Text routing firm Aerialink says that all major US cell carriers have closed an SMS loophole that allowed hackers to easily reroute a target's text messages
All the mobile carries have mitigated a major SMS security loophole that allowed a hacker to hijack text messages for just $16. — Joseph Cox
Context & Ripple Effects
Ten days before this announcement, a reporter showed how little friction SMS hijacking required: a hacker paid messaging firm Sakari just $16 to reroute his texts and then used intercepted two-factor codes to break into his accounts. That demo turned an obscure corner of the carrier messaging stack into a named, priced attack path.
The closure reported by routing firm Aerialink lands against a broader backdrop of fragility in the same layer: [[a:1158964|Syniverse, which routes texts for AT&T, Verizon and others, later disclosed hackers had access to its databases for five years]], and researchers had already flagged telco RCS deployments as exposing users to interception and spoofing. Carriers are patching the cheapest hole in a system whose deeper plumbing keeps producing problems.
First-order effects
- Attackers lose the roughly $16 self-serve route to redirecting a target's texts at every major US carrier, closing off the specific SMS-2FA hijack chain demonstrated through Sakari.
Second-order effects
- Bulk-messaging intermediaries of the Sakari type face tighter vetting and onboarding controls from carriers, raising costs across the legitimate business-SMS market those firms serve.
- Hijack demand migrates to the remaining soft spots in the text ecosystem — intercarrier routers like Syniverse and other messaging-API vendors — since the exploit economics simply move rather than disappear.
Third-order effects
- If each fix arrives only after a journalist buys the exploit, the pattern points toward formal regulation of bulk SMS routing tools rather than ad hoc carrier patches, and toward continued erosion of SMS's standing as a two-factor channel.
The trend: SMS infrastructure security is being hardened exploit-by-exploit in response to public demonstrations, while each closure pushes attackers toward the routing and API layers the fixes don't touch.