Monday, December 16, 2024

A huge hack of U.S. phone companies means your text messages may not be safe

Must read

After a recent attack on U.S. telecom companies that’s being blamed on a Chinese hacking group, cybersecurity experts say people should take action to protect their text messages. (Aaron Amat/Shutterstock – image credit)

At least eight U.S. telecom firms and dozens of countries have been impacted this week by what a top White House official called a Chinese hacking campaign that has also raised concerns about the security of text messaging.

At a media briefing Wednesday, U.S. deputy national security adviser Anne Neuberger shared details about the breadth of a sprawling hacking campaign that gave officials in Beijing access to private texts and phone conversations of an unknown number of Americans.

A group of hackers known as Salt Typhoon is being blamed for the attack targeting companies, which reportedly included AT&T, Verizon and Lumen Technologies. White House officials cautioned that the number of telecommunication firms and countries impacted could still grow.

Canadian cybersecurity experts paying close attention to this latest breach say some industry practices and government regulations that allow intelligence organizations access to the telecommunications system are part of the problem. These experts and U.S. law enforcement officials are recommending that people take action to protect their text messages.

“The attack that is unfolding in the United States is a reflection of historical and continuing vulnerabilities in telecommunication networks around the world, and some of those vulnerabilities are made worse by government,” said Kate Robertson, a lawyer and senior researcher at the University of Toronto’s Citizen Lab, which studies digital threats to civil society.

Though the hack apparently focused on American politicians and government officials, experts say regular SMS text messages, the kind most wireless carriers offer, aren’t very secure because they’re unencrypted.

“We are constantly bombarded with concerns about phishing and email scams and malicious links,” said security consultant Andrew Kirsch, a former intelligence officer with the Canadian Security Intelligence Service (CSIS).

“This shines a light on the fact that the other vulnerability is through our telecommunications, phone calls and text messages.”

Security consultant Andrew Kirsch, a former intelligence officer with the CSIS says the U.S. telcecom hack shows that people vulnerable not just to email phishing scams by hackers but also calls and text messages being intercepted.
Security consultant Andrew Kirsch, a former intelligence officer with the CSIS says the U.S. telcecom hack shows that people vulnerable not just to email phishing scams by hackers but also calls and text messages being intercepted.

Security consultant Andrew Kirsch, a former intelligence officer with CSIS, says the U.S. telecom hack shows that text messages are vulnerable to hackers. (Submitted by Andrew Kirsch)

Agency ‘not aware’ of Canadian networks impacted 

Communications Security Establishment Canada (CSE), which provides the federal government with information technology security and foreign signals intelligence, said in a statement on Saturday that at this time, it “is not aware of any Canadian networks impacted by this activity.”

Latest article