/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Hackers exploited SS7, a protocol used by cellphone providers, to intercept two-factor codes sent to online banking customers, letting them empty bank accounts

Iain Thomson / The Register :

The Register Iain Thomson

Context & Ripple Effects

The SS7 hole was documented years ago: researchers disclosed critical vulnerabilities in the telephony protocol in late 2014, and Karsten Nohl demonstrated live call and text interception on 60 Minutes in 2016 using nothing but a phone number. What changed with this report is the target and the payoff — the technique moved from demos to draining real online banking accounts via intercepted SMS two-factor codes.

That matters because the banking industry had been treating SMS codes as adequate authentication even as coverage flagged how fragile the practice is; a later piece on why two-factor authentication is a mess catalogued exactly these SMS and email recovery weaknesses. The story also sits beside the $81M Bangladesh central bank SWIFT heist, where cheap second-hand switches and no firewall opened the payment network — different entry point, same lesson about aging financial infrastructure.

First-order effects

  • Online banking customers relying on SMS-delivered two-factor codes are directly exposed: an attacker who knows a phone number can intercept the code and empty the account without ever touching the customer's device.
  • Carriers running SS7 now face concrete liability exposure rather than abstract criticism, since the attack they could previously dismiss as theoretical has produced actual bank losses.

Second-order effects

  • Banks are pushed to abandon SMS as a second factor in favor of app-based or hardware-token verification, forcing vendors of those alternatives into a demand surge while carriers absorb blame for a protocol flaw predating any single operator.
  • The same phone-number-centric weakness shows up in adjacent markets — hackers later hijacked cell numbers to drain cryptocurrency wallets — meaning exchanges and wallet services face the identical forced migration away from SMS verification.

Third-order effects

  • If the pattern holds, SMS-based authentication gets structurally deprecated across finance, with regulators and banks treating the carrier network itself as an untrusted channel rather than a secure delivery path.
  • Telecom operators face mounting pressure to harden or replace legacy global signaling protocols like SS7, shifting inter-carrier security from an industry backwater to a board-level and regulatory issue.

The trend: SMS-based two-factor authentication is being exposed as a systemic weak point across banking and crypto, accelerating the shift toward app- and hardware-based verification and forcing carriers to answer for legacy protocol flaws.