thread, waits for an invoice and answers it with different bank details. No malware, no attachment, nothing for a scanner to find.
Callback phishing
An email that carries no link and no attachment, only a plausible invoice or subscription notice and a phone number to dispute it. The attack begins when the victim calls, and the person who answers walks them into installing remote access software.
Checker
A tool that tests stolen credentials against a target service in bulk and sorts the live ones from the dead. The industrialized step between a combolist and an account takeover.