How to lose an account on the State. services in 5 seconds

Errors when integrating different systems are not so rare. And the main thing here is to receive calls on time and fix these problems.







I want to tell you about a critical vulnerability with such integration and the possibility of losing your account in the state. services.









It all started in the evening. Resting after work, I receive SMS from the state. services with a password for the first login. At first I get confused. Then the realization that something is wrong here. And I climb into the application of the state. services on the phone to check your personal data. And then I discover that I do not have an associated phone number.







After that, panic begins. I am trying to link my phone number to my account, to which I receive an SMS stating that it is already linked to another. After such a message, I start to shake, tk. I realize that the state. services a lot of things are attached. It's good that I have a second phone number. I immediately linked it and changed the password. After that I calmed down more or less. But the sediment remained, as it were.







Screen sms




While I was looking for how to contact the tech. support, my husband came and started talking to me about strange messages from Sberbank. I tell him that I was hacked. And then it turns out what happened as a result.







My husband, like 90% of the population of Russia (not Moscow), receives a gray salary. And he gave me a salary card. And besides that, he also receives a pension on Sberbank. And somehow it so happened that my phone number turned out to be the main one in his personal account of Sberbank. Well, it didn’t matter to me, so no one changed anything.







This year he was forced to issue the Mir card for retirement. And now he received a message that he had to send his card details to the FIU. And that this can be done by pressing one button in the Sberbank application. Well, as they say, he did it. And after these actions, I lost my number to the state. services. More precisely, my number turned out to be tied in his personal account on the state. services. Naturally after that he linked his phone number, and removed mine.







. . , .







. . ( , 30 ) .







, . . . . — — . .. .



















, . — , , . .. . , - . .







, . - .







P.S.





:

, *** .



, , ( — -).




.. , . .








All Articles