Surveillance firms can track phones without hacking them by posing as carriers. Researchers at Citizen Lab uncovered two campaigns that exploited weaknesses in global telecom signaling to query subscribers' locations via SS7 and Diameter, using at least three telecoms — including Israeli operator 019Mobile and UK-based Tango Networks U.K. — as entry or transit points.
How vendors disguised as carriers gained footholds
Citizen Lab identified two separate campaigns in which surveillance firms operated as so-called "ghost" carriers, obtaining legitimate access to the global signaling fabric that connects mobile networks. Once they had that access, the firms piggybacked on routing and signaling privileges to query location information for targeted subscribers.
Those ghost operators didn't need to compromise end-user devices or intercept internet traffic. They used the same interconnection channels that carriers rely on every day to hand off calls, messages and roaming services. That access gives them a direct way to ask other networks where a phone is registered and which cell tower it's attached to.
According to Citizen Lab, the vendors exploited long-standing security gaps in the signaling protocols that let networks communicate. Those flaws let malicious or poorly screened actors make location requests and move them through third-party carriers so the original source is hard to spot.
SS7 flaws remain a primary vector
Signaling System 7, or SS7, was built decades ago to let networks route calls and messages between providers worldwide.
The protocol assumed that all actors on the SS7 network were trusted, so it lacks strong authentication and encryption.
That trust model is why SS7 has repeatedly been used to track phones. With a few messages, an operator on SS7 can locate a subscriber by asking other networks where that handset is currently registered. Citizen Lab's report makes clear attackers still use SS7 when they can, especially against carriers or roaming links that haven't added newer protections.
Because SS7 links are global, a rogue operator in one country can query a target on another carrier far away. The lookup requests travel through intermediaries. Those intermediaries can be legitimate carriers that, intentionally or not, provide the entry and transit points the vendors need.
Diameter promised fixes—yet gaps persist
Diameter was designed for 4G and 5G networks to replace SS7 and add built-in security features. In theory, it limits who can make sensitive queries and supports encryption for signaling traffic. But Citizen Lab's findings show Diameter isn't a silver bullet.
Some carriers haven't fully implemented Diameter's protections. Others run legacy interconnections that allow attackers to fall back to SS7 or to exploit weak Diameter configurations. That means a surveillance vendor with the right network links can still reach into roaming and interconnect paths to pull location data.
In the campaigns described, Citizen Lab found operators that repeatedly acted as the surveillance entry and transit points within the telecommunications ecosystem. That pattern points less to a single technical exploit and more to a business and governance failure: the networks that accept, route and authenticate inter-carrier traffic sometimes don't have strict controls over who can join their routing fabric.
Named carriers and the scale of access
The report names at least two carriers that were used in these operations. One is Israeli operator 019Mobile; the other is Tango Networks U.K. Citizen Lab says those providers were implicated in multiple surveillance attempts and that three specific telecoms served repeatedly as infrastructure hosts for the activity.
Citizen Lab didn't publicly name the surveillance vendors.
Related Articles
- Advocates Demand Google Stop Sharing Data With ICE
- Developers Are Running AI Locally. CISOs Didn't See This Coming.
- Amazon Music Adds Bandsintown Concert Listings
Citizen Lab says the campaigns used three transit or entry carriers and specifically named Israeli operator 019Mobile and UK-based Tango Networks U.K. as repeatedly implicated.
This article was created with AI assistance.