Cybercriminals target Banks and Financial Firms intercepting calls and SMS text messages

 

 

 

 

 

 

 

 

 

 

Background

The capability to conduct this type of “man in the middle attack”  is now widely available and in the hands of financially-driven cybercriminal groups.  The National Cyber Security Centre (NCSC) confirmed that SS7* is being used to intercept codes used for banking.  “We are aware of a known telecommunications vulnerability being exploited to target bank accounts by intercepting SMS text messages used as 2-Factor Authentication (2FA)”.  As the threat landscape continues to evolve so must a firm’s security posture.  The financial industry has seen an increased adoption rate in multi-factor authentication.  Many online financial providers now send a SMS text with a one-time code.  Consequently, Cyber criminals are now leveraging advanced machine learning techniques and launching more sophisticated attacks. 

*signaling System 7 (SS7) is a telephony protocol used world wide to setup and tear down  phone calls and used for SMS messaging.

 Technical Overview

Multi-factor authentication requires two of the following three components: 

  1. Something the user knows (like a password)
  2. Something the user has (like a mobile device)
  3. Something that is the user (fingerprint, iris scan, voice print)

Cyber Criminals typically gain access to the victim’s password through a phishing attempt or a credential spill from a previous data breach.  With the introduction of this “man in the middle attack” the Cyber Criminal no longer needs the victim’s cell phone as they are able to intercept the SMS message due to the inherent flaws in the global telecommunication signaling (SS7) infrastructure.

 Recommendation

  1. Implement a multi-layered Cybersecurity framework to mitigate the risk of phishing attempts and the impact of credential spills.
  2. Select a multi-factor authentication (MFA) provider that does not rely on SMS but rather requires an application on the mobile device.
  3. Leverage a Mobile Device Management Platform to properly secure mobile devices.

 Additional Details on these recent SS7 attacks can be found at:

https://www.technadu.com/telecom-infrastructure-ss7-attacks-rise/56704/

https://motherboard.vice.com/en_us/article/mbzvxv/criminals-hackers-ss7-uk-banks-metro-bank

Share:

Leave a Reply

Your email address will not be published. Required fields are marked *

*

HTML tags are not allowed.