UK's Metro Bank confirms it has faced an SS7 attack intercepting 2FA codes; a telecom lobbying group previously told Congress such an attack is “theoretical”
Metro Bank—that was targeted http://motherboard.vice.com/ ... http://twitter.com/... Jason Koebler / @jason_koebler : You may remember SS7 from such previous Motherboard stories as the “telecom industry tells Congress that SS7 attacks are only ‘theoretical’ and doesn't need fixing” https://motherboard.vice.com/ ... Joseph Cox / @josephfcox : New: hackers are exploiting the phone data backbone, SS7, to intercept 2FA tokens, empty bank accounts. We identified a specific UK bank; defensive arm of GCHQ confirms our reporting. But sources say this is a much wider issue. “Global” one said https://motherboard.vice.com/ ...
Context & Ripple Effects
The SS7 story has been building for years: researchers first demonstrated that the global signaling protocol could be used to decrypt calls and texts in 2014, and by 2017 hackers were using it to intercept two-factor codes sent to online banking customers and drain accounts. When DHS flagged the flaws, a lobbying group for Verizon and AT&T told Congress the attacks were merely 'theoretical' and needed no fix — a claim experts disputed at the time.
That position is now untenable. Motherboard has identified a specific victim — UK's Metro Bank — and GCHQ's defensive arm has confirmed the reporting that an SS7 attack intercepted the bank's 2FA codes. Sources describe the exploitation as much wider than one bank, potentially global.
First-order effects
- Metro Bank customers whose SMS-delivered 2FA codes were intercepted face direct account-takeover losses, and the bank now carries a publicly confirmed SS7 breach on its record.
- The telecom lobbying group's 'theoretical' testimony to Congress is directly contradicted by a named bank victim and GCHQ's own confirmation, handing regulators evidence the carriers' trade group previously denied existed.
Second-order effects
- Banks relying on SMS two-factor authentication are pushed toward app-based tokens or hardware keys, since the SS7 interception technique defeats any code sent over the phone network regardless of the bank's own defenses.
- Carriers face renewed congressional scrutiny over SS7 remediation costs, with the earlier documented SS7 vulnerabilities now tied to concrete financial harm rather than lab demonstrations.
Third-order effects
- If sources are right that SS7 exploitation is global, SMS-based authentication becomes structurally unreliable as a security control, accelerating its retirement across banking and other high-value services — a shift later reinforced by cheap SMS-rerouting services like the Sakari $16 text-redirection attack.
- Signaling-layer weaknesses keep surfacing beyond SS7 itself — the SimJacker SIM-card vulnerability showed a private actor exploiting the same phone-network trust model for surveillance — pointing toward regulatory mandates for telecom network security rather than voluntary carrier fixes.
The trend: Telecom signaling flaws are migrating from academic demonstrations to confirmed financial attacks, forcing banks to abandon SMS-based authentication and regulators to treat carrier network security as a mandate rather than a lobbying question.