{"id":583,"date":"2019-02-04T15:55:34","date_gmt":"2019-02-04T12:55:34","guid":{"rendered":"https:\/\/airome.tech\/?p=583"},"modified":"2023-06-22T10:06:50","modified_gmt":"2023-06-22T07:06:50","slug":"metro-bank-is-the-first-bank-that-disclosed-ss7-attacks-against-its-customers","status":"publish","type":"post","link":"https:\/\/airome.tech\/id\/metro-bank-is-the-first-bank-that-disclosed-ss7-attacks-against-its-customers\/","title":{"rendered":"Metro Bank is the first bank that disclosed SS7 attacks against its customers"},"content":{"rendered":"<p>A new type of cyber attack was used for the first time against the Metro Bank, threat actors are leveraging known flaws in the SS7 signaling protocol to intercept the codes sent via text messages to customers to authorize transactions.<\/p>\n<p>The Signaling System 7, aka SS7, which is a set of protocols developed in 1975 that allows the connections of one mobile phone network to another. The information passed from a network to another is needed for routing calls and text messages between several networks.<\/p>\n<p>The SS7 performs out-of-band signaling in support of the call establishment, billing, routing, and information exchange functions of the public switched telephone network (PSTN).<\/p>\n<p>Attackers exploited the flaw in the SS7 protocol to defeat the 2FA authentication used by Metro Bank to protect its customers.<\/p>\n<p>\u201cThis activity was typically only within reach of intelligence agencies or surveillance contractors, but now Motherboard has confirmed that this capability is much more widely available in the hands of financially-driven cybercriminal groups, who are using it to empty bank accounts.\u201d reported Motherboard that first reported the attacks.<\/p>\n<p>\u201cSo-called SS7 attacks against banks are, although still relatively rare, much more prevalent than previously reported. Motherboard has identified a specific bank\u2014the UK\u2019s Metro Bank\u2014that fell victim to such an attack.\u201c<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"640\" height=\"360\" class=\"aligncenter wp-image-587\" src=\"https:\/\/airome.tech\/wp-content\/uploads\/2019\/02\/17-1-mini.jpg\" alt=\"\" \/><\/p>\n<p>This is not an isolated case, other banks have also been affected by this specific attack. A Metro Bank spokesman confirmed that only a \u201csmall number\u201d of the bank\u2019s customers had been affected.<\/p>\n<p>\u201cAt Metro Bank we take our customers\u2019 security extremely seriously and have a comprehensive range of safeguards in place to help protect them against fraud. We have supported telecommunication companies and law enforcement authorities with an industry-wide investigation and understand that steps have been taken to resolve the issue.\u201d said the Bank spokesman.<\/p>\n<p>\u201cOf those customers impacted by this type of fraud, an extremely small number have been Metro Bank customers and none have been left out of pocket as a result. Customers should continue to remain vigilant and report any suspicious activity using the number on the back of their card or on our website.\u201d<\/p>\n<p>Metro Bank immediately informed the authorities of the attacks, but many other financial institutions that were affected by SS7 attacks have not disclosed it.<\/p>\n<p>\u201cWe are aware of a known telecommunications vulnerability being exploited to target bank accounts by intercepting SMS text messages used as 2-Factor Authentication (2FA).\u201d said National Cyber Security Centre spokesman.<\/p>\n<p>\u201cWhile text messages are not the most secure type of two-factor authentication, they still offer a huge advantage over not using any 2FA at all.\u201d<\/p>\n<p>Karsten Nohl, a researcher from Security Research Labs, conducted numerous studies on the flaws affecting the SS7 protocol and confirmed that many banks suffered similar attacks.<\/p>\n<p>\u201cSome of our clients in the banking industry or other financial services; they see more and more SS7-based [requests],\u201d Karsten Nohl, a researcher from Security Research Labs who has worked on SS7 for years, told Motherboard in a phone call. \u201cAll of a sudden you have someone\u2019s text messages.\u201d<\/p>\n<h3>UK case<\/h3>\n<p>Major British UK company BT confirmed that it is aware of SS7 attacks to commit banking fraud.<\/p>\n<p>\u201cCustomer security is our top priority so we\u2019re always upgrading our systems and working with the industry and banks to help protect our customers.\u201d a BT spokesperson.<\/p>\n<p>Who is behind the SS7 attacks on Metro Bank?<\/p>\n<p>Experts believe there is a well-resourced and coordinate cyber criminal group of highly skilled professionals.<\/p>\n<p>\u201c[Graeme Coffey, head of sales at cybersecurity firm AdaptiveMobile] said criminals could have acquired access from legitimate providers, or are piggybacking off that access, making the SS7 requests appear somewhat more legitimate.\u201d concludes Motherboard. \u201cNohl pointed to how hackers could target someone who already has SS7 access. In 2017, this reporter went undercover as an SMS routing service and was successfully offered SS7 access for around $10,000.\u201d<\/p>\n<p>&nbsp;<\/p>\n<p>by Security Affairs<\/p>\n<p>Reference: <a href=\"https:\/\/securityaffairs.co\/wordpress\/80649\/cyber-crime\/metro-bank-ss7-attacks.html\">https:\/\/securityaffairs.co\/wordpress\/80649\/cyber-crime\/metro-bank-ss7-attacks.html<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Metro Bank has become the first major bank to disclose SS7 attacks against its customers.<\/p>\n","protected":false},"author":5,"featured_media":587,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[112],"class_list":["post-583","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-criminal_cases","tag-ss7-attacks"],"translation":{"provider":"WPGlobus","version":"3.0.0","language":"id","enabled_languages":["en","id"],"languages":{"en":{"title":true,"content":true,"excerpt":true},"id":{"title":false,"content":false,"excerpt":false}}},"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v25.6 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Metro Bank is the first bank that disclosed SS7 attacks against its customers - Airome<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/airome.tech\/metro-bank-is-the-first-bank-that-disclosed-ss7-attacks-against-its-customers\/\" \/>\n<meta property=\"og:locale\" content=\"id_ID\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Metro Bank is the first bank that disclosed SS7 attacks against its customers - Airome\" \/>\n<meta property=\"og:url\" content=\"https:\/\/airome.tech\/metro-bank-is-the-first-bank-that-disclosed-ss7-attacks-against-its-customers\/\" \/>\n<meta property=\"og:site_name\" content=\"Airome\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/airometech\" \/>\n<meta property=\"article:published_time\" content=\"2019-02-04T12:55:34+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-06-22T07:06:50+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/airome.tech\/wp-content\/uploads\/2019\/02\/17-1-mini.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"640\" \/>\n\t<meta property=\"og:image:height\" content=\"360\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Airome Technologies\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@airome_tech\" \/>\n<meta name=\"twitter:site\" content=\"@airome_tech\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Airome Technologies\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/airome.tech\/metro-bank-is-the-first-bank-that-disclosed-ss7-attacks-against-its-customers\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/airome.tech\/metro-bank-is-the-first-bank-that-disclosed-ss7-attacks-against-its-customers\/\"},\"author\":{\"name\":\"Airome Technologies\",\"@id\":\"https:\/\/airome.tech\/#\/schema\/person\/4305f9424f28ed17c089815d871cf0fa\"},\"headline\":\"Metro Bank is the first bank that disclosed SS7 attacks against its customers\",\"datePublished\":\"2019-02-04T12:55:34+00:00\",\"dateModified\":\"2023-06-22T07:06:50+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/airome.tech\/metro-bank-is-the-first-bank-that-disclosed-ss7-attacks-against-its-customers\/\"},\"wordCount\":668,\"publisher\":{\"@id\":\"https:\/\/airome.tech\/#organization\"},\"image\":{\"@id\":\"https:\/\/airome.tech\/metro-bank-is-the-first-bank-that-disclosed-ss7-attacks-against-its-customers\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/airome.tech\/wp-content\/uploads\/2019\/02\/17-1-mini.jpg\",\"keywords\":[\"SS7 attacks\"],\"articleSection\":[\"Industrial &amp; Criminal cases\"],\"inLanguage\":\"id-ID\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/airome.tech\/metro-bank-is-the-first-bank-that-disclosed-ss7-attacks-against-its-customers\/\",\"url\":\"https:\/\/airome.tech\/metro-bank-is-the-first-bank-that-disclosed-ss7-attacks-against-its-customers\/\",\"name\":\"Metro Bank is the first bank that disclosed SS7 attacks against its customers - Airome\",\"isPartOf\":{\"@id\":\"https:\/\/airome.tech\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/airome.tech\/metro-bank-is-the-first-bank-that-disclosed-ss7-attacks-against-its-customers\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/airome.tech\/metro-bank-is-the-first-bank-that-disclosed-ss7-attacks-against-its-customers\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/airome.tech\/wp-content\/uploads\/2019\/02\/17-1-mini.jpg\",\"datePublished\":\"2019-02-04T12:55:34+00:00\",\"dateModified\":\"2023-06-22T07:06:50+00:00\",\"description\":\"UK company BT confirmed that it is aware of SS7 attacks to commit banking fraud\",\"breadcrumb\":{\"@id\":\"https:\/\/airome.tech\/metro-bank-is-the-first-bank-that-disclosed-ss7-attacks-against-its-customers\/#breadcrumb\"},\"inLanguage\":\"id-ID\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/airome.tech\/metro-bank-is-the-first-bank-that-disclosed-ss7-attacks-against-its-customers\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"id-ID\",\"@id\":\"https:\/\/airome.tech\/metro-bank-is-the-first-bank-that-disclosed-ss7-attacks-against-its-customers\/#primaryimage\",\"url\":\"https:\/\/airome.tech\/wp-content\/uploads\/2019\/02\/17-1-mini.jpg\",\"contentUrl\":\"https:\/\/airome.tech\/wp-content\/uploads\/2019\/02\/17-1-mini.jpg\",\"width\":640,\"height\":360},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/airome.tech\/metro-bank-is-the-first-bank-that-disclosed-ss7-attacks-against-its-customers\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u0413\u043b\u0430\u0432\u043d\u0430\u044f \u0441\u0442\u0440\u0430\u043d\u0438\u0446\u0430\",\"item\":\"https:\/\/airome.tech\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Metro Bank is the first bank that disclosed SS7 attacks against its customers\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/airome.tech\/#website\",\"url\":\"https:\/\/airome.tech\/\",\"name\":\"Airome\",\"description\":\"Simple. Mobile. Secure. Your mTAS.\",\"publisher\":{\"@id\":\"https:\/\/airome.tech\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/airome.tech\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"id-ID\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/airome.tech\/#organization\",\"name\":\"Airome\",\"url\":\"https:\/\/airome.tech\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"id-ID\",\"@id\":\"https:\/\/airome.tech\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/airome.tech\/wp-content\/uploads\/2020\/02\/logo-206.png\",\"contentUrl\":\"https:\/\/airome.tech\/wp-content\/uploads\/2020\/02\/logo-206.png\",\"width\":206,\"height\":64,\"caption\":\"Airome\"},\"image\":{\"@id\":\"https:\/\/airome.tech\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/airometech\",\"https:\/\/x.com\/airome_tech\",\"https:\/\/www.linkedin.com\/company\/airome\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/airome.tech\/#\/schema\/person\/4305f9424f28ed17c089815d871cf0fa\",\"name\":\"Airome Technologies\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"id-ID\",\"@id\":\"https:\/\/airome.tech\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/cf1864c9ce26e9439ecfb0b95c8af0d14ba56239900be8267722a9e1193e0c98?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/cf1864c9ce26e9439ecfb0b95c8af0d14ba56239900be8267722a9e1193e0c98?s=96&d=mm&r=g\",\"caption\":\"Airome Technologies\"},\"url\":\"https:\/\/airome.tech\/id\/author\/s-dvukhzhennov\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Metro Bank is the first bank that disclosed SS7 attacks against its customers - Airome","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/airome.tech\/metro-bank-is-the-first-bank-that-disclosed-ss7-attacks-against-its-customers\/","og_locale":"id_ID","og_type":"article","og_title":"Metro Bank is the first bank that disclosed SS7 attacks against its customers - Airome","og_url":"https:\/\/airome.tech\/metro-bank-is-the-first-bank-that-disclosed-ss7-attacks-against-its-customers\/","og_site_name":"Airome","article_publisher":"https:\/\/www.facebook.com\/airometech","article_published_time":"2019-02-04T12:55:34+00:00","article_modified_time":"2023-06-22T07:06:50+00:00","og_image":[{"width":640,"height":360,"url":"https:\/\/airome.tech\/wp-content\/uploads\/2019\/02\/17-1-mini.jpg","type":"image\/jpeg"}],"author":"Airome Technologies","twitter_card":"summary_large_image","twitter_creator":"@airome_tech","twitter_site":"@airome_tech","twitter_misc":{"Written by":"Airome Technologies","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/airome.tech\/metro-bank-is-the-first-bank-that-disclosed-ss7-attacks-against-its-customers\/#article","isPartOf":{"@id":"https:\/\/airome.tech\/metro-bank-is-the-first-bank-that-disclosed-ss7-attacks-against-its-customers\/"},"author":{"name":"Airome Technologies","@id":"https:\/\/airome.tech\/#\/schema\/person\/4305f9424f28ed17c089815d871cf0fa"},"headline":"Metro Bank is the first bank that disclosed SS7 attacks against its customers","datePublished":"2019-02-04T12:55:34+00:00","dateModified":"2023-06-22T07:06:50+00:00","mainEntityOfPage":{"@id":"https:\/\/airome.tech\/metro-bank-is-the-first-bank-that-disclosed-ss7-attacks-against-its-customers\/"},"wordCount":668,"publisher":{"@id":"https:\/\/airome.tech\/#organization"},"image":{"@id":"https:\/\/airome.tech\/metro-bank-is-the-first-bank-that-disclosed-ss7-attacks-against-its-customers\/#primaryimage"},"thumbnailUrl":"https:\/\/airome.tech\/wp-content\/uploads\/2019\/02\/17-1-mini.jpg","keywords":["SS7 attacks"],"articleSection":["Industrial &amp; Criminal cases"],"inLanguage":"id-ID"},{"@type":"WebPage","@id":"https:\/\/airome.tech\/metro-bank-is-the-first-bank-that-disclosed-ss7-attacks-against-its-customers\/","url":"https:\/\/airome.tech\/metro-bank-is-the-first-bank-that-disclosed-ss7-attacks-against-its-customers\/","name":"Metro Bank is the first bank that disclosed SS7 attacks against its customers - Airome","isPartOf":{"@id":"https:\/\/airome.tech\/#website"},"primaryImageOfPage":{"@id":"https:\/\/airome.tech\/metro-bank-is-the-first-bank-that-disclosed-ss7-attacks-against-its-customers\/#primaryimage"},"image":{"@id":"https:\/\/airome.tech\/metro-bank-is-the-first-bank-that-disclosed-ss7-attacks-against-its-customers\/#primaryimage"},"thumbnailUrl":"https:\/\/airome.tech\/wp-content\/uploads\/2019\/02\/17-1-mini.jpg","datePublished":"2019-02-04T12:55:34+00:00","dateModified":"2023-06-22T07:06:50+00:00","description":"UK company BT confirmed that it is aware of SS7 attacks to commit banking fraud","breadcrumb":{"@id":"https:\/\/airome.tech\/metro-bank-is-the-first-bank-that-disclosed-ss7-attacks-against-its-customers\/#breadcrumb"},"inLanguage":"id-ID","potentialAction":[{"@type":"ReadAction","target":["https:\/\/airome.tech\/metro-bank-is-the-first-bank-that-disclosed-ss7-attacks-against-its-customers\/"]}]},{"@type":"ImageObject","inLanguage":"id-ID","@id":"https:\/\/airome.tech\/metro-bank-is-the-first-bank-that-disclosed-ss7-attacks-against-its-customers\/#primaryimage","url":"https:\/\/airome.tech\/wp-content\/uploads\/2019\/02\/17-1-mini.jpg","contentUrl":"https:\/\/airome.tech\/wp-content\/uploads\/2019\/02\/17-1-mini.jpg","width":640,"height":360},{"@type":"BreadcrumbList","@id":"https:\/\/airome.tech\/metro-bank-is-the-first-bank-that-disclosed-ss7-attacks-against-its-customers\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u0413\u043b\u0430\u0432\u043d\u0430\u044f \u0441\u0442\u0440\u0430\u043d\u0438\u0446\u0430","item":"https:\/\/airome.tech\/"},{"@type":"ListItem","position":2,"name":"Metro Bank is the first bank that disclosed SS7 attacks against its customers"}]},{"@type":"WebSite","@id":"https:\/\/airome.tech\/#website","url":"https:\/\/airome.tech\/","name":"Airome","description":"Simple. Mobile. Secure. Your mTAS.","publisher":{"@id":"https:\/\/airome.tech\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/airome.tech\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"id-ID"},{"@type":"Organization","@id":"https:\/\/airome.tech\/#organization","name":"Airome","url":"https:\/\/airome.tech\/","logo":{"@type":"ImageObject","inLanguage":"id-ID","@id":"https:\/\/airome.tech\/#\/schema\/logo\/image\/","url":"https:\/\/airome.tech\/wp-content\/uploads\/2020\/02\/logo-206.png","contentUrl":"https:\/\/airome.tech\/wp-content\/uploads\/2020\/02\/logo-206.png","width":206,"height":64,"caption":"Airome"},"image":{"@id":"https:\/\/airome.tech\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/airometech","https:\/\/x.com\/airome_tech","https:\/\/www.linkedin.com\/company\/airome\/"]},{"@type":"Person","@id":"https:\/\/airome.tech\/#\/schema\/person\/4305f9424f28ed17c089815d871cf0fa","name":"Airome Technologies","image":{"@type":"ImageObject","inLanguage":"id-ID","@id":"https:\/\/airome.tech\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/cf1864c9ce26e9439ecfb0b95c8af0d14ba56239900be8267722a9e1193e0c98?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/cf1864c9ce26e9439ecfb0b95c8af0d14ba56239900be8267722a9e1193e0c98?s=96&d=mm&r=g","caption":"Airome Technologies"},"url":"https:\/\/airome.tech\/id\/author\/s-dvukhzhennov\/"}]}},"_links":{"self":[{"href":"https:\/\/airome.tech\/id\/wp-json\/wp\/v2\/posts\/583","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/airome.tech\/id\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/airome.tech\/id\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/airome.tech\/id\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/airome.tech\/id\/wp-json\/wp\/v2\/comments?post=583"}],"version-history":[{"count":4,"href":"https:\/\/airome.tech\/id\/wp-json\/wp\/v2\/posts\/583\/revisions"}],"predecessor-version":[{"id":1718,"href":"https:\/\/airome.tech\/id\/wp-json\/wp\/v2\/posts\/583\/revisions\/1718"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/airome.tech\/id\/wp-json\/wp\/v2\/media\/587"}],"wp:attachment":[{"href":"https:\/\/airome.tech\/id\/wp-json\/wp\/v2\/media?parent=583"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/airome.tech\/id\/wp-json\/wp\/v2\/categories?post=583"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/airome.tech\/id\/wp-json\/wp\/v2\/tags?post=583"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}