SMS-Based Authentication Is Imploding, Precisely as Experts Predicted

SMS-Based Authentication Is Imploding, Precisely as Experts Predicted

For a relatively long time it seemed as if the password problem had been solved using SMS text messages.

For a relatively long time it seemed as if the password problem had been solved using SMS text messages. Forgot your password? Don’t worry, we’ll send you a one-time passcode via text message.

Except there was a problem behind this security technique, one that was well known to security professionals. That is, SMS is not always a secure communication channel. Using vulnerabilities in the mobile data network known as Signaling System 7 (SS7), hackers can intercept, forward, and relay text messages in a few simple steps.

It was only a matter of time before this was loophole was breached in a major way and that’s just what happened when hackers exploited it in Germany recently to drain several bank accounts over the past few months, according to the country’s largest subscription daily newspaper Süddeutsche Zeitung.

According to the report, the scheme was composed of two parts. The first phase involved a fake email (phishing) that tricked people into entering their personal account information, including their mobile phone number, into a lookalike bank website.

Then, armed with this information, the cybercriminals instructed the global communications network, via SS7, to forward all calls and SMS messages sent to the victim’s mobile phone to a number operated by the criminals. The fraudsters could then log into the victim’s bank account, set up a money transfer, and approve it.

Because of the global usage of SS7 to route text messages, the episode has already generated widespread condemnation. On Friday, not long after the news broke, Congressman Ted Lieu of California issued the following statement:

“Everyone's accounts protected by text-based two-factor authentication, such as bank accounts, are potentially at risk until the FCC and telecom industry fix the devastating SS7 security flaw. Both the FCC and telecom industry have been aware that hackers can acquire our text messages and phone conversations just knowing our cell phone number. It is unacceptable the FCC and telecom industry have not acted sooner to protect our privacy and financial security. I urge the Republican-controlled Congress to hold immediate hearings on this issue.”

The Writing Was on the Wall

Like the iceberg that hit the Titanic, this is a problem that should have been anticipated long before it happened. The warning signs were already there. Last year the National Institute of Standards and Technology specifically recommended against the use of SMS in multi-factor authentication (MFA).

Despite these warnings, why have so many organizations continued to use SMS to secure their communications and websites? Until now, there was no real alternative. The sending of one-time passcodes through separate communication channels (referred to as “out-of-band” communication) like SMS was considered best practice because it made fraud more difficult.

But, as the German hack demonstrated, not impossible. The SMS system was vulnerable to social engineering and “man-in-the-middle” attacks (as done in the two-prong attack) in addition to malware and other means of compromise. For this reason, organizations need to refrain from sending information through SMS that contains sensitive information and transaction-specific information.

This type of out-of-band security overlooks the possibility to leverage the inherent and superior security found in dedicated mobile apps. These apps, unlike SMS, rely on tokens and end-to-end encryption to create a secure environment to communicate and perform transactions. Further, when these encrypted communication channels are coupled with authentication software, the device itself can acts as a trusted token and make all communication 100% secure. This method eliminates reliance on insecure third-party messaging systems, like SS7, to handle sensitive information, and guarantees only the intended device can receive and read the message.

The silver lining to this high-profile incident is it appears it may be the wake-up call for the industry that alerts the larger public to the danger. And, hopefully, this awareness will prompt a widespread migration towards closed loop communication channels through dedicated mobile apps. Financial organizations can no longer afford to take a “wait and see” stance in moving away from SMS and instead should take advantage of new ways to push notifications, step up challenges, or at the very least ensuring defense in depth with other layers of defense when SMS is the only available option. It’s clear what the financial and reputational implications are.


Featured

  • TSA Introduces New $45 Fee Option for Travelers Without REAL ID Starting February 1

    The Transportation Security Administration (TSA) announced today that it will refer all passengers who do not present an acceptable form of ID and still want to fly an option to pay a $45 fee to use a modernized alternative identity verification system, TSA Confirm.ID, to establish identity at security checkpoints beginning on February 1, 2026. Read Now

  • The Evolution of IP Camera Intelligence

    As the 30th anniversary of the IP camera approaches in 2026, it is worth reflecting on how far we have come. The first network camera, launched in 1996, delivered one frame every 17 seconds—not impressive by today’s standards, but groundbreaking at the time. It did something that no analog system could: transmit video over a standard IP network. Read Now

  • From Surveillance to Intelligence

    Years ago, it would have been significantly more expensive to run an analytic like that — requiring a custom-built solution with burdensome infrastructure demands — but modern edge devices have made it accessible to everyone. It also saves time, which is a critical factor if a missing child is involved. Video compression technology has played a critical role as well. Over the years, significant advancements have been made in video coding standards — including H.263, MPEG formats, and H.264—alongside compression optimization technologies developed by IP video manufacturers to improve efficiency without sacrificing quality. The open-source AV1 codec developed by the Alliance for Open Media—a consortium including Google, Netflix, Microsoft, Amazon and others — is already the preferred decoder for cloud-based applications, and is quickly becoming the standard for video compression of all types. Read Now

  • Cost: Reactive vs. Proactive Security

    Security breaches often happen despite the availability of tools to prevent them. To combat this problem, the industry is shifting from reactive correction to proactive protection. This article will examine why so many security leaders have realized they must “lead before the breach” – not after. Read Now

  • Achieving Clear Audio

    In today’s ever-changing world of security and risk management, effective communication via an intercom and door entry communication system is a critical communication tool to keep a facility’s staff, visitors and vendors safe. Read Now

New Products

  • EasyGate SPT and SPD

    EasyGate SPT SPD

    Security solutions do not have to be ordinary, let alone unattractive. Having renewed their best-selling speed gates, Cominfo has once again demonstrated their Art of Security philosophy in practice — and confirmed their position as an industry-leading manufacturers of premium speed gates and turnstiles.

  • 4K Video Decoder

    3xLOGIC’s VH-DECODER-4K is perfect for use in organizations of all sizes in diverse vertical sectors such as retail, leisure and hospitality, education and commercial premises.

  • Luma x20

    Luma x20

    Snap One has announced its popular Luma x20 family of surveillance products now offers even greater security and privacy for home and business owners across the globe by giving them full control over integrators’ system access to view live and recorded video. According to Snap One Product Manager Derek Webb, the new “customer handoff” feature provides enhanced user control after initial installation, allowing the owners to have total privacy while also making it easy to reinstate integrator access when maintenance or assistance is required. This new feature is now available to all Luma x20 users globally. “The Luma x20 family of surveillance solutions provides excellent image and audio capture, and with the new customer handoff feature, it now offers absolute privacy for camera feeds and recordings,” Webb said. “With notifications and integrator access controlled through the powerful OvrC remote system management platform, it’s easy for integrators to give their clients full control of their footage and then to get temporary access from the client for any troubleshooting needs.”