HomeSecurityTelegram: Update released to prevent "voicemail hack"

Telegram: Update released to prevent “voicemail hack”

Over the weekend, messaging service Telegram released an update aimed at preventing hackers from exploiting voicemail accounts to gain access to other users' accounts.Telegram

Telegram was forced to release this fix after hackers have been using the so-called “voicemail hack” or “voicemail hijack”. The attackers exploited voicemail and gained access to more than 1,000 Telegram accounts in Brazil. Many of the accounts that were compromised belonged to politicians in the country.

The most prominent victims of the recent attacks are Brazilian President Jair Bolsonaro, Justice Minister Sergio Moro, and Finance Minister Paulo Guedes.

How is voicemail hacked?

Through the voicemail hack, hackers add a account to their device. To do this, they must request a password by calling the account holder's phone number.

Telegram: Update released to prevent "voicemail hack"

If the account holder does not answer the call for three consecutive times, the password will be sent to the user's voicemail account.

Attackers can then use VoIP services to spoof the victim's phone number, gain access to the voicemail account, and use a default passcode of 0000 or 1234 (which most users don't change) to obtain the one-time password. With this passcode, hackers can add another user's Telegram account to their device

Some of the attackers used this technique to gain access to accounts, send spam messages, etc. Others, however, used it to gain access to the history of well-known Brazilian politicians.

Telegram released an update over the weekend

Considering all these attacks, Telegram released an updateto prevent similar account hacking incidents.

According to a Telegram spokesperson, from now on, the one-time password will only be sent via call if the account is protected with two-factor authentication

The update applies to all Telegram users , not just those in Brazil.

The voicemail hack is a well-known hacking technique in recent years. It first appeared in 2017 and exploited WhatsApp. Security researchers have found that this technique could also be used on many other services, such as Facebook, Google, Twitter, WordPress, eBay or PayPal.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS