Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
'Misdial Trap' Phone Scam Hits Financial Services
Newest First  |  Oldest First  |  Threaded View
StudiousMonkey
StudiousMonkey,
User Rank: Apprentice
11/19/2014 | 2:58:53 PM
Clever
Various phone scammers and prank callers have used this technique for years.

Check out the "Touchtone Terrorists". This guy (Pete Dzoghi) made a living telesquatting many of the major courrier services like UPS and FedEx, as well as other organizations and companies. He would pose as various disgruntled customer service agents to ultimately get a huge rise out of the unsuspecting customer who had dialed the wrong number. He recorded these calls and sold them through retail channels.

Although the end result and goal are not the same, the concept has been around for years.
vnewman2
vnewman2,
User Rank: Strategist
11/19/2014 | 1:44:50 AM
Cyber squatting but for phones
So it's telesquatting then. It's pretty clever actually. This is the first time I'm hearing of it. So what is the solution? Unlike websites you can't as easily monitor or pull the plug on a phone number before a boatload of damage has been done.


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Black Hat USA 2022 Attendee Report
Black Hat attendees are not sleeping well. Between concerns about attacks against cloud services, ransomware, and the growing risks to the global supply chain, these security pros have a lot to be worried about. Read our 2022 report to hear what they're concerned about now.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2022-2838
PUBLISHED: 2022-08-16
In Eclipse Sphinxâ„¢ before version 0.13.1, Apache Xerces XML Parser was used without disabling processing of referenced external entities allowing the injection of arbitrary definitions which is able to access local files and expose their contents via HTTP requests.
CVE-2022-35734
PUBLISHED: 2022-08-16
'Hulu / ????' App for Android from version 3.0.47 to the version prior to 3.1.2 uses a hard-coded API key for an external service. By exploiting this vulnerability, API key for an external service may be obtained by analyzing data in the app.
CVE-2022-36293
PUBLISHED: 2022-08-16
Buffer overflow vulnerability in Nintendo Wi-Fi Network Adaptor WAP-001 All versions allows an attacker with an administrative privilege to execute arbitrary code via unspecified vectors.
CVE-2022-36344
PUBLISHED: 2022-08-16
An unquoted search path vulnerability exists in 'JustSystems JUST Online Update for J-License' bundled with multiple products for corporate users as in Ichitaro through Pro5 and others. Since the affected product starts another program with an unquoted file path, a malicious file may be executed wit...
CVE-2022-36381
PUBLISHED: 2022-08-16
OS command injection vulnerability in Nintendo Wi-Fi Network Adaptor WAP-001 All versions allows an attacker with an administrative privilege to execute arbitrary OS commands via unspecified vectors.