{"id":1308,"date":"2020-02-20T13:00:28","date_gmt":"2020-02-20T09:00:28","guid":{"rendered":"https:\/\/www.techxmedia.com\/?p=1308"},"modified":"2025-04-18T00:01:37","modified_gmt":"2025-04-17T20:01:37","slug":"avoid-getting-phone-hacked","status":"publish","type":"post","link":"https:\/\/techxmedia.com\/en\/avoid-getting-phone-hacked\/","title":{"rendered":"3 ways to avoid getting phone hacked"},"content":{"rendered":"\n<p><a><strong>By Haider\nPasha<\/strong><\/a><\/p>\n\n\n\n<p>You have probably seen in the news\nthat <a href=\"https:\/\/www.wsj.com\/articles\/report-alleging-saudi-hack-of-bezos-phone-puzzles-security-experts-11579865394\">high-net-worth\nindividuals<\/a>, famous athletes and entertainers are becoming favorite\ntargets of phone hacking. In some cases, when security experts can\u2019t agree,\nit\u2019s because mobile device forensics is very limited to even confirm that\nsomeone has been compromised and reconstruct what exactly happened. &nbsp;\n&nbsp;<\/p>\n\n\n\n<p>Mobile phones are becoming a fruitful\nand surprisingly easy target for hackers. It used to be that businesses issued\ntheir executives work phones that used only business applications. But today,\nour phones are just as likely to hold intellectual property memos as they are\nto be used for listening to music.<\/p>\n\n\n\n<p>Hackers started by looking for\nsalacious photos and embarrassing text messages, but now they\u2019ve moved to\nmobile malware, ransomware and identity theft aimed at penetrating corporate\nnetworks and exfiltrating mission-critical data held on the phones of CEOs,\nboard members and political leaders.<\/p>\n\n\n\n<p>Let\u2019s be clear: Your organization\u2019s\nmost sensitive and proprietary data is at risk, in large part because you are\nroutinely accessing it through your mobile phone. And the hackers know\nit.&nbsp;We must recognize the magnitude and potential impact of this problem\nand take decisive steps to bolster our cyber defense.<\/p>\n\n\n\n<p><strong>Mobile Phone Security Threats Are\nEvolving<\/strong><\/p>\n\n\n\n<p>When we rely on our mobile phones for\nwork tasks, we expand the cybersecurity threat landscape. There are two big\nchallenges associated with mobile cybersecurity threats:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>The Wolf in Sheep\u2019s Clothing. The sheer number of applications we can use on our phones is exploding. Apple and Google are doing excellent work with securing their operating systems,      but securing third-party applications remains a big challenge. We\u2019ve added a lot of functionality to our phones, but much of those added features have made it far easier for bad actors to access things like our work contacts and their phone numbers. As hackers work their way into our phones through fraudulent applications that suddenly develop a second life or exploiting vulnerabilities in common applications like WhatsApp, it\u2019s not a big leap to installing professional malware for jailbreaking, espionage, ransomware or data exfiltration.<\/li><li>No Place Left to Hide. I\u2019ll spare you the technical details, but keep in mind that mobile networks rely on vulnerable roaming protocols like SS7 or Diameter, which are easy targets for cyber threats. Simply having access to your phone number allows hackers with a little investment to trace your location quite easily \u2026 or even to take over your incoming calls or text\/SMS or WhatsApp messages. These attack methods have been used for a long time, not only for professional espionage but also for large-scale online banking fraud. This is also the reason why banks don\u2019t consider SMS as a secured two-factor authentication approach anymore. All in all, it\u2019s very difficult to protect yourself against location tracing or phone or SMS takeover attacks.<\/li><\/ul>\n\n\n\n<p>But, the good news is that the state\nof mobile phone cybersecurity is not as bleak as it sounds from the press.\nToday\u2019s mobile phones, at the device level, have strong security architectures.\nThe ecosystems for the most popular phones\u2014Apple iPhone and Google Android\u2014are\nhighly secure, with strong hardware-based security and isolation approaches.\nAnd, unlike other software exploits, exploit code to compromise a mobile device\nwithout your interaction <a href=\"https:\/\/zerodium.com\/program.html\">would cost attackers millions<\/a>.\nA hacker has to make a huge investment if he wants to compromise your mobile\nphone in order to exfiltrate your data.<\/p>\n\n\n\n<p>Still, are you going to take a chance\non exposing your enterprise\u2019s most critical data due to lax cybersecurity\nframeworks and practices? Of course not.<\/p>\n\n\n\n<p><strong>What You Can Do Now<\/strong><\/p>\n\n\n\n<p>There are three strong steps all\nbusiness leaders can and should do now in order to harden their phones\u2019\ndefenses:<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li><strong>Security <\/strong>hygiene.&nbsp;If you\u2019re a heavy user of your phone for business, you have to make sure it has the most up-to-date security. Also, antivirus for mobile phones is a myth. Compared to our computers, an anti-virus app on mobile phone will often not be able to protect against malicious apps. The reason is that the hardware-based architecture of the mobile phone forces every app to be isolated from each other.&nbsp;However, one security control which is often overlooked on mobile devices is network security. Instead of routing all your insecurely to the Internet, you can use secure VPN or <a href=\"https:\/\/blogs.gartner.com\/andrew-lerner\/2019\/12\/23\/say-hello-sase-secure-access-service-edge\/\">Secure      Access Service Edge (SASE)<\/a> solution. Such solution can block traffic to malicious websites or data exfiltration attempts.<\/li><li>Application hygiene. Any application on your phone can expose data and be used as a bridge to compromise your device. Whitelisting <a href=\"https:\/\/www.securityroundtable.org\/can-you-talk-the-talk-cybersecurity-jargon-101-for-executives\/\">and blacklisting<\/a> applications are now becoming standard practice for IT and security administrators, and you should follow these practices on your own phone as well. For instance, do you really need those five messenger applications? Are you automatically downloading content across social media applications? Do your kids or grandchildren use your phone and download games?<\/li><li>Privacy hygiene. Having just your phone number will allow cybercriminals to trace you, physically and electronically, everywhere in the world. And remember that your colleagues,      suppliers, and customers store your number and other contact details on their phones as well. And this data can be easily exfiltrated by fraudulent applications installed on their phones to expose your number.<\/li><\/ol>\n\n\n\n<p>The more you use your phone for work reasons, the greater you expand cybersecurity threat vectors into your organization\u2019s applications, databases and data. It\u2019s like opening the door of your factory-wide open and handing strangers an access card to your mainframe and robotics equipment. It can only end badly.<\/p>\n\n\n\n<p>As an executive, you should follow\nthese best practices personally, but also support the deployment and\nadministration of sound mobile phone cybersecurity processes for all employees.\nYou are in a unique, powerful position to send the right message to your\ncolleagues and subordinates. Your phone is every bit as much a computer as any\ndesktop, notebook or server. Protect it accordingly.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Mobile phones are becoming a fruitful and surprisingly easy target for hackers. It used to be that businesses issued their executives work phones that used only business applications. But today, our phones are just as likely to hold intellectual property memos as they are to be used for listening to music.<\/p>\n","protected":false},"author":8,"featured_media":1313,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[1595,9621],"tags":[369,315,464,465,466],"contributor":[],"class_list":["post-1308","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","category-emerging-technologies","tag-cyberattack","tag-cybercrime","tag-cybersecurityawareness","tag-mobilesecurity","tag-mobilesolutions"],"featured_image_src":"https:\/\/techxmedia.com\/en\/wp-content\/uploads\/2020\/02\/Haider-Pasha-e1582189367847.jpg","author_info":{"display_name":"Rabab","author_link":"https:\/\/techxmedia.com\/en\/author\/rabab\/"},"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/posts\/1308","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/comments?post=1308"}],"version-history":[{"count":0,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/posts\/1308\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/media\/1313"}],"wp:attachment":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/media?parent=1308"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/categories?post=1308"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/tags?post=1308"},{"taxonomy":"contributor","embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/contributor?post=1308"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}