Over a billion Android phones vulnerable to phishing attack

(Image credit: Shutterstock.com)

Over a billion Android smartphones, including those from the world's largest manufacturers, are vulnerable to a hugely dangerous cyberattack, researchers have warned.

A new report from Check Point Research has uncovered a security flaw that could leave users open to advanced phishing attacks that would steal personal information.

The company says that hundreds of millions of Android phones across the world are at risk from the attack, with devices from Samsung, Huawei, LG and Sony among those affected.

Counterfeit

The flaw allowed hackers to steal user email addresses using counterfeit Android SMS messages that have been custom-engineered to intercept all email traffic to and from mobiles. 

The affected Android phones use over-the-air (OTA) provisioning, which allows mobile network operators to deploy network-specific settings to a new phone joining their network. 

In this case, the SMS is disguised as an innocent ‘update network settings’ text from the mobile network provider.

The researchers say that anyone connected to a cellular network can be targeted by such attacks, as the SMS doesn't require a victim's device to be connected to a Wi-Fi network, and it only takes a single message to gain full access to a device’s emails. 

Samsung phones were found to be the most at risk to the attack as they do not have an authenticity check. The user only needs to accept the message for the malicious software to be installed without the sender needing to prove their identity.

“Given the popularity of Android devices, this is a critical vulnerability that must be addressed,” said Slava Makkaveev, security researcher at Check Point Software Technologies. 

“Without a stronger form of authentication, it is easy for a malicious agent to launch a phishing attack through over-the-air provisioning. ”

Check Point says the flaw was first detected in March 2019, and the company told the affected manufacturers soon after. 

So far, Samsung and LG have released fixes, with Huawei set to launch its patch in the next generation of Mate and P-series smartphones - with Sony insisting its devices are already up to scratch.

Mike Moore
Deputy Editor, TechRadar Pro

Mike Moore is Deputy Editor at TechRadar Pro. He has worked as a B2B and B2C tech journalist for nearly a decade, including at one of the UK's leading national newspapers and fellow Future title ITProPortal, and when he's not keeping track of all the latest enterprise and workplace trends, can most likely be found watching, following or taking part in some kind of sport.

Latest in Security
Woman shocked by online scam, holding her credit card outside
Cybercriminals used vendor backdoor to steal almost $600,000 of Taylor Swift tickets
Woman using iMessage on iPhone
UK government guidelines remove encryption advice following Apple backdoor spat
Cryptocurrencies
Ransomware’s favorite Russian crypto exchange seized by law enforcement
Wordpress brand logo on computer screen. Man typing on the keyboard.
Thousands of WordPress sites targeted with malicious plugin backdoor attacks
HTTPS in a browser address bar
Malicious "polymorphic" Chrome extensions can mimic other tools to trick victims
ransomware avast
Hackers spotted using unsecured webcam to launch cyberattack
Latest in News
MacBook Air mute key
The new M4 MacBook Air finally fixes an Apple keyboard annoyance that's been around for decades
A collage of Ellie and Joel in The Last of Us season 2
The Last of Us season 2's new trailer teases a huge showdown between Bella Ramsey's Ellie and Pedro Pascal's Joel, but the big moment I'm waiting for is still being held back
Apple iPhone 16 Pro Max REVIEW
New iPhone 17 Air leak may have revealed some key specs – and how it compares to the iPhone 17 Pro Max
Gaming with AI
I asked Gemini to play a text-based adventure game with me and the AI whisked me away to a word-based fantasy
Apple iPhone 16 Review
Three iPhone 17 model dummy units appear in a hands-on video leak
The Samsung Galaxy S25 Edge on display the January 22, 2025 Galaxy Unpacked event.
New Samsung Galaxy S25 Edge may have revealed some key details – including its price