How Do Mobile Phone Cyber Attacks Occur?

mobile phone cyber crimes article

Team CSP recently hosted their event ‘Life’s a Breach’ back in September, as part of Leeds Digital Festival 2021. The event involved an interactive game that attendees had to solve and guess who committed the cyber-crime internally to steal £20,000 from ‘Small Company Ltd’. So, from our event, we now know ‘who dun it’, but how did the suspect really commit the crime?

This article will go over how a criminal might attack your company through mobile phone cyber attacks and the solutions we recommend to put in place.

The scenario was:
  • Small Company Ltd sells widgets
  • Utilises SaaS based solutions extensively
  • Almost all staff works all hours
  • Key workers have access to SaaS solutions via multiple devices
  • External consultant brought in to ‘tidy up’ access controls
  • It appears that £20,000 has disappeared
  • Accounts all reconciled
  • Only MD and Bookkeeper have access to accounts

The criminal that internally committed the cyber-crime was in fact the office manager and was using a sim swap technique. This is how they did it…

Firstly, the office manager rang the support line for the mobile phone company, pretending to be the bookkeeper saying they needed to swap services. As they had access to some personal information, they were able to pass any checks the mobile company had and were given the Porting Authorization Code (PAC) number.

Once they had transferred the number to their own phone, they used the reset password function to get a new password text to themselves for the manufactures account. This then gave the office manager access to the cloud backup of all the apps the bookkeeper had access too. Like most people the bookkeeper had saved all her credentials locally on the phone, even if they hadn’t, it would be possible to get a password reset sent to the phone. Thereby, access to the accounts package to raise a false invoice and then access the banking app to make the payment.

So, if you want to avoid this sort of cyber-attack occurring to your business, then read on for more expert advice.

The main focus of the event was to demonstrate how much we depend on mobile devices and how they are now part of our information infrastructure. While mobile companies are more aware of sim swap fraud then they used to, they rely on mostly public domain information when they ask security questions; date of birth, home address etc. Sim fraud is a form of identity theft, so one of the easiest things to do is to share a non-public piece of information, a password or phrase, with your mobile provider as a validation check.

So, what now?

Below are a few points from the NCSC page (National Cyber Security Centre) on mobile device security and some extra advice from us at CSP.

NCSC advice:

  • Use complex pin or password
  • Make sure lost or stolen devices can be tracked, locked or wiped
  • Keep device up to date
  • Keep apps up to date

Also, specific phone advice is available on the NCSC website, at:

https://www.ncsc.gov.uk/collection/device-security-guidance/platform-guides

CSP advice

  • Is your 2fa application pin protected?
  • Enable device restrictions on SaaS service
  • Define financial limits which need 2 people to sign off on
  • Use a mobile device monitoring system to warn you when devices are changed
  • Consider setting a password or phrase with your mobile service provider so they know for certain it’s you

 

Contact Team CSP here for any other enquiries and help with your cyber security.

One thought on “How Do Mobile Phone Cyber Attacks Occur?

Leave a Reply

Your email address will not be published. Required fields are marked *