For $16, Companies Can Reroute Your Text Messages To Hackers Without Your Consent

-


A newly discovered cybersecurity threat came to light after a reporter revealed telecom companies can reroute a person’s text messages to a hacker for a measly amount of $16.

To demonstrate the flaw, Motherboard reporter Joseph Cox shared how a hacker successfully carried out an attack targeting his phone number.

(Photo : Stock Snap from Pixabay)

Using an SMS redirection service by a company called Sakari, the hacker did not only manage to break into Cox’s text messages without consent, but he was also able to receive and reply to the reporter’s text messages without his knowledge.

Cox, later on, contacted other companies that offer SMS redirection services and was told that they had seen this sort of attack before.

This attack not only proved the gaping holes in the telecommunications infrastructure, but it also showed how unregulated commercial SMS tools really are.

Unlike SIM swapping, where a phone completely disconnects from a cellular network, SMS redirection is particularly hard to notice and gives enough time for hackers to compromise the victim’s accounts.

Also Read: Top 5 Best Bulk Texting Services In 2021

Telecommunications Blunder

AT&T, T-Mobile, and Verizon were asked why this type of attack is even possible but diverted the query over to the Cellular Telecommunications and Internet Association (CTIA) – a trade association representing the wireless industry.

CTIA said that they immediately investigated the issue and took precautionary measures as soon as being told of the potential threat.

However, they explained that the carriers were unable to detect any malicious activity and therefore unable to replicate the threat.

Cybersecurity Legislation

The statement issued by CTIA caught the attention of Senate Finance Committee Chairman Ron Wyden, who pointed out the enormity of the threat towards one’s safety and security.

According to the Washington Post, the Democratic senator strongly urged the FCC to intervene and “use its authority to force phone companies to secure their networks from hackers.”

Lawmakers had been debating the importance of passing legislation that requires companies to report major cyber breaches to the government for more than a decade.

However, the recent breaches of SolarWinds and Microsoft Exchange have renewed the issue, forcing companies to actively urge Congress to take immediate action.

Representatives Jim Langevin (D-R.I.) and Michael McCaul (R-Tex.) had been working side-by-side to introduce a pair of bills to identify which incidents would require reporting to the government and if the breach needs to be said to the public.

“We want to give certainty in terms of when customers would need to be notified and when it’s important to report to the government when you have an incident,” said Langevin.

He added that the urgency created by the SolarWinds breach gives their bill a good chance at passing compared to previous attempts, as the incident proved the necessity and timeliness of the legislation.

Meanwhile, the Biden administration had recently announced that a team had been formed to ramp up coordination between the private sector and the government.

The White House is also looking at potential solutions, such as a rating system for software and one that requires home devices to come with a security label.

The administration clarified that the President does not intend to grant the government additional authorities to surveil domestic Internet traffic for hackers.

Related Article: How to Read Someone’s Text Messages Without Their Phone Free  

This article is owned by Tech Times

Written by Lee Mercado

ⓒ 2018 TECHTIMES.com All rights reserved. Do not reproduce without permission.





Source link

Ariel Shapiro
Ariel Shapiro
Uncovering the latest of tech and business.

Latest news

Aiper’s Scuba V3 Pool Robot Brings AI Vision Underwater

The app also includes access to two scheduled operational modes for those who would like to leave the...

I Tried DoorDash’s Tasks App and Saw the Bleak Future of AI Gig Work

The flash from my iPhone camera illuminates my dirty socks and underwear as I hold each item up...

Cyberattack on a Car Breathalyzer Firm Leaves Drivers Stuck

United States law enforcement this week took down the Aisuru, Kimwolf, JackSkid, and Mossad botnets, a slate of...

‘Jury Duty Presents: Company Retreat’ Almost Makes Corporate Culture Seem Fun

Anthony Norman is your typical Gen Z worker: 25, a little wayward, and struggling to find a full...

How BYD Got EV Chargers to Work Almost as Fast as Gas Pumps

Somehow, the whole thing got even faster. Earlier this month, Chinese automaker BYD announced that its Flash Chargers,...

Anthropic Denies It Could Sabotage AI Tools During War

Anthropic cannot manipulate its generative AI model Claude once the US military has it running, an executive wrote...

Must read

You might also likeRELATED
Recommended to you