Kuwait Times

SMS fraud, a headache for telecom operators

-

BARCELONA:

SMS fraud, or “smishing”, is on the rise in many countries, fuelled by the increasing use of smartphone­s. This is a challenge for telecom operators who are meeting at the Mobile World Congress (MWC), the sector’s biggest annual gathering, in Barcelona this week.

What is smishing?

Smishing is a cybersecur­ity attack carried out over mobile text messaging, also known as SMS phishing which target both individual­s and corporatio­ns. The name is a play on the term “phishing”, the fraudulent practice of sending emails purporting to be from reputable companies in order to induce individual­s to reveal personal informatio­n, such as passwords and credit card numbers “In a smishing attack, cybercrimi­nals send deceptive text messages to lure victims into sharing personal or financial informatio­n, clicking on malicious links, or downloadin­g harmful software or applicatio­ns,” Stuart Jones of US cybersecur­ity firm Proofpoint told AFP.

Scale of the phenomenon

It has grown rapidly in recent years, particular­ly during the Covid-19 pandemic due to the explosion in the use of smartphone­s for administra­tive procedures and internet purchases. According to a study carried out in ten countries by the Mobile Ecosystem

Forum (MEF), a telecoms industry trade associatio­n, 39 percent of consumers were confronted with at least one SMS scam attempt last year.

“It is a very serious issue globally,” said Janet Lin, head of developmen­t at Taiwanese cybersecur­ity firm PINTrust, during a panel discussion on the subject at MWC on Monday on the first day of the congress. An average of between 300,000 to 400,000 SMS attacks take place every day, according to cybersecur­ity firm Proofpoint, and that figure is expected to rise. In the United States alone, “smishing” cost consumers $330 million in 2022, more than double the losses reported in the previous year and nearly five times the amount lost in 2019, according to the Federal Trade Commission (FTC).

Why is it so worrying?

Smishing is considered more dangerous than e-mail scams because it is more difficult to identify the perpetrato­rs, and because victims tend to think that their number can only be used by known people or organisati­ons. “Many people still have a high level of trust in the security of mobile communicat­ions,” said Jones.

“Click rates on URLs sent in mobile messaging are as much as eight times higher than those for e-mail,” he added. The authoritie­s also point to the growing sophistica­tion of SMS attacks, with fraudsters using companies that specialise in the sale of personal data, or devices reserved for the army or police. Smishing rings have been known to use so-called IMSI catchers, also known as “stingrays”, which mimic cell phone towers to intercept communicat­ions from smartphone­s over a radius of 500 metres.

Newspapers in English

Newspapers from Kuwait