City
Epaper

Hackers use OTP APIs for SMS bombing, 44 Indian APIs exposed

By IANS | Updated: August 28, 2023 15:00 IST

New Delhi, Aug 28 Hackers have developed automated software programmes that exploit OTP (One-Time Password) verification APIs (Application ...

Open in App

New Delhi, Aug 28 Hackers have developed automated software programmes that exploit OTP (One-Time Password) verification APIs (Application Programming Interface) to flood mobile devices with excessive OTP SMS messages, a new report said on Monday.

According to the cyber-security company CloudSEK, when these rogue scripts are released, they have the potential to cause targeted outages of telecommunications services, causing financial and reputational harm to the brands affected.

The situation raises concerns about the possibility of "multi-factor authentication (MFA) fatigue" or "exhaustion" attacks in account takeover scenarios.

The researchers have uncovered multiple GitHub repositories containing references to global companies and their APIs. These APIs allow unlimited OTP SMS messages to be sent to any number, lacking rate limiting or captcha protection.

This vulnerability has led to the abuse of these APIs by automated tools, resulting in increased API costs, legal repercussions, and reputational damage to affected brands.

"This attack could be used as a veil to hide illegitimate login attempts made by the threat actors to gain access to the users' device. This also implies that while the attack is going on the user may miss out on critical notifications," said Mudit Bansal, Cyber Threat Researcher, CloudSEK.

"Further, due to the constant request of OTPs a service might block your account and you might not be able to access it," he added.

Moreover, the number of exposed APIs according to the country includes -- India with 44 exposed APIs, Russia with 81 exposed APIs, and Indonesia with one exposed APIs.

The findings also underline the accessibility and financial aspects of these malicious services, which include -- numerous online tools that enable anyone to launch such campaigns effortlessly, the tools are available for free, as the primary cost burden falls on the brands owning the SMS-sending APIs, and a single OTP SMS could cost a brand up to 20 paisa.

Bombarding phones with SMS messages, even after activating DND (Do Not Disturb) services, constitutes harassment and nuisance under IPC Section 268, and further qualifies as theft, cheating, and dishonest inducement of property delivery under IPC Sections 378 & 420, the report mentioned.

Disclaimer: This post has been auto-published from an agency feed without any modifications to the text and has not been reviewed by an editor

Tags: congresspitrodadelhimodideepikabjpwest-bengaldeepika-padukoneajay-devgnthakur
Open in App

Related Stories

MumbaiHemant Savara Accident: Palghar BJP MP Suffers Minor Injuries, Driver’s Hand Fractured After Dumper Rams Into Vehicle in Naigaon

MumbaiMumbai-Delhi Expressway: 5 Burnt Alive After Car Catches Fire Near Alwar

NationalWest Bengal Exit Poll Results 2026: BJP Ahead in 3 Surveys; One Projects Win for Mamata Banerjee’s TMC

NationalKerala Exit Polls 2026: Congress-Led UDF Likely to Return to Power After a Decade, LDF Faces Setback

MaharashtraMLC Election 2026: Uddhav Thackeray Picks Ambadas Danve for Council Polls

Technology Realted Stories

Technology‘Technology reshaping justice’, says CJI as Sikkim becomes India’s first paperless judiciary​

TechnologyGreat Nicobar project key to securing India’s maritime interests: Industry

TechnologyMaharashtra Tech Wari 2.0: Over 6,000 employees to take part in person and 9 lakh via live streaming

TechnologyMaruti Suzuki India hits record April sales, up 33 pc at 2.39 lakh units

TechnologyIndia’s white‑collar job market opens FY27 with 6 pc surge in hiring