Skip to content

Comment on Substack confirms data breach affects users’ email addresses and phone numbersparent

Comments

Phone number login in 2026 is really just asking for someone to do a SIM swap attack on the victim's account to steal their identity.

Surely a list of services that allow phone number logins exists so that one can avoid signing up in the first place and we would then see it in another connecting breach.

Most banks and credit cards, as far as I’ve seen.

For example, I tried to set up another form of 2FA on Chase, but it still defaults to phone. I can’t disable or change it.

PayPal :(

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.