FCC rule could make phone accounts richer targets for crypto attackers
Proposed FCC rule requiring carriers to retain customer data could expand attack vectors for crypto theft.

The Federal Communications Commission (FCC) has proposed a rule requiring voice service providers to collect and retain detailed customer information, a move that could inadvertently increase the attractiveness of phone accounts for cryptocurrency attackers.
Under the proposed robocall rule published May 26 (CG Docket Nos. 17-59 and 02-278), providers would need to collect names, physical addresses, government-issued ID numbers, alternate phone numbers, and supporting verification records before granting service. The data would be retained for up to four years after a customer relationship ends.
Security experts note that such aggregated data could become a prime target for attackers seeking to execute SIM-swap attacks or social engineering schemes to gain access to cryptocurrency accounts tied to phone numbers. The richer the data on file, the more valuable each phone account becomes as a stepping stone for crypto theft.
The FCC is currently seeking public comment on the proposed rule. The crypto community may weigh in on potential security implications before the regulation is finalized.