Hackers exploited SS7, a protocol used by cellphone providers, to intercept two-factor codes sent to online banking customers, letting them empty bank accounts
Iain Thomson / The Register :
Context & Ripple Effects
The SS7 hole was documented years ago: researchers disclosed critical vulnerabilities in the telephony protocol in late 2014, and Karsten Nohl demonstrated live call and text interception on 60 Minutes in 2016 using nothing but a phone number. What changed with this report is the target and the payoff — the technique moved from demos to draining real online banking accounts via intercepted SMS two-factor codes.
That matters because the banking industry had been treating SMS codes as adequate authentication even as coverage flagged how fragile the practice is; a later piece on why two-factor authentication is a mess catalogued exactly these SMS and email recovery weaknesses. The story also sits beside the $81M Bangladesh central bank SWIFT heist, where cheap second-hand switches and no firewall opened the payment network — different entry point, same lesson about aging financial infrastructure.
First-order effects
- Online banking customers relying on SMS-delivered two-factor codes are directly exposed: an attacker who knows a phone number can intercept the code and empty the account without ever touching the customer's device.
- Carriers running SS7 now face concrete liability exposure rather than abstract criticism, since the attack they could previously dismiss as theoretical has produced actual bank losses.
Second-order effects
- Banks are pushed to abandon SMS as a second factor in favor of app-based or hardware-token verification, forcing vendors of those alternatives into a demand surge while carriers absorb blame for a protocol flaw predating any single operator.
- The same phone-number-centric weakness shows up in adjacent markets — hackers later hijacked cell numbers to drain cryptocurrency wallets — meaning exchanges and wallet services face the identical forced migration away from SMS verification.
Third-order effects
- If the pattern holds, SMS-based authentication gets structurally deprecated across finance, with regulators and banks treating the carrier network itself as an untrusted channel rather than a secure delivery path.
- Telecom operators face mounting pressure to harden or replace legacy global signaling protocols like SS7, shifting inter-carrier security from an industry backwater to a board-level and regulatory issue.
The trend: SMS-based two-factor authentication is being exposed as a systemic weak point across banking and crypto, accelerating the shift toward app- and hardware-based verification and forcing carriers to answer for legacy protocol flaws.