Using leaked data to examine vulnerabilities in SMS routing and SS7 signalling medium.com

Every day, millions of two-factor authentication codes travel the globe, securing access to bank accounts, email inboxes, dating profiles and encrypted chats. These SMS messages are designed to keep people’s accounts safe, yet rely on a sprawling, opaque and unregulated industry of intermediaries to reach their devices. A new leak obtained by Lighthouse Reports exposes just how vulnerable that system is.

I learned a lot how SMS messages are delivered and how vulnerable this system is. 2FA should absolutely not use SMS, rather use OTP for example.

Published: July 20, 2025
Tags: #security