The Threats That Make the News Are Rarely New

Itwerx is a managed IT and cybersecurity provider serving businesses across Seattle, Everett and Lynnwood since 2005. This is about how to read an alarming security headline, using one widely reported story as the worked example.

In January 2025, a wave of press coverage described serious, large-scale intrusions into telecom carrier infrastructure, reportedly reaching calls, texts and one-time codes sent by SMS. This piece is not about litigating those specific claims – attribution in cases like this is disputed territory and not something worth restating as settled fact. It is about the two durable ideas the story is actually an example of.

What gets called new is usually just what became newsworthy

The threats that make headlines are almost never genuinely new. They are existing techniques that finally reached an impact, or a scale, large enough to be reported. A meaningful share of real cybersecurity preparedness is quieter than that: watching what security researchers are actually finding, rather than what reporters are covering, and then judging when a known-but-obscure threat crosses the line into something worth spending money to defend against. That judgment call can genuinely take years, sometimes longer, and getting the timing right is most of the work.

The part that has been true for a decade already

SMS-based and email-based multi-factor authentication have been understood as weak for well over a decade. That is not a new finding prompted by any particular news story – it is old enough that banks began issuing hardware security keys to business account holders roughly that long ago, and banks are institutions that spend money on security only when they are convinced they need to. If a financial institution you use still does not support a hardware key, that is worth flagging directly to them. If it does and you have not switched your account over yet, that is a five-minute task worth doing regardless of which headline prompted the thought.

Itwerx Corp is a service-disabled veteran-owned small business providing IT services across Seattle, Bellevue, Everett and Snohomish County. This is the kind of thing our cybersecurity work deals with – talk to us about yours.