Australian telecom provider injects advertisement into Google text message

Spread the love

An Australian telecom provider has placed advertisements in a verification SMS from Google, much to Google’s surprise. That was discovered by a developer who received the text message. It wasn’t about phishing; the verification code was legit. Google is in talks with the provider.

The ad was discovered by developer Chris Lacy, who posted a screenshot on Twitter . It shows that the verification code is followed by an ‘SMS AD’ for a VPN service. At first, the SMS looks like a phishing attempt, but according to Lacy, the code in the SMS for logging in with 2fa worked and was therefore a legitimate SMS from Google. Google Messages also marks the SMS as spam.

After input from several Google employees , Lacy says it appears that his telecom provider injected the ad into the text message. In a response to 9to5Google , Google says that it was not an advertisement from them and that it is in talks with the telecom provider to find out what happened. Google’s security researcher Mark Risher says the company does not accept this practice.

Lacy is aware that SMS is not suitable for two-step verification because it is not encrypted, he says. It was an old account that had no alternative 2fa set. He does not want to reveal the name of the provider for privacy reasons.

You might also like