The Times Australia
The Times World News

.
The Times Real Estate

.

Scammers can slip fake texts into legitimate SMS threads. Will a government crackdown stop them?

  • Written by Suranga Seneviratne, Senior Lecturer - Security, University of Sydney
Scammers can slip fake texts into legitimate SMS threads. Will a government crackdown stop them?

Are you tired of receiving SMS scams pretending to be from Australia Post, the tax office, MyGov and banks? You’re not alone. Each year, thousands of Australians fall victim to SMS scams[1]. And losses have surged[2] in recent years.

In 2022 SMS scam losses exceeded A$28 million, which is nearly triple the amount from 2021. This year they’ve already reached A$4 million – more than the 2020 total. These figures are probably much higher if you include unreported losses, as victims often won’t speak up due to shame and social stigma.

Last month, the federal government announced plans to fight SMS-based scams by implementing an SMS sender ID registry. Under this system, organisations that want to SMS customers will first have to register their sender ID with a government body.

What kinds of scams would the proposed registry help prevent? And is it too little, too late?

Read more: 'We have filed a case under your name': beware of tax scams — they'll be everywhere this EOFY[3]

Sender ID manipulation

One of the more concerning types of SMS scams is when fraudulent messages creep into legitimate message threads, making it difficult to differentiate between a legitimate service and a scam[4].

SMS is an older technology that lacks many modern security features, including end-to-end encryption and origin authentication (which lets you verify whether a message is sent by the claimed sender). The absence of the latter is the reason we see highly believable scams like the one below.

An example of a scam SMS message ending up in a legitimate message thread. Luu Y Nhi Nguyen

There are two main types of SMS:

  • peer-to-peer (P2P) is what most people use to send messages to friends and family

  • application-to-person (A2P) is a way for companies to send messages in bulk through the use of a web portal or application.

The problem with A2P messaging is that applications can be used to enter any text or number (or combination) in the sender ID field – and the recipient’s phone uses this sender ID to group messages into threads.

In the example above, the scammer would have simply needed to write “ANZ” in the sender ID field for their fraudulent message to show up in the real message thread with ANZ. And, of course, they could still impersonate ANZ even if no previous legitimate thread existed, in which case it would show up in a new thread.

Web portals and apps offering A2P services generally don’t do their due diligence and check whether a sender is the actual owner of the sender ID they’re using. There are also no requirements for telecom companies to verify this.

Moreover, telecom providers generally can’t block scam SMS messages due to how difficult it is to distinguish them from genuine messages.

How would sender ID registration help?

Last year the Australian Communications and Media Authority introduced new rules[5] for the telecom industry to combat SMS scams by tracing and blocking them. The Reducing Scam Calls and Scam Short Messages Industry Code required providers to share threat intelligence about scams and report them to authorities.

In January, A2P texting solutions company Modica received a warning[6] for failing to comply with the rules. ACMA found[7] Modica didn’t have proper procedures to verify the legitimacy of text-based SMS sender IDs, which allowed scammers to reach many mobile users in Australia.

Although ACMA’s code is useful, it’s challenging to identify all A2P providers who aren’t following it. More action was needed.

In February, the government instructed[8] ACMA to explore establishing an SMS sender ID registry. This would essentially be a whitelist of all alphanumeric sender IDs that can be legitimately used in Australia (such as “ANZ”, “T20WorldCup” or “Uber”).

Any company wanting to use a sender ID would have to provide identification and register it. This way, telecom providers could refer to the registry and block suspicious messages at the network level – allowing an extra defence in case A2P providers don’t do their due diligence (or become compromised).

It’s not yet decided what identification details an Australia registry would collect, but these could include sender numbers associated with an organisation, and/or a list of A2P providers they use.

So, if there are messages being sent by “ANZ” from a number that ANZ hasn’t registered, or through an A2P provider ANZ hasn’t nominated, the telecom provider could then flag these as scams.

An SMS sender ID registry would be a positive step, but arguably long overdue and sluggishly taken. The UK and Singapore[9] have had similar systems in place since 2018 and last year, respectively. But there’s no clear timeline for Australia. Decision makers must act quickly, bearing in mind that adoption by telecom providers will take time.

Remaining alert

An SMS sender ID registry will reduce company impersonation, but it won’t prevent all SMS scams. Scammers can still use regular sender numbers for scams such as the “Hi Mum[10]” scam.

Also, as SMS security comes under increased scrutiny, bad actors may shift to messaging apps such as WhatsApp or Viber, in which case regulatory control will be challenging.

These apps are often end-to-end encrypted, which makes it very difficult for regulators and service providers to detect and block scams sent through them. So even once a registry is established, whenever that may be, users will need to remain alert[11].

Read more: Australians lost more than $10 million to scammers last year. Follow these easy tips to avoid being conned[12]

References

  1. ^ to SMS scams (theconversation.com)
  2. ^ have surged (www.scamwatch.gov.au)
  3. ^ 'We have filed a case under your name': beware of tax scams — they'll be everywhere this EOFY (theconversation.com)
  4. ^ legitimate service and a scam (7news.com.au)
  5. ^ new rules (www.acma.gov.au)
  6. ^ received a warning (www.acma.gov.au)
  7. ^ ACMA found (www.acma.gov.au)
  8. ^ government instructed (www.smh.com.au)
  9. ^ Singapore (www.sgnic.sg)
  10. ^ Hi Mum (www.accc.gov.au)
  11. ^ remain alert (www.sydney.edu.au)
  12. ^ Australians lost more than $10 million to scammers last year. Follow these easy tips to avoid being conned (theconversation.com)

Read more https://theconversation.com/scammers-can-slip-fake-texts-into-legitimate-sms-threads-will-a-government-crackdown-stop-them-200644

The Times Features

Understanding the Dangers of Ignoring a Gas Leak

Gas leaks are silent threats lurking within both homes and workplaces. A gas leak occurs when natural gas or any other gaseous substance escapes from a pipeline or containment. T...

Can You Sell Your House Privately in Queensland? Here’s How

Selling a house privately in Queensland is entirely possible and can be a cost-effective alternative to using a real estate agent. While agents provide valuable expertise, their co...

Itinerary to Maximize Your Two-Week Adventure in Vietnam and Cambodia

Two weeks may not seem like much, but it’s just the right time for travelers to explore the best of Vietnam and Cambodia. From the bustling streets of Hanoi to the magnificent te...

How to Protect Your Garden Trees from Wind Damage in Australia

In Australia's expansive landscape, garden trees hold noteworthy significance. They not only enhance the aesthetic appeal of our homes but also play an integral role in the local...

Brisbane Homeowners Warned: Non-Compliant Flexible Hoses Pose High Flood Risk

As a homeowner in Brisbane, when you think of the potential for flood damage to your home, you probably think of weather events. But you should know that there may be a tickin...

Argan Oil-Infused Moroccanoil Shampoo: Nourish and Revitalize Your Hair

Are you ready to transform your hair from dull and lifeless to vibrant and full of life? Look no further than the luxurious embrace of Argan Oil-Infused Moroccanoil Shampoo! In a...

Times Magazine

"Eternal Nurture" by Cara Barilla: A Timeless Collection of Wisdom and Healing

Renowned Sydney-born author and educator Cara Barilla has released her latest book, Eternal Nurture, a profound collection of inspirational quotes designed to support mindfulness, emotional healing, and personal growth. With a deep commitment to ...

How AI-Driven SEO Enhancements Can Improve Headless CMS Content Visibility

Whereas SEO (search engine optimization) is critical in the digital landscape for making connections to content, much of it is still done manually keyword research, metatags, final tweaks at publication requiring a human element that takes extensiv...

Crypto Expert John Fenga Reveals How Blockchain is Revolutionising Charity

One of the most persistent challenges in the charity sector is trust. Donors often wonder whether their contributions are being used effectively or if overhead costs consume a significant portion. Traditional fundraising methods can be opaque, with...

Navigating Parenting Arrangements in Australia: A Legal Guide for Parents

Understanding Parenting Arrangements in Australia. Child custody disputes are often one of the most emotionally charged aspects of separation or divorce. Parents naturally want what is best for their children, but the legal process of determining ...

Blocky Adventures: A Minecraft Movie Celebration for Your Wrist

The Minecraft movie is almost here—and it’s time to get excited! With the film set to hit theaters on April 4, 2025, fans have a brand-new reason to celebrate. To honor the upcoming blockbuster, watchfaces.co has released a special Minecraft-inspir...

The Ultimate Guide to Apple Watch Faces & Trending Wallpapers

In today’s digital world, personalization is everything. Your smartwatch isn’t just a timepiece—it’s an extension of your style. Thanks to innovative third-party developers, customizing your Apple Watch has reached new heights with stunning designs...

LayBy Shopping