started · updated
Cybercriminals use SMS phishing and 2G exploits to target mobile users
A new SMS phishing campaign is targeting users in Argentina by impersonating loyalty and benefits programs. Cybercriminals send messages claiming accumulated points are about to expire, prompting victims to redeem them for products. The fraud is particularly deceptive because the messages can appear within the same conversation thread used by legitimate telecommunications providers, such as Claro, Personal, and Movistar.
When victims click the provided link, they are directed to a fraudulent website that mimics the aesthetic of the telecom company. The scam concludes by requesting credit card details to pay for the supposed shipping of the reward.
To combat such vulnerabilities, Google is working to enhance Android 17 to prevent attackers from using fake base stations, known as SMS Blasters. These devices trick mobile phones into abandoning 5G networks to connect to insecure 2G networks. Once connected via 2G, attackers can inject unencrypted messages and bypass carrier fraud detection systems by spoofing legitimate sender identities.