NZ Herald
  • Home
  • Latest news
  • Herald NOW
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
  • Herald NOW
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Politics
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Herald NOW
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Business / Companies / Banking and finance

Is your money safe? Bank hack could affect millions across globe

Daily Mail
5 May, 2017 09:27 PM4 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

The vulnerability exposed in the hack could be used against any bank that uses two-step login verification. Photo / 123RF

The vulnerability exposed in the hack could be used against any bank that uses two-step login verification. Photo / 123RF

It was designed as a security measure to increase protection of internet users across the globe.

But hackers have used a well-known security vulnerability in worldwide mobile telecoms networks to steal access codes to online bank accounts, the Daily Mail reports.

The exploit could be used against any bank that uses two-step login verification, as well as high-profile websites like Facebook, Google and many others.

And until money has come out of your bank account, or malicious messages have been sent on social media, you won't know you've been hit.

The attacks, first reported in Germany, are the first time that criminals have been able to exploit the Signal System 7 (SS7) to steal funds from bank accounts.

Advertisement
Advertise with NZME.
Advertisement
Advertise with NZME.

SS7 service helps mobile networks across the world route calls and texts, for example by keeping calls connected as users speed along roads, switching from signal tower to signal tower.

But it can also be used by criminals to redirect data, and hackers have now found a way to intercept the two-stage authentication codes sent out by banks.

These are used to verify the identity of customers attempting log in to their accounts or to place some online transactions.

Advertisement
Advertise with NZME.

They are usually sent in the form of SMS messages and by intercepting these codes through the SS7 service, criminals have free reign to empty funds from your account.

The attacks, reported by German newspaper Süddeutsche Zeitung, were confirmed by telecoms company O2 Telefonica although it is not known how many of their customers were affected.

But most banks and high profile websites use the two-step method, meaning millions of users around the world could be vulnerable.

And the attacks have already come to the attention of legislators in the US who are calling for a crack down on the flaw, which has been known since 2014.

Congressman Ted W Lieu said in a statement: "Everyone's accounts protected by text-based two-factor authentication, such as bank accounts, are potentially at risk until the FCC and telecom industry fix the devastating SS7 security flaw.

"Both the FCC and telecom industry have been aware that hackers can acquire our text messages and phone conversations just knowing our cell phone number.

"It is unacceptable the FCC and telecom industry have not acted sooner to protect our privacy and financial security."

It was also in Germany that researchers discovered the flaw in SS7 in December 2014.

They warned at the time that hackers could use the exploit to locate callers anywhere in the world, listen to calls as they happen or record hundreds of encrypted calls and texts at a time for later decryption.

Despite this, two-step authentication codes continue to be sent via SMS messages by many of the world's largest internet companies.

Advertisement
Advertise with NZME.

Among them is Google, who promotes '2-Step Verification' as an extra-layer of security designed to 'keep the bad guys out.

Thankfully hackers must already have access to the first stage of verification, namely your username and password, for the attack to work, and this is something you can control.

Login details are usually sourced from data leaks affecting other sites, as people often use the same passwords.

There are a number of websites that collect information on mass data-breeches and allow you to check whether your details are among them, including one widely-used site 'Have I Been Pwned?'.

It is important to note that in a data breech, for example where your Hotmail email address is listed in a breech of LinkedIn, it is the password for LinkedIn which hackers have access to rather than the Hotmail account - unless they are the same.

This is why it is vital to use different and complex passwords across different sites, so that a breech of your password on one site does not allow hackers to access your account on others..

Advertisement
Advertise with NZME.

Reputable password managers that suggest strong passwords and stores them in an encrypted file on your own computer can make these more simple to generate and remember.

Save

    Share this article

Latest from Banking and finance

Banking and finance

Rishi Sunak returns to Wall Street bank he joined as intern

09 Jul 12:07 AM
Premium
Companies|banking and finance

NZ’s largest taxpayers revealed - does big business play fair?

01 Jul 05:00 PM
Banking and finance

Watercare secures $3.4b debt facility, largest for NZ corporate

30 Jun 05:00 PM

From early mornings to easy living

sponsored
Advertisement
Advertise with NZME.

Latest from Banking and finance

Rishi Sunak returns to Wall Street bank he joined as intern

Rishi Sunak returns to Wall Street bank he joined as intern

09 Jul 12:07 AM

His pay will go to his charity, the Richmond Project.

Premium
NZ’s largest taxpayers revealed - does big business play fair?

NZ’s largest taxpayers revealed - does big business play fair?

01 Jul 05:00 PM
Watercare secures $3.4b debt facility, largest for NZ corporate

Watercare secures $3.4b debt facility, largest for NZ corporate

30 Jun 05:00 PM
Big Reserve Bank scheme to protect Kiwis' savings launching

Big Reserve Bank scheme to protect Kiwis' savings launching

29 Jun 05:00 PM
Solar bat monitors uncover secrets of Auckland’s night sky
sponsored

Solar bat monitors uncover secrets of Auckland’s night sky

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven Car Guide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP