Mon, 20 Apr 2009 Hackers paying £22k for old Nokia 1100 mobile phones
A software problem in the Nokia 1100 allows criminals to intercept online banking details
Criminals are willing to pay thousands of euros for a discontinued Nokia mobile phone with a software problem that can be exploited to hack into online bank accounts, according to a fraud investigator in the Netherlands.
About 10 days ago, investigators observed someone transfer €25,000 (£22,207) for a Nokia 1100 phone, said Frank Engelsman of Ultrascan Advanced Global Investigations. The candy-bar style phone is one of Nokia's all-time best-selling models, and originally sold for under €100.
Question of the day!
Do you share your creations online?
% of Macworld readers agree with you
What do you create and how do you share it?
Follow the conversation at @TabletChat
paintings & illustrations, mostly, which i upload to flickr.RT @fragmentedm
I draw manga/anime characters. I also do graphic design and photography.RT @spialelo
Yes. I usually put them up on my #deviantart account for feedback on how to improve.RT @spialelo
Engelsman said police contacted Ultrascan about six months ago to see if the security company knew why the phones were in demand. Since then, Ultrascan has seen the price for the Nokia 1100 rise from around €5,000 to the latest figure.
"We thought 'What could be so special about the phone?'" Engelsman said.
The 1100 was a low-cost phone released in late 2003 and aimed at developing markets. Nokia has sold more than 200 million of the 1100 and its successors.
However, the high prices are only being paid for Nokia 1100 phones that were made in a factory in Bochum, Germany, Engelsman said, citing an Ultrascan informant. Those phones contain Nokia software from 2002 that is apparently vulnerable to tampering.
Investigators don't have a complete picture of the technical problem. However, Ultrascan's informant said the phones can be used to intercept one-time passwords needed to complete an online banking transaction, Engelsman said.
It appears that a known Russian and Moroccan cybercrime gang, as well as other Romanian gangs, are trying to obtain the Nokia 1100 with the vulnerable software, Engelsman said.
Nokia officials contacted Monday morning did not have an immediate comment.

Engelsman said cybercriminals have collected thousands of user names and passwords for online banking accounts in countries such as Germany and Holland. Banks in those countries also request a TAN (transaction authentication number) code, or a one-time password, to complete a transaction.
The banks previously issued lists of TAN codes to customers. During a transaction, the bank would request one of the codes to complete the transaction. However, due to successful phishing attacks where people have been tricked into revealing some TAN codes, the banks are now sending a code by SMS (Short Message Service) to a person's mobile phone, Engelsman said.
The Bochum-made 1100 can apparently be reprogrammed to use someone else's phone number, thus intercepting the TAN code and enabling an illegal money transfer into a criminal's account, Engelsman said. Ultrascan is trying to obtain the affected 1100 model to verify if the attack works as described, he said.
The Nokia 1100 has had other software problems. A drug-related criminal case in the Netherlands in late 2005 detailed how the police had difficulty linking SMSes sent from certain Nokia 1100 phones to a specific phone number. Police were, however, able to use other means to identify the general area in which the phones were used, which helped bolster their case, Engelsman said.
Check out our new Macworld Mobile site.
Follow Macworld UK on twitter: www.twitter.com/macworlduk
Email A Friend
Email this article to a friend or colleague:
PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.
Permalink This Article
This articles permalink is:
http://www.macworld.co.uk/digitallifestyle/news/index.cfm?newsid=25771
<<prev article | back to news index | next article>>
Latest News
- Apple intros Aperture 3, adds over 200 new features
- VIP iPhone app drops from millionaire priced £279.99 to under a tenner
- Play.com: Google Nexus One now available for pre-order
- Amazon's Kindle gets ready to battle Apple's iPad
- Apple Store is down, new Macs imminent?
- Canon intros EOS 550D 18-megapixel DSLR camera
- WSJ: Apple could slash iPad prices if sales disappoint
- Apple offers 'find out how' tutorials as podcasts
- Adobe says sorry for 16-month-old Flash bug
- Getty launches subscription stock image service, Thinkstock
- RouteBuddy intros RouteBuddy Atlas 1.3 for iPhone, iPod touch
- AppFund seeks Apple iPad developers, offers funding up to $500,000

It's easy and free to get the latest news headlines, reviews and opinions straight to your email inbox. Sign up NOW to make sure you receive the latest Mac news, reviews and tutorials on your favourite topics.






Comments received
theodora Wayte said on Mon, 20 Apr 2009
I have two of those!
Robb said on Mon, 20 Apr 2009
lucky you ^^ !!
be ironic if you sold them and then got hacked :P
Susan said on Tue, 21 Apr 2009
This is a myth that's spreading like wildfire.... Ultrascan are looking like such fools!!!!!
Salvo said on Tue, 21 Apr 2009
i have this phone... it's from german :D
jopa said on Tue, 21 Apr 2009
another feeble attempt by iphone makers to kick superb nokia devices
gatyi said on Wed, 22 Apr 2009
even if u have u not a hacker lol
CJD said on Fri, 24 Apr 2009
Sorry, I don't quite get this. Is this the hardware or operating system which is at fault?
KOKO said on Sat, 25 Apr 2009
good i have three mobile 1100
a mishra said on Tue, 12 May 2009
i have 4 in my home 1 is dead =))
Disclaimer
Opinions expressed here are those of the writers and do not reflect those of Macworld. Macworld accepts no responsibility legal or otherwise for their accuracy of content.
Click here to read the house rules.
Click here for the latest reader comments