Twitter CEO hack highlights dangers of ‘SIM swap’ fraud

Published on Sep 04, 2019 07:41 AM IST
Jack Dorsey became the latest target of so-called “SIM swap” fraud which enables a fraudster to trick a mobile carrier into transferring a number -- potentially causing people to lose control not only of social media, but bank accounts and other sensitive information.
Twitter chief executive Jack Dorsey.(Reuters Photo)
Twitter chief executive Jack Dorsey.(Reuters Photo)
Washington | ByAgence France-Presse

Even with considerable security precautions in place, Twitter chief executive Jack Dorsey became the victim of an embarrassing compromise when attackers took control of his account on the platform by hijacking his phone number.

Jack Dorsey became the latest target of so-called “SIM swap” fraud which enables a fraudster to trick a mobile carrier into transferring a number -- potentially causing people to lose control not only of social media, but bank accounts and other sensitive information.

This type of attack targets a weakness in “two factor authentication” via text message to validate access to an account, which has become a popular break-in method in recent years.

Twitter said Friday the account was restored after a brief time in which the attackers posted a series of offensive tweets.

But Ori Eisen, founder of Arizona-based security firm Trusona, which specializes in authentication without passwords, said the rapid fix should not be seen as an answer to the broad problem of SIM swap fraud.

“The problem is not over,” Eisen said, noting that these kinds of attacks have been used to take over other high-profile social media accounts and for various kinds of fraud schemes.

Eisen said it’s not clear how many people are attacked in this manner but that automated technology can create billions of calls that lure people into giving up information or passwords.

Switching phones, or fraud?

Some analysts say hackers have found ways to easily get enough information to get a telecom carrier to transfer a number to a fraudster’s account, especially after hacks of large databases which result in personal data sold on the so-called “dark web.”

“Mobile accounts’ text messages can be hijacked by sophisticated hardware techniques, but also by so-called ‘social engineering’ -- convincing a mobile provider to migrate your account to another, unauthorized phone,” said R. David Edelman, a former White House adviser who heads a cybersecurity research center at the Massachusetts Institute of Technology.

“It only takes a few minutes of confusion to make mischief like Dorsey experienced.”

Thousands of these attacks have been reported in countries where mobile payments are common, including in Brazil, Mozambique, India and Spain.

Researchers at the security firm Kaspersky say security systems by many mobile operators “are weak and leave customers open to SIM swap attacks” especially if the attackers are able to gather information such as birth dates and other data.

In a recent blog post, Kaspersky researchers Fabio Assolini and Andre Tenreiro said some cases come from cybercriminals paying off corrupt employees of mobile carriers -- for as little as $10 to $15 per victim.

“The interest in such attacks is so great among cybercriminals that some of them decided to sell it as a service to others,” the researchers wrote.

In Brazil, some criminals have taken over victims’ WhatsApp accounts, using it to ask the person’s friends for “urgent payment,” Assolini and Tenreiro wrote.

‘Ripe’ for fraud

“This is a pretty ripe avenue for fraud,” said Joseph Hall, technologist at the Center for Democracy & Technology in Washington.

Hall said some carriers are using artificial intelligence to separate the legitimate SIM card replacements from fraud, but that this has not been universally deployed.

“I would blame the carriers for not having more robust ways to authenticate users,” he added, while also calling on Twitter to offer better safeguards.

A faked tweet from the president or other prominent person could lead to “devastating consequences,” such as a plunge in financial markets, Hall said.

“This kind of thing becomes hard to counteract, because even after the information comes out that it’s a hoax, people may not believe it,” he said.

The Dorsey case, Hall said, highlights the need for better forms of authentication, especially for large online platforms like Facebook and Twitter where messages can have an impact.

This could involve a physical key that plugs into a device or a software-based system such as Google Authenticator, Hall noted.

Eisen said that paradoxically, the push for longer and more complex passwords has led to greater use of insecure text messages for authentication.

“The security practitioners must come to terms with the fact that what used to work doesn’t work now,” he said.

“We need to look for solutions that are not so easily exploited by bad guys and are easy for people to adopt.”

(This story has been published from a wire agency feed without modifications to the text. Only the headline has been changed.)

SHARE THIS ARTICLE ON
Close Story
QUICKREADS

Less time to read?

Try Quickreads

  • A view of the exposed riverbed of Yangtze river on a hot day in Chongqing, China, on Wednesday. (REUTERS)

    Climate crisis: China hit by worst heat wave in decades

    A scorching heat wave, the worst in six decades, sweeping China has dried up rivers and reservoirs, threatened crop yields and forced industries to shut down and ration electricity. One of the regions hit badly by the heat wave is China's southwestern Sichuan province, which has shut down factories for six days to ease a crippling power shortage.

  • With Sunak showing little sign of making inroads, Truss is the hot favorite to become the party’s and the country’s next leader.

    Rishi Sunak losing UK prime minister race, trails Liz Truss by 32 points

    Liz Truss led Rishi Sunak by 32 points in the latest survey of UK Tory members by the ConservativeHome website, suggesting she remains on track to win the race to succeed Boris Johnson as prime minister. Some 60% of the 961 Tory members polled by the influential website said they favored Truss to become the Conservative Party's new leader, while just 28% backed Sunak, ConservativeHome said on Wednesday.

  • Afghanistan, where Taliban are ruling now, however, is yet to meet the expectations of both China as well as Pakistan on many counts.

    China wants military outposts in Pakistan to safeguard its investments

    Having made significant investments in the conflict-prone Pakistan-Afghanistan region as part of its hugely ambitious Belt and Road Initiative, China is planning to protect its interests in the two countries by stationing its own forces in specially created outposts, according to top diplomatic sources. Pakistan, where according to some estimates the Chinese investments have risen above USD 60 billion, is largely dependent on China not only for financial but also military and diplomatic support.

  • US Representative Liz Cheney at an election night event during the Wyoming primary election.

    Republican leader who voted for Trump's impeachment loses Wyoming primary

    Cheney will now be forced from Congress at the end of her third and final term in January. Far, US President Donald Trump's has helped install loyalists who parrot his conspiracy theories in general election matchups from Pennsylvania to Arizona. With Cheney's loss, Republicans who voted to impeach Trump are going extinct. Democrats across America, major donors among them, took notice. Trump earned nearly 70% of the vote in 2016 and 2020.

  • Former US President Donald Trump.

    Trump says FBI returned his passports: 'Unfortunately, they just grabbed…'

    Former US president Donald Trump on Wednesday said that the department of justice and the FBI returned his passports seized during the raid at his Mar-a-Lago residence in Florida last week. Trump said on Tuesday in a statement in a Truth Social post. On Monday, he alleged that the federal law enforcement agency “stole” three passports, one of which he said was expired.

SHARE
Story Saved
×
Saved Articles
Following
My Reads
Sign out
New Delhi 0C
Wednesday, August 17, 2022
Start 15 Days Free Trial Subscribe Now