Categories: Hacking

AT&T short codes exposes users to phishing scams

Computer programmer Dani Grant revealed that short codes from AT&T are easy to spoof and expose customers to phishing scams.

AT&T customers are exposed phishing attacks due to proprietary AT&T’s text protocols. Computer programmer Dani Grant discovered that is quite easy to spoof text messages from AT&T. In this variant of “Phishing” attacks, crooks attempt to trick victims into revealing their sensitive data by sending text messages, containing short codes, that appear to be from legitimate companies.

Grant explained that AT&T uses different short codes that could be abused by attackers to trick company’s customers into phishing scams. AT&T customers are unable to distinguish between the legitimate short codes and phishing messages.

“It’s sent from a short code I’ve never seen, and prompts me to visit a URL that’s not obviously an AT&T site. It looks like phishing, but I’ll bet a lot of AT&T’s customers click on it anyway.” states Grant in a blog post.

AT&T handles its customer alerts via text messages, for this reason, cyber criminals try to reproduce this functionality for phishing attacks. Grant explained that attackers also use short codes as a social engineering tactic, the programmer highlighted that short codes are typically expensive, so users tend to believe that messages containing them are sent by a trustable entity. Threat actors could send AT&T alerts that appear like the legitimate one and AT&T customers have no way to discriminate them.

“Twilio charges a couple thousand dollars for them—so they could be seen as an indicator that a message is coming from a business, but a well-funded hacker would have no problem acquiring one, and I was able to find a free trial for 30 days of short code.” continues Grant.
As proof of concept, Grant used a free trial for 30 day service for short code generation and bought a domain that appears as legitimate (attmobilityllc.net) for $10.89, then sent a message. Grant demonstrated that was impossible to distinguish bogus messages from legitimate ones.

Another security issue is that some of AT&T legitimate links redirect users to domains not obviously associated with AT&T like att.com and dl.mymobilelocate.com.

Another problem is that AT&T directs customers to URLs like dl.mymobilelocation.com which aren’t obviously associated with AT&T,” Grant wrote. “Every AT&T text looks like this, so customers learn to trust any text that claims to be from AT&T, no matter on what they’re being asked to click.

Another element that generates confusion is the lack of a specific format for the AT&T text messages, as explained by Grant some messages start with all capital letters,  “AT&T FREE MSG”, in other cases in all lowercase: “AT&T Free MSG.”

Grant provided the following possible solution to the security issue:

  • Use URLs that are subdomains or extensions of att.com.
  • Preload short codes as phone contacts for AT&T sold devices. That way, customers will know what numbers actually belong to AT&T and which do not.
  • A third option is for AT&T to communicate through other methods besides text messages. While there is certainly the tradeoff of convenience, emails from @att.com addresses or push notifications through AT&T’s app are alternatives.
Grant ethically reported the issues to AT&T, but the company hasn’t commented them.

Pierluigi Paganini

(Security Affairs – AT&T, phishing, short codes)

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

CISA adds Cisco ASA and FTD and CrushFTP VFS flaws to its Known Exploited Vulnerabilities catalog

CISA adds Cisco ASA and FTD and CrushFTP VFS vulnerabilities to its Known Exploited Vulnerabilities…

41 mins ago

CISA adds Microsoft Windows Print Spooler flaw to its Known Exploited Vulnerabilities catalog

U.S. CISA added the Windows Print Spooler flaw CVE-2022-38028 to its Known Exploited Vulnerabilities catalog.…

7 hours ago

DOJ arrested the founders of crypto mixer Samourai for facilitating $2 Billion in illegal transactions

The U.S. Department of Justice (DoJ) announced the arrest of two co-founders of a cryptocurrency mixer…

8 hours ago

Google fixed critical Chrome vulnerability CVE-2024-4058

Google addressed a critical Chrome vulnerability, tracked as CVE-2024-4058, that resides in the ANGLE graphics…

13 hours ago

Nation-state actors exploited two zero-days in ASA and FTD firewalls to breach government networks

Nation-state actor UAT4356 has been exploiting two zero-days in ASA and FTD firewalls since November…

1 day ago

Hackers hijacked the eScan Antivirus update mechanism in malware campaign

A malware campaign has been exploiting the updating mechanism of the eScan antivirus to distribute…

1 day ago

This website uses cookies.