This website requires JavaScript.

‘SIM Card Registration No Silver Bullet Versus Spam Texts’

‘SIM Card Registration No Silver Bullet Versus Spam Texts’
Photo by Reuters

While the passage of a subscriber identity module or SIM card registration law is welcome, it will not be a silver bullet to end the problem on scammers who use information communications technology (ICT) to victimize consumers, according to executives of the National Privacy Commission (NPC) and leading telecommunication companies (telcos).

For NPC Deputy Commissioner Leandro Angelo Aguirre, there will be a need for constant vigilance and awareness among telco consumers that ICT will always be used as a means for unscrupulous people to trick unsuspecting victims for money.

“(The passage of a law) can help. Hopefully, it can be a deterrent to the use of SIM cards to carry out (such scams),” Aguirre said at a virtual press briefing with telco executives and the National Telecommunications Commission (NTC) on Wednesday, Sept. 6, to discuss the government and private sector’s action against text scammers.

“It will definitely help, but it will not completely stop scammers from doing their thing because they will keep finding ways to use other kinds of technology or other methodology to be able to send these scam texts,” he added in Filipino.

The NPC official also underscored the need to continuously investigate the matter and for the agency to coordinate with other people as it is crucial in resolving the issue.

Angel Redoble, first vice president and chief information security officer of the PLDT Group, Smart Communications and the e-PLDT Group, echoed Aguirre’s position.

“We have always been supportive of SIM registration. We are excited … and we welcome that SIM registration law,” Redoble said at the same briefing.

“As to whether it will be a silver bullet against text scams, well, I agree with what Deputy Commissioner Aguirre said,” he added.

The law might be effective today, but scammers are also getting better, according to Redoble.

“We have to prepare and we should anticipate,” he said. “We have a saying in cyber security: to catch a hacker, you have to think like a hacker. In this case, perhaps, we don’t allow the scammers to stay one step or two steps ahead of us. We will get ahead of them.”

Phone-to-phone transmission

The NPC said data aggregators are unlikely to be the source of the recent wave of targeted smishing messages, emphasizing that these messages are possibly sent through a phone-to-phone (P2P) transmission.

“The NPC, through its Complaints and Investigation Division, has observed from the smishing reports it received, that the smishing messages appear to have been sent using specific mobile numbers registered to certain texting services,” he added.

As confirmed with the telcos, Aguirre noted that smishing messages which are sent using mobile numbers are possible through a P2P transmission.

“Such transmission is usually coursed through a telecommunication company’s regular network and does not pass through data aggregators,” he said.

He explained that data aggregators, on the other hand, use an application-to-phone (A2P) transmission.

Under the A2P transmission, messages received will not appear to have come from specific mobile numbers; instead, it will come from a sender that has SMS ID, such as bank names or organization, which identifies the data aggregator, or the brand or business name using the data aggregator’s services.

During the webinar, NPC Complaints and Investigation Division chief Michael Santos explained that once receivers click the link in the smishing message, they will be taken to a website where it will encourage them to sign up to invest.

These will ask the receiver to click certain permissions and put in more information, according to Santos.

“We think now, they only know names and numbers. That’s why they are asking you to sign up. They want to get the rest of the personal information so they can use it to scam us,” he said in Filipino.

Meanwhile, Aguirre said the NPC has been continuously investigating potential sources and root cause of targeted smishing messages such as patterns in the use of name formats that prospectively match the names of data subjects registered with popular payment applications, mobile wallets and messaging applications.

He added that the NPC is working closely with telcos in formulating countermeasures against the recent wave of targeted smishing messages.

“As a concrete course of action, telecommunication companies have blocked identified mobile numbers that sent smishing messages and are continuously blocking messages with mali-cious URL links associated with smishing,” Aguirre said.

URLs, which stand for uniform resource locators, refer to specific entities’ websites or addresses on the internet.

The NPC official said they would pursue the investigation to its full extent and within the bounds of its mandate to protect the fundamental human right to privacy.

“Through relevant issuances, the commission will be compelling entities involved to take firm action in addressing the possible privacy risk brought about by targeted smishing messages,” he added.

The NPC further reminded the public to remain vigilant and report incidents of targeted smishing.

Challenge

The investigation to find out the people responsible for the proliferation of personalized spam text messages is proving to be a challenge for the Philippine National Police (PNP).

PNP spokesperson Col. Jean Fajardo admitted on Wednesday that among the challenges that investigators are facing is the legal processes to obtain cyber warrants.

“We have to understand our (data) privacy act,” Fajardo said at a press conference at Camp Crame.

Another hindrance, she noted, is that SIM cards can be easily bought and disposed of after a crime is committed.

The PNP is supporting the proposed investigation of the Senate committee on public services on the continued proliferation of text scam messages victimizing millions of Filipinos.

PNP officer-in-charge Lt. Gen. Jose Chiquito Malayo said they would contribute to and cooperate in the investigation.

Malayo also expressed approval for the implementation of the SIM Card Registration Act which, he said, will help them identify scammers who use their communication devices to victimize un-suspecting individuals.

The PNP official, however, said security measures should be in place to safeguard the prepaid SIM subscriber’s data, similar to security features of postpaid SIM card subscribers.

“We continuously call on our fellow citizens to be wary of messages being sent to them and not easily believe in them even if the text messages have their names in them,” Malayo said in a statement in Filipino.

Numbers blocked

Meanwhile, leading telcos PLDT-Smart Communications has blocked almost 200,000 SIM card phone numbers while rival Globe Telecom has deactivated about 23,000 in their respective battles against the proliferation of unsolicited text promos and scams affecting the country’s telco consumers.

Redoble bared that his group has been waging a 24/7 blocking campaign of Smart SIM cards that are found and confirmed to be sending out unsolicited text promo and scam messages.

“Because our operations in blocking these numbers is 24/7, we receive reports 24/7,” he said at the same virtual press briefing with the NPC and NTC on Wednesday.

“I don’t have the exact figures, but there are many. Our total now of blocked mobile numbers is almost 200,000 since a few months ago,” he added.

Globe deactivated almost 23,000 SIM card phone numbers from January to July this year, according to the telco firm’s chief privacy officer Irish Salandanan-Almeida.

“Looking at figures for Globe, from January to July only, we’ve blocked already 784 million scam and spam messages, and we also deactivated 14,058 SIMs and we blacklisted 8,973 other SIMs,” Almeida said.

“The links in SMS (short messaging service) or text messages, we already blocked 610 domains or URLs,” Almeida said.

DITO Telecommunity Corp. data protection officer Roberto Miguel Raneses said they had a small number of such erring SIM card phone number holders.

“We have very minimal cases. We have less than 50,” Raneses added.

He said telco consumers or mobile phone users should be aware that senders of such unsolicited text messages with links on supposed promotional offers are scammers. – With Catherine Talavera, Emmanuel Tupas