SS7 Flaw Used by Hackers to Drain Bank Accounts Protected by Two Factor Authentication

Advertisement
By Tasneem Akolawala | Updated: 5 May 2017 16:11 IST
Highlights
  • SS7 flaw has been prevalent since many years now
  • Telecom operators have been complacent about it
  • Few users have lost all their money due to SS7 flaw exploit

German network provider O2 Telefonica has confirmed that few of its subscribers have been drained of their bank accounts, due to hackers exploiting a flaw in the Signaling System 7 (SS7) protocol, used by networks to communicate with each other for many years.

The German company O2 Telefonica has confirmed to Sddeutsche Zeitung that hackers have used an SS7 exploit to drain the bank accounts of few of its subscribers. The hackers intercepted two-factor authentication codes needed for online banking, and after gaining access, emptied their entire bank accounts. This has been occurring for a few months now, the report states.

For security reasons, German banks use a two-factor authentication system, and online customers need to punch a code that is sent to their phone to process transferring the funds from one account to the other. The attackers have exploited this 2FA system, the report ads, allowing them to empty the bank accounts of affected customers easily.

Advertisement

To do this, the hackers first got inside the users' PCs and got hold of sensitive information like login details, password, account balance, and mobile number. "Then they purchased access to a rogue telecommunications provider and set up a redirect for the victim's mobile phone number to a handset controlled by the attackers," The Register explains.

Advertisement

The attackers then logged into victims' bank accounts, preferably at a time when they are asleep, and then transfer out all the money. The code sent to the phone was routed to the criminals, making it easy for them to enter.

The report adds that the SS7 flaw has been an issue since many years, and while researchers have been making noise, and asking telcos to do something, network operators have been very complacent about it. Now, that one of the telcos has confirmed a hack due to the SS7 exploit, a solution may come to fruition. Also, the alternative method proposed to replace SS7, is equally flawed, and the dubbed Diameter protocol cannot be considered as a viable solution for now.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Annagaru Vostaru OTT Release: When, Where to Watch Karthi's Action-Comedy
  2. Google Pixel 10a Review: More of the Same?
  3. Here's When the Poco C85x 5G Will be Launched in India
  4. iPhone 17e vs OnePlus 15R vs iQOO 15R: Price in India, Features Compared
  5. Vikram On Duty OTT Release: When, Where to Watch This Telugu Crime Thriller
  6. OTT Releases This Week: Gandhi Talks, Subedaar, War Machine, Hello Bachhon, and More
  7. Truke TruClips With Open-Ear Design Launched in India: See Price, Features
  8. The Upcoming Poco X8 Pro Series Could be Launched Globally on This Date
  1. Vikram On Duty OTT Release: When, Where to Watch Nikhil Maliyakkal’s Telugu Crime Thriller
  2. Annagaru Vostaru OTT Release: When, Where to Watch Karthi’s Telugu Action-Comedy
  3. Local Times OTT Release: Know When and Where to Watch the Tamil Comedy Drama Online
  4. Vivo X300 Max With Zeiss Cameras and Android 16 Spotted at MWC 2026, Could Launch Soon
  5. WhatsApp Update Introduces Support for Discovering Stickers While Typing Emoji: How It Works
  6. This AI-Powered Portable Device Claims to Detect Microphones and Jam Audio Recordings
  7. Poco X8 Pro Series Global Launch Date Leaked Ahead of Anticipated Debut: Expected Price, Specifications
  8. MacBook Neo Geekbench Scores Indicate It Performs on Par With iPhone 16 Pro Max
  9. Xiaomi Testing Experimental AI Agent Miclaw, Can Perform Complex Tasks Across Devices
  10. Dear Radhi OTT Release: Where to Watch the Tamil Thriller Online?
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.