AIO APEX

Iran-linked actors tracked US personnel via decades-old SS7 telecom flaw, FT investigation finds

Financial Times (via Roya News)
Share:
Iran-linked actors tracked US personnel via decades-old SS7 telecom flaw, FT investigation finds

A Financial Times investigation has found that actors linked to Iran tracked the locations of US personnel and contractors in the Middle East during recent hostilities by exploiting two long-known but still-unresolved weaknesses in global telecom infrastructure: the SS7 signaling protocol and commercially available mobile advertising data. The reporting draws on data from the Mobile Surveillance Monitor research project and comes as US lawmakers have separately raised concerns about roaming-system and adtech vulnerabilities.

How the tracking reportedly worked

SS7, or Signaling System No. 7, is the decades-old protocol telecom carriers use to route calls and texts between networks, including determining a phone's approximate location when it roams outside its home network. Security researchers have warned for over a decade that SS7 lacks robust authentication, letting an operator with network access send location-query "pings" to a target's carrier and receive back an approximate position — without the target's knowledge or any exploit running on the phone itself. According to the FT's reporting, Middle Eastern telecom networks recorded and blocked repeated SS7 ping requests during the relevant period, evidence that someone was actively probing for location data on specific numbers.

Separately, actors linked to Iran are reported to have used commercially available advertising databases — the same real-time-bidding data exchanges that power targeted mobile ads — to track phones in northern Iraq's semi-autonomous Kurdistan region. This is a distinct technique from SS7 exploitation: adtech location data is generated when apps share device location with ad networks for bidding purposes, and that data has repeatedly been shown to be purchasable or accessible to parties well outside its intended advertising use.

Why this combination matters

Gary Miller, a senior research fellow at Citizen Lab who was quoted in the investigation, said Iran "absolutely has capabilities to get real-time, immediate and continuous location information," adding that it would be surprising if Iran were not using SS7 or other mobile network access across the region to track US-linked users. The Gulf officials cited in the reporting suspected the roaming-agreement exploitation specifically, pointing to how thoroughly integrated commercial telecom infrastructure is with state surveillance capability once an actor gains any level of network access.

A known, unfixed problem

SS7's vulnerabilities are not new — security researchers have demonstrated SS7-based location tracking and call interception publicly since at least 2014, and Citizen Lab has published extensive research cataloguing telecom exploitation by state and commercial surveillance vendors, including a broader report titled "Bad Connection: Uncovering Global Telecom Exploitation by Covert Surveillance Actors." The protocol remains in global use because replacing it across every interconnected carrier worldwide is a massive coordination problem that the industry has never fully solved, even as intelligence agencies, commercial spyware vendors, and now apparently state-linked actors in active conflicts continue to exploit it.

Neither the US government nor Gulf telecom regulators have issued a public confirmation or response to the FT's findings as of publication. The episode adds to a growing body of evidence that legacy telecom signaling protocols and unregulated advertising data markets represent parallel, largely unaddressed surveillance risks — one rooted in 1970s-era network architecture, the other in the modern mobile advertising economy, as reported by the Financial Times.

Originally reported by Financial Times (via Roya News). Read the original article for additional details.

View original source
Share: