Your Code is 0000: An Analysis of the Disposable Phone Numbers Ecosystem

06/26/2023
by   José Miguel Moreno, et al.
0

Short Message Service (SMS) is a popular channel for online service providers to verify accounts and authenticate users registered to a particular service. Specialized applications, called Public SMS Gateways (PSGs), offer free Disposable Phone Numbers (DPNs) that can be used to receive SMS messages. DPNs allow users to protect their privacy when creating online accounts. However, they can also be abused for fraudulent activities and to bypass security mechanisms like Two-Factor Authentication (2FA). In this paper, we perform a large-scale and longitudinal study of the DPN ecosystem by monitoring 17,141 unique DPNs in 29 PSGs over the course of 12 months. Using a dataset of over 70M messages, we provide an overview of the ecosystem and study the different services that offer DPNs and their relationships. Next, we build a framework that (i) identifies and classifies the purpose of an SMS; and (ii) accurately attributes every message to more than 200 popular Internet services that require SMS for creating registered accounts. Our results indicate that the DPN ecosystem is globally used to support fraudulent account creation and access, and that this issue is ubiquitous and affects all major Internet platforms and specialized online services.

READ FULL TEXT
research
04/17/2021

Towards Fortifying the Multi-Factor-Based Online Account Ecosystem

With the rapid growth of online services, the number of online accounts ...
research
07/09/2020

Value driven Analysis Framework of Service Ecosystem Evolution Mechanism

With the development of cloud computing, service computing, IoT(Internet...
research
04/04/2022

Clues in Tweets: Twitter-Guided Discovery and Analysis of SMS Spam

With its critical role in business and service delivery through mobile d...
research
02/03/2022

Entanglement: Cybercrime Connections of an Internet Marketing Forum Population

Many activities related to cybercrime operations do not require much sec...
research
11/14/2019

Arguing Ecosystem Values with Paraconsistent Logics

The valuation of ecosystem services prompts dialogical settings where no...
research
01/25/2018

Forecasting Suspicious Account Activity at Large-Scale Online Service Providers

In the face of large-scale automated social engineering attacks to large...
research
07/26/2021

Collaborative Problem Solving on a Data Platform Kaggle

Data exchange across different domains has gained much attention as a wa...

Please sign up or login with your details

Forgot password? Click here to reset