Critical 2026 Detection — SMS/Voice MFA Method Re-Registered to New Phone Number
Detects a suspicious sequence of events where a user modifies their MFA phone number, followed within 30 minutes by a sign-in event flagged with 'impossibleTravel' or 'unfamiliarFeatures' risk. This pattern is indicative of potential SIM-swap fraud, where an attacker has hijacked the user's phone number to receive MFA prompts and then attempts to access the account from an anomalous location.
Sigma

