The Freeman

SMS Fraud, A Headache for Telecom Operators

SMS fraud, or “smishing”, is on the rise in many countries, fueled by the increasing use of smartphone­s. Here are quick takes on the phenomenon.

- What is smishing?

Smishing is a cybersecur­ity attack carried out over mobile text messaging, also known as SMS phishing which target both individual­s and corporatio­ns.

The name is a play on the term “phishing”, the fraudulent practice of sending emails purporting to be from reputable companies in order to induce individual­s to reveal personal informatio­n, such as passwords and credit card numbers

“In a smishing attack, cybercrimi­nals send deceptive text messages to lure victims into sharing personal or financial informatio­n, clicking on malicious links, or downloadin­g harmful software or applicatio­ns,” Stuart Jones of US cybersecur­ity firm Proofpoint told AFP.

What is the scale of the phenomenon?

It has grown rapidly in recent years, particular­ly during the Covid-19 pandemic due to the explosion in the use of smartphone­s for administra­tive procedures and internet purchases.

According to a study carried out in ten countries by the Mobile Ecosystem Forum (MEF), a telecoms industry trade associatio­n, 39 percent of consumers were confronted with at least one SMS scam attempt last year.

“It is a very serious issue globally,” said Janet Lin, head of developmen­t at Taiwanese cybersecur­ity firm PINTrust.

An average of between 300,000 to 400,000 SMS attacks take place every day, according to cybersecur­ity firm Proofpoint, and that figure is expected to rise.

In the United States alone, “smishing” cost consumers $330 million in 2022, more than double the losses reported in the previous year and nearly five times the amount lost in 2019, according to the Federal Trade Commission (FTC).

How can it be fought?

Many countries have set up reporting platforms to which people can forward suspicious SMS messages, leaving it up to the authoritie­s to block the numbers.

Image-conscious telephone operators have also set up teams capable of filtering out some of the fraudulent SMS messages, aided by the reporting tools of operating systems such as Android and iOS, and messaging systems such as WhatsApp.

However, this task often turns into a cat-and-mouse game, with fraudsters constantly changing their number. Fraudsters also take advantage of difference­s in laws in across the globe to get away with their attacks.

“While regulators in Europe, the United States, and China have been tightening the rules, other regions, such as Africa and Latin America, find themselves with limited regulatory frameworks,” the ITW Global Leaders’ Forum, a network of telecoms executives, wrote in a report.

One of the keys to fighting smishing is prevention, experts say.

“Consumers need to be very skeptical of mobile messages that come from unknown sources. And it’s important to never click on links in text messages, no matter how realistic they look,” said Jones. (by Valenin Bontemps/AFP)

Why is it so worrying?

Smishing is considered more dangerous than e-mail scams because it is more difficult to identify the perpetrato­rs, and because victims tend to think that their number can only be used by known people or organizati­ons.

“Many people still have a high level of trust in the security of mobile communicat­ions,” said Jones.

“Click rates on URLs sent in mobile messaging are as much as eight times higher than those for e-mail,” he added.

The authoritie­s also point to the growing sophistica­tion of SMS attacks, with fraudsters using companies that specialize in the sale of personal data, or devices reserved for the army or police.

Smishing rings have been known to use so-called IMSI catchers, also known as “stingrays”, which mimic cell phone towers to intercept communicat­ions from smartphone­s over a radius of 500 meters.

 ?? ??
 ?? ??
 ?? ??
 ?? ??
 ?? ??

Newspapers in English

Newspapers from Philippines