SS7 Flaw Used by Hackers to Drain Bank Accounts Protected by Two Factor Authentication

Advertisement
By Tasneem Akolawala | Updated: 5 May 2017 16:11 IST
Highlights
  • SS7 flaw has been prevalent since many years now
  • Telecom operators have been complacent about it
  • Few users have lost all their money due to SS7 flaw exploit
SS7 Flaw Used by Hackers to Drain Bank Accounts Protected by Two Factor Authentication

German network provider O2 Telefonica has confirmed that few of its subscribers have been drained of their bank accounts, due to hackers exploiting a flaw in the Signaling System 7 (SS7) protocol, used by networks to communicate with each other for many years.

The German company O2 Telefonica has confirmed to Sddeutsche Zeitung that hackers have used an SS7 exploit to drain the bank accounts of few of its subscribers. The hackers intercepted two-factor authentication codes needed for online banking, and after gaining access, emptied their entire bank accounts. This has been occurring for a few months now, the report states.

For security reasons, German banks use a two-factor authentication system, and online customers need to punch a code that is sent to their phone to process transferring the funds from one account to the other. The attackers have exploited this 2FA system, the report ads, allowing them to empty the bank accounts of affected customers easily.

To do this, the hackers first got inside the users' PCs and got hold of sensitive information like login details, password, account balance, and mobile number. "Then they purchased access to a rogue telecommunications provider and set up a redirect for the victim's mobile phone number to a handset controlled by the attackers," The Register explains.

Advertisement

The attackers then logged into victims' bank accounts, preferably at a time when they are asleep, and then transfer out all the money. The code sent to the phone was routed to the criminals, making it easy for them to enter.

The report adds that the SS7 flaw has been an issue since many years, and while researchers have been making noise, and asking telcos to do something, network operators have been very complacent about it. Now, that one of the telcos has confirmed a hack due to the SS7 exploit, a solution may come to fruition. Also, the alternative method proposed to replace SS7, is equally flawed, and the dubbed Diameter protocol cannot be considered as a viable solution for now.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Microsoft Wants Websites to Have an AI-Powered Natural Language Interface
  2. Google's New Beam Video Communication Platform Can Turn 2D Video Into 3D
  3. Nothing Phone 3 Confirmed to Launch Globally in July
  4. iQOO Neo 10 Pro+ With Snapdragon 8 Elite, 6,800mAh Battery Launched
  5. Amazon's Drones Will Now Deliver Apple Products and More to Your Doorstep
  6. Infinix GT 30 Pro Leaked Images Suggest RGB Lighting, Other Design Elements
  7. Gemini 2.5 Series Gets Improved Capabilities and a Deep Think Mode
  8. Apple WWDC 2025 Scheduled From June 9 to June 13: All You Need to Know
  1. Asus ExpertBook P3 Series With AMD Ryzen AI 7 350 Processor Launched at Computex 2025
  2. Tesla on Track to Launch Robotaxi Trial in Austin, Texas, by June End, Musk Says
  3. Stellar Blade Sequel Confirmed by Shift Up, Launch Planned Before 2027
  4. Epic Games' Fortnite Returns to Apple App Store in US After Nearly Five Years
  5. Amazon's Drones Can Now Deliver New Categories of Devices Like iPhone, AirPods and More
  6. Infinix GT 30 Pro Leaked Images Suggest RGB Lighting, Colour Options Ahead of Global Debut
  7. Bitcoin Surges Past $107,000 for First Time Since January as Altcoins Rally
  8. Inheritance OTT Release Date: When and Where to Watch Spy Thriller Movie Online?
  9. America's Sweethearts: Dallas Cowboys Cheerleaders Season 2 OTT Release Date Announced
  10. Night Swim Now Streaming on Netflix: Everything You Need To Know about American Horror Movie
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.