LONDON — Security analysts are reporting hackers have discovered a way to compromise "out-of-band" authentication, considered to be one of the strongest formats for online security.
Banks in the United Kingdom have been already been targeted and penetrated, experts are reporting, using a technique that is also known as "phone-jacking."
Phone-jacking earned its name from what is essentially the hijacking of authentication calls or text messages sent by some banks to customers' phones as a means of authenticating a transaction. The hackers use a communication channel that is different from the one the financial institution used to initiate the conversation. The calls are instead routed to the hackers' phone, where approval of a fraudulent transaction is then approved, according to analysts.
In order to succeed, an element of social engineering is required, as the customer service rep at the customer's phone provider must be convinced to forward a victim's phone calls to a number controlled by the attacker. Once accomplished, the criminal can use other stolen data to log into the customer's account.
Several banks in the U.K. have confirmed having been subjected to such attacks. Analysts say several infrastructure and legal differences between in the U.S. and the U.K. make it more difficult to conduct such fraud in the United States.











