Hacker took advantage of the vulnerability in SS7 to steal bank accounts
Earlier this year, many hackers took advantage of Signaling 7 vulnerabilities (Signaling System No. 7 (SS7) as the phone protocol used to set up most calls in PSTN) to pass. Two-factor verification and stealing money from bank accounts in Germany, the German newspaper Suddeutsche Zeitung said.
Hacker steals login information through fake emails, claiming to come from the victim's bank. Then use the vulnerabilities in SS7 to redirect SMS messages requesting confirmation of money transfer transactions. On Ars Technica, representative of O2 Telefonica said: " Criminals perform attacks from the international mobile network in the middle of January ." " The attack will redirect SMS messages from customers to attackers ."
Ars Technica said security researcher Karrsten Nohl described the potential impact of errors in SS7 late last year by recording calls and tracking the location of US House member Ted Lieu.
Earlier this week, Lieu posted a line on Twitter saying, " I have urgently requested the FCC and the telecommunications industry to fix the security flaw in SS7. Perhaps losing money in the bank will cause them to act ."
A warning to the mobile operator
Mark Windle, Mavenir's chief marketing and security manager, told eSecurity Planet that the news should be considered a warning to the mobile user community. "The network has collaborated to understand how to exploit vulnerabilities and eliminate them ," he said.
" SS7 technology can eventually be replaced with Diameter or SIP but at least SS7 will last for at least 10 years. And simply canceling such a protocol is not a solution ." Windle added: " As long as there is a national and international connection, the door is still there ."
" At the same time, by continuing to overcome security problems in signaling protocols through the use of optimized multi-layer solutions, operators can make users more confident, reducing the proportion of customers leaving. The product and most importantly protect mobile devices, "he added.
Balance between security and convenience
A recent survey of more than 800 representatives from financial institutions around the world showed that 24% of banks face the identification of customers when trading through online services, carefully number.
The survey funded by Kaspersky Lab and implemented by B2B International also results in 30% of banks encountering security incidents, affecting Internet banking services, and expected increase in financial losses. The main reason for fraud in the next 3 years will be 59%. 38% of respondents said that the balance between prevention methods and customer convenience is one of the biggest concerns.
" While thinking of other approaches to securing mobile and digital trading channels, banks still have to avoid putting pressure on customers, " said the head of the fraud protection department. Kaspersky Lab Alexander Ermakovich said.
You should read it
- Many serious vulnerabilities have been discovered that allow attackers to take full control of the 4G router
- Signs show clearly that your system is being hacked
- The unsafe 'feature' on UC Browser allows hackers to take control of Android phones remotely
- Anyone must memorize these golden rules to secure bank accounts
- iPhone is stuck with a dangerous security error
- Basic operations to remove fake security software
- IBM developed a new technology to patch security holes
- Security vulnerabilities threaten more than 1 billion Android smartphones
May be interested
- How to protect bank accounts, Facebook, ... from appropriationthese types of hidden extensions containing malware can steal personal information, attack bank accounts, gmail, facebook, ... easily.
- It turns out this is how hackers attack your computer through the main screenthe video clearly shows how he entered the user's computer through the main screen, creating a vulnerability on the computer to steal personal information. in this way, the hacker can even change the amount of money in the user's bank account.
- Security experts discovered that the line appropriated bank accounts, Facebook, Gmail ... very large in Vietnam, you can also be a victimmany types of accounts, from bank accounts to website administration accounts.
- China - hacker 'factory'with just a few keystrokes, the nickname hacker majia turned up the screen showing his latest victims.
- Detecting a Thunderbolt flaw allows a hacker to steal system data for 5 minutesrecently, international security researcher bjorn ruytenberg unexpectedly discovered a vulnerability called 'thunderspy' that exists in thunderbolt ports, allowing hackers to easily steal data.
- Hackers Use Malicious Google Ads to Steal Users' Microsoft Accountsthere is a dangerous trend being deployed by the global hacker community, which is abusing the google ads platform to spread malicious code.
- The Ministry of Public Security warned users to warn of bank account theft when withdrawing money at ATMsaccording to the ministry of public security, the operation of criminals using high technology is increasingly sophisticated. they can use high-tech devices located at many public atms to steal bank account information to hijack cardholders' assets or use fake bank cards to withdraw money at atms. .
- Windows 365 accounts and passwords can be stolen easilyif the hacker gets into the system, the hacker can query the windows 365 user account and password in plain text.
- 9 apps that scam and steal users' Facebook accountsaccording to a report from security researchers, there are 9 android apps on the play store created with the purpose of tricking users and stealing their facebook accounts.
- A series of famous accounts were hacked, TikTok issued an urgent announcementhackers took advantage of an undisclosed security vulnerability on the short video platform tiktok to attack the accounts of celebrities and big brands such as cnn, sony and paris hilton.