Search Whitehat Blog

Friday 30 January 2015

Safaricom Leaked Data Bundles Frauds.

Safaricom, Ltd is a leading mobile network operator in Kenya.It provides telecommunication services including cellular network provision , internet services to homes and offices, mobile banking and others.

Safaricom provides internet data to its mobile subscribers. In this way ,as a carrier user, you purchase your data bundle through credit cards , online services, the mobile banking service dubbed M-pesa or get subscriptions depending on your plan.

This telecommunication company is one of the most preferred providers by the citizens and covers most of the countries network system.

Cause of the blunder.

Late in 2014 and early this year , Safaricom sold out some brands of mobile phones and smartphones in their outlets and care centers,e.g Samsung , Nokia ,Techno and Alcatel includes others . This kind of purchase was given out with customers promotions of free airtime and data bundles. Before customers were given this promotions , they used their purchased mobiles EMEI numbers to verify grants of promotions.

Concept of the fraud.

This is where everything become a fraud, technology enthusiasts thought further and dug out how the mobile brand suppliers generate their EMEI  numbers. They then used one valid EMEI address from the vendor to calculate and generate EMEI addresses of corresponding mobile phone produced at a particular time . This mobile brands manufacturers may have sold out this phones in bulk and this made every EMEI calculation SUCCESSFUL.

Fraud Accelerated.

When the fraudsters had identified the formula to generate this EMEI  addresses , an android application was written to ease out  calculations and this turned alarming to Safaricom.

The Theory Behind. (Formula)

The formula that is used by most mobile manufacturers to assign EMEI addresses to every devise is called The Luhn algorithm or Luhn formula . 
As summarized bellow , it is used to generate a code that exits in an encrypted sequence.


PICTURE CREDIT: GOOGLE.COM