Hackers with access to Signaling System 7 (SS7) used for connecting to mobile networks worldwide were able to gain access to the Telegram messenger and the email data of high‑profile individuals in the cryptocurrency business.
The hackers obtained the two-factor authentication ( 2FA ) login codes through the victim's mobile provider's short messaging system

Well-prepared hackers
Hackers carrying out an SS7 attack can monitor a user's text messages and calls by receiving information about the location of their device as if it were registered to a different network (roaming scenario).
The attack took place in September and targeted at least 20 subscribers of Partner Communications Company (formerly known as Orange Israel) – all of them participated in high-level cryptocurrency projects.
Tsachi Ganot, co-founder of Pandora Security in Tel-Aviv, who investigated the incident and helped victims regain access to accounts , told BleepingComputer that all indications point to an SS7 attack.
Pandora Security specializes in creating secure digital environments and provides cybersecurity technology and services to high- profile, including prominent business figures and celebrities. According to Ganot, its clients include some of the wealthiest people in the world.
Ganot told us that the attackers likely spoofed a mobile network to send an "update location request" for a targeted number of phones to Partner (other providers may still be vulnerable to this type of attack).
The information request essentially asked Partner to send all voice calls and SMS messages intended for the victims.
Ganot says the attackers had good knowledge of the victims' accounts and passwords . They knew unique international subscriber numbers and international mobile subscriber identity (IMSI) numbers.
SS7 attacks, while more frequent in recent years, are not easy to carry out and require good knowledge of the interaction of home mobile networks and communication on a global level.
In this case, the hackers' goal was to obtain cryptocurrency. Ganot believes that some of the inboxes were compromised in this way to act as a backup method for other email accounts with more data, allowing the threat actor to achieve their goal.
This method is well-known in the cryptocurrency community, and users are usually wary of such requests. Ganot says that “to our knowledge, no one has taken the bait.”
Even though sending verification codes via SMS is widely considered insecure in the information community, many services continue to rely on this practice, putting users at risk.
There are better authentication methods today than 2FA authentication via SMS or calls. Purpose-built apps or “physical keys” are among the solutions, Ganot says, adding that telecommunications standards need to move away from older protocols like SS7 (developed in 1975), which cannot address many modern issues.
The Israeli newspaper Haaretz published details about this attack earlier this month, saying that Israel's national intelligence agency (Mossad) and the National Cyber Security Authority were involved in the investigation.
