Most Popular Detection – Vishing/Rogue MFA Takeover/Helpdesk-Support Impersonation 2026: Phone Number Change Followed by MFA Factor Reset (SIM-Swap Precursor)

Detects a suspicious sequence of events where a user's registered phone number or recovery contact method is updated, followed shortly by an MFA factor reset or new factor enrollment. This pattern is a common indicator of a SIM-swap attack, where an attacker intercepts SMS-based MFA codes after hijacking the victim's phone number.