Follow Us

Criminals offer huge sum for flawed mobile

Cheapo Nokia used for PAYG back hacks.

Criminals are willing to pay thousands of euros for a discontinued Nokia mobile phone with a software problem that can be exploited to hack into online bank accounts, according to a fraud investigator in the Netherlands.

About 10 days ago, investigators observed someone transfer €25,000 (£22,200 or $32,413 US) for a Nokia 1100 phone, said Frank Engelsman of Ultrascan Advanced Global Investigations. The candy-bar style phone is one of Nokia's all-time best-selling models, and originally sold for under €100.

Engelsman said police contacted Ultrascan about six months ago to see if the security company knew why the phones were in demand. Since then, Ultrascan has seen the price for the Nokia 1100 rise from around €5,000 to the latest figure.

"We thought 'What could be so special about the phone?'" Engelsman said.

The 1100 was a low-cost phone released in late 2003 and aimed at developing markets. Nokia has sold more than 200 million of the 1100 and its successors.

However, the high prices are only being paid for Nokia 1100 phones that were made in a factory in Bochum, Germany, Engelsman said, citing an Ultrascan informant. Those phones contain Nokia software from 2002 that is apparently vulnerable to tampering.

Investigators don't have a complete picture of the technical problem. However, Ultrascan's informant said the phones can be used to intercept one-time passwords needed to complete an online banking transaction, Engelsman said.

It appears that a known Russian and Moroccan cybercrime gang, as well as other Romanian gangs, are trying to obtain the Nokia 1100 with the vulnerable software, Engelsman said.

Nokia officials contacted Monday morning did not have an immediate comment.

Engelsman said cybercriminals have collected thousands of user names and passwords for online banking accounts in countries such as Germany and Holland. Banks in those countries also request a TAN (transaction authentication number) code, or a one-time password, to complete a transaction.

The banks previously issued lists of TAN codes to customers. During a transaction, the bank would request one of the codes to complete the transaction. However, due to successful phishing attacks where people have been tricked into revealing some TAN codes, the banks are now sending a code by SMS to a person's mobile phone, Engelsman said.

The Bochum-made 1100 can apparently be reprogrammed to use someone else's phone number, thus intercepting the TAN code and enabling an illegal money transfer into a criminal's account, Engelsman said. Ultrascan is trying to obtain the affected 1100 model to verify if the attack works as described, he said.

The Nokia 1100 has had other software problems. A drug-related criminal case in the Netherlands in late 2005 detailed how the police had difficulty linking SMSes sent from certain Nokia 1100 phones to a specific phone number. Police were, however, able to use other means to identify the general area in which the phones were used, which helped bolster their case, Engelsman said.




Comments

sufiyan rajwani said: i am having 1 piece of nokia 1100 plz provide me the best priceof what you can give the i can give the photo also to the seriousbuyers my email id is sufiyanrajwani gmail com 919998152560



Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Choose – and Choose Wisely – the Right MSP for Your SMB

End users need a technology partner that provides transparency, enables productivity, delivers...

Download Whitepaper

10 Effective Habits of Indispensable IT Departments

It’s no secret that responsibilities are growing while budgets continue to shrink. Download this...

Download Whitepaper

Optimise Performance For Global eCommerce

Global is all the rage: eBusiness teams are feverishly building new international initiatives in...

Download Whitepaper

Gartner Magic Quadrant for Enterprise Information Archiving

Enterprise information archiving is contributing to organisational needs for e-discovery and...

Download Whitepaper

Techworld UK - Technology - Business

Part 2 of your journey to virtualisation

You can still access part 2 of our virtualisation journey - explore how you can improve your servers, storage and networks by developing your infrastructure.

Watch now...
Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

From Wow to How : Making mobile and cloud work for you

On demand Biztech Briefing - Learn how to effectively deliver mobile work styles and cloud services together.

Watch now...

Site Map

* *