Protecting High-Profile Accounts: SIM Swaps, Phishing and 2FA
Public figures lose accounts to SIM swaps, phishing and impersonation. A practical guide to 2FA, recovery codes and the habits that keep a known name safe.
When a public figure loses control of an account, the damage is rarely limited to one password. A hijacked profile can publish a fake announcement to millions, message a private contact list, empty a crypto wallet or quietly read years of conversations. The more recognisable the name, the more valuable the account, and the more effort attackers will spend to take it.
The good news is that most account takeovers follow a small number of well understood patterns. Close those patterns and you remove most of the risk. This guide covers the main routes attackers use, the protections that work, and how a private, invite-only platform like VOIDEX approaches identity differently.
Why known names are targeted
A public figure's account has three kinds of value. It has reach, which can be used to promote a scam to an audience that trusts the name. It has contacts, many of them valuable in their own right. And it has history: private messages, drafts, photographs and plans.
In July 2020, attackers took over the Twitter accounts of prominent people and companies and used them to promote a cryptocurrency scam. Twitter later explained that the attackers had targeted a small number of its own employees with a phone spear phishing attack to reach internal tools. The accounts themselves had done nothing wrong. The lesson is that an account is only as safe as every route that can reach it, including support desks and internal staff.
The main routes to a takeover
SIM swapping
In a SIM swap, an attacker persuades or bribes a mobile carrier to move a victim's phone number onto a SIM card the attacker controls. From that moment, every text message and call meant for the victim goes to the attacker, including password reset codes. The FBI has warned publicly about criminals using SIM swaps to steal accounts and funds.
Public figures are particularly exposed because their phone numbers circulate widely: among staff, agents, venues, production teams and old contacts. Once a number is known, it can be targeted.
Phishing
Phishing has become polished. A login page can be a pixel-perfect copy of the real one. A message can appear to come from a platform's verification team, a brand partner or a festival organiser. Some attacks relay the victim's login in real time, capturing the password and the one-time code together.
Impersonation
Not every attack takes over an account. Some simply create a convincing copy. A lookalike profile messages fans, collaborators or family members, asks for money, requests a private phone number or tries to arrange a meeting. The real person often finds out last.
Weak recovery paths
Many services let you recover an account through email, text message or answers to security questions. For a public figure, the answers to security questions may be in a published interview. A recovery email that has not been secured becomes the easiest way into everything else.
Two-factor authentication, done properly
Two-factor authentication is essential, but not all second factors are equal.
- Text message codes are the weakest option. They are better than nothing, but they are exposed to SIM swaps and interception. NIST's digital identity guidelines, SP 800-63B, treat SMS as a restricted authenticator for this reason.
- Authenticator apps are stronger. A time-based code generated on the device does not travel through the phone network.
- Hardware security keys and passkeys are the strongest. They are bound to the real website, so a phishing page cannot use them. CISA describes this family of methods as phishing-resistant MFA.
For any account that matters, remove the phone number as a recovery or login method wherever the service allows it, and use an authenticator app or a security key instead.
Recovery codes are the keys to the house
Most serious services offer recovery codes: a set of one-time codes that let you back into your account if you lose your second factor. They are often generated once, shown once and forgotten. For a public figure, they deserve the care you would give a passport.
Good practice is simple:
- Write recovery codes down or store them in a password manager you trust, never in a note on the same phone.
- Keep a second copy somewhere physically separate.
- Know who else, if anyone, has access to them. A former assistant with a copy of your recovery codes is a former assistant with your account.
- When a team member leaves, rotate codes and passwords they had access to.
Habits that close most of the gaps
- Use a unique password for every account, generated by a password manager.
- Keep the number that protects your accounts private. Consider a separate number that is never shared, used only for the carriers and services that insist on one.
- Ask your mobile carrier about account locks or a port-out PIN, so your number cannot be moved without extra checks.
- Never log in from a link. Open the app or type the address yourself.
- Agree a verification phrase with the people closest to you, so a message asking for money or a private number can be checked.
- Review which devices are signed in, and remove the ones you do not recognise.
- Separate your public presence from your private conversations. The account that talks to the world should not be the place where your family talks to you.
How VOIDEX approaches identity
VOIDEX is an invite-only, end-to-end encrypted platform owned by CNOTA, free and without ads, third-party trackers or ad pixels. Its design reduces several of the risks above by construction.
Private conversations live apart from the public account. In VOIDEX Messenger, direct messages use a hybrid post-quantum key agreement (X25519 with ML-KEM-768) and a double ratchet with post-quantum re-keying, so each message has its own key. Keys are created on the member's own devices, and VOIDEX's servers store only public keys and ciphertext. Someone who gets into a server does not get the conversations.
Keys are checked, not assumed. Impersonation often depends on quietly swapping an identity. On VOIDEX, every device key change is appended to a public, append-only key transparency log, and clients refuse keys that are not in it. Tree heads are signed with Ed25519 and ML-DSA-65, public endpoints let anyone audit the log, and an independent witness watches it.
The recovery code belongs to you alone. Each VOIDEX member has a recovery code that opens their message history on a new device. VOIDEX never holds it. That means no support desk can be talked into handing it over, which closes the route used in so many takeovers elsewhere. It also means a lost code cannot be restored by anyone, so it needs the same care as any other recovery code. Members can switch the encrypted history copy off if they prefer. We explain the trade in own your keys.
Reach cannot be bought. On VOIDEX nobody can pay for reach, and there are no ads. A hijacked or fake account has no advertising system to amplify it.
A public face, and a private voice. In VOIDEX Space, every member has a public Face and an anonymous Phantom. VOIDEX never publishes a link between the two. For a public figure, that means a place to be known and a separate place to simply speak. Read more in private social networks for public figures.
Honest limits
No platform can protect an account whose owner hands the code to someone else, or a phone that is unlocked in the wrong hands. VOIDEX protects its own accounts and conversations; your other accounts still need the habits described above. Public posts in VOIDEX Space and public channels are not end-to-end encrypted, because they are meant to be seen, and they are labelled as such.
The short version
Most high-profile account takeovers come down to a phone number, a convincing login page or a recovery path that was never secured. Move off text message codes, protect your recovery codes like documents, keep private conversations away from public accounts, and check identities before you trust them.
VOIDEX is invite-only. Ask for an invitation, or see how VOIDEX checks every key.
Sources
- Twitter, An update on our security incident (July 2020): https://blog.twitter.com/en_us/topics/company/2020/an-update-on-our-security-incident
- FBI IC3, Public Service Announcement on SIM swapping (February 2022): https://www.ic3.gov/Media/Y2022/PSA220208
- NIST, SP 800-63B Digital Identity Guidelines: https://pages.nist.gov/800-63-3/SP800-63B.html
- CISA, Implementing Phishing-Resistant MFA: https://www.cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf
Enter VOIDEX
VOIDEX is invite-only and free, with no ads and no trackers. Messages are protected by hybrid post-quantum encryption (X25519 with ML-KEM-768) and checked against a public key transparency log. VOIDEX runs in your browser and as apps for Windows and Mac, with iPhone and Android on the way.
Explore the Voidverse
VOIDEX is one private universe: post-quantum encrypted messaging, an anonymous social layer, short video, collectibles and a private window onto the web.



