SMS Messages Can Be Rerouted to Hackers for Just $16.

Sms Messages Redirected Featured

I’ve been getting obviously fake text messages from “Amazon” for the past week. Whether a hack, spam, scam, whatever, I know they aren’t real, but I have wondered where they came from. This news makes me wonder even more: SMS messages can be redirected to hackers for just $16.

Hackers Buy SMS Access

Do you get errant text messages and have no idea where they come from? Companies that you trust may have sold hackers access to your messages, which could include private data.

A Motherboard reporter, Joseph Cox, performed a test on this theory, and the hacker who obtained access to his SMS only paid $16. So perhaps someone paid a few dollars for your SMS as well.

Sms Messages Redirected Man

There are companies that manage text messages that appear to be behind this, or at the very least, they are enablers in this scenario. These services silently redirect text messages. Sometimes they are redirecting them right into the hands of attackers.

These companies often don’t even send messages to the account owners to let them know their SMS messages are being redirected to someone they don’t know and haven’t given access to. The attackers gain the ability to not only intercept your messages but reply to them as well. What would they possibly say?

Cox was able to get someone to carry out an attack on his phone number, the one that only cost the attacker $16. He was also able to get SMS redirection services to admit they’d seen these types of attacks before.

Sms Messages Redirected Texting

This is an exploit on the part of the SMS redirection services. They apparently believe they are selling the access to other legitimate companies. The company that sold Cox’s number has now fixed the exploit.

AT&T and Verizon were asked by The Verge if it was possible for messages to be redirected to hackers. Both companies suggested they contact the wireless industry trade organization, CTIA. CTIA told Motherboard it had “no indication of any malicious activity involving the potential threat or that any customers were impacted.”

These were already other known methods of text messaging interference. The industry has been aware of SMS swapping and SST attacks for a couple of years. Victims of SMS swapping know, however, of the attacks. It won’t be as obvious when your text messages are redirected.

Further Implications

It could get even worse than just access to your SMS messages – it could extend to your other accounts. Think of all the password reset codes that are sent to you via text. With access to your account, an attacker now has access to those reset accounts as well. Login links are sent through text as well. That’s even more accounts that have now been opened to the hackers.

Sms Messages Redirected Woman

For all these reasons, avoid sending anything security-related through your SMS messages. This includes two-factor authentication. Sometimes you may not have a choice. Just make sure you have an ironclad password.

Was this the source of my fake Amazon texts? It doesn’t appear so, but it’s no less troubling.

Read on to learn how to block your SMS messages from spammers on an iPhone and about some apps to block spam on Android.

Subscribe to our newsletter!

Our latest tutorials delivered straight to your inbox

Laura Tucker Avatar

Read next

When the SS Great Eastern laid the first working transatlantic telegraph cable in 1866, a message that had taken ten days by steamship suddenly crossed the ocean in minutes, and the financial markets of London and New York were forced, within a single trading week, to invent the modern concept of synchronised global price.
The Big Ear telescope was scanning at 1420.4056 megahertz on the night of 15 August 1977, the exact frequency at which hydrogen atoms vibrate across the universe, because Giuseppe Cocconi and Philip Morrison had argued years earlier that any species trying to be found would broadcast on that channel — and then, for 72 seconds, something did.
In 2016, archaeologists dated two rings of snapped stalagmites in France’s Bruniquel Cave to 176,500 years ago, evidence that Neanderthals had walked 336 metres into darkness with fire and built architecture deep underground long before modern humans reached Europe
Otto von Bismarck was 74 when Germany adopted the world’s first national old-age social insurance program in 1889, setting the pension age at 70 after years of fighting socialists with bans, laws, and a promise few workers would live long enough to use
When cosmonaut Valeri Polyakov stepped out of his Soyuz capsule in March 1995 after 437 consecutive days aboard Mir, doctors recorded him at several centimetres above his pre-flight height, and his spine had become so unaccustomed to gravity that the recovery team carried him to a chair rather than risk the compression of letting him walk.
When Bell Labs engineer Karl Jansky pointed a rotating antenna at the sky in 1932 looking for sources of transatlantic radio static, he kept picking up a faint hiss that peaked every 23 hours and 56 minutes, and he eventually realized he had become the first human to hear the center of the Milky Way.
When Harvard astronomer Cecilia Payne submitted her 1925 doctoral thesis arguing that the Sun was made almost entirely of hydrogen, the field’s senior figure Henry Norris Russell talked her into adding a line calling the result ‘almost certainly not real,’ and then published the same conclusion himself four years later to widespread acclaim.
When seismic waves from the Chicxulub impact reached what is now North Dakota roughly ten minutes after the asteroid struck, they appear to have triggered a ten-metre standing wave in an inland river that flung fish onto the bank and buried them under glass beads still falling from the sky.