Surveillance vendors caught abusing access to telcos to track people’s phone locations, researchers say

Surveillance vendors caught abusing access to telcos to track people’s phone locations, researchers say

Recent investigations by security experts have unveiled two distinct spying operations exploiting critical weaknesses in the global telecommunications infrastructure to monitor individuals' locations. The findings suggest these operations represent just a fraction of a more extensive issue involving surveillance vendors gaining unauthorized access to global mobile networks. On Thursday, Citizen Lab, a prominent digital rights organization with extensive experience in identifying surveillance abuses, released a detailed report on these two newly discovered campaigns. The surveillance vendors, not named by Citizen Lab, operated under the guise of legitimate cellular providers, leveraging their access to collect sensitive location data on targeted individuals. The report highlights ongoing abuses of known vulnerabilities in the technologies that form the backbone of global telecommunications. A major point of concern is the Signaling System 7 (SS7), a set of protocols integral to 2G and 3G networks. For years, experts have warned that SS7's lack of authentication and encryption allows for potential exploitation by governments and surveillance technology companies, enabling them to geolocate cell phone users. While the newer Diameter protocol was designed for 4G and 5G communications to address these security shortcomings, Citizen Lab's report indicates that it too remains susceptible to exploitation. This is primarily because not all cellular providers implement the necessary security measures effectively, sometimes allowing attackers to revert to using the outdated SS7 protocol. Both surveillance campaigns shared a commonality in that they exploited access through three specific telecommunications providers, which acted as entry points in the surveillance ecosystem. This access allowed the vendors and their government clients to operate under the radar, as explained in the report. The first of these providers, Israeli operator 019Mobile, was implicated in various surveillance attempts. Similarly, the British provider Tango Networks U.K. and Airtel Jersey, which is now owned by Sure, were also identified as part of this surveillance activity. In response to the allegations, Sure's CEO, Alistair Beak, asserted that their company does not knowingly lease access for tracking individuals and has implemented measures to prevent such misuse. 019Mobile and Tango Networks have yet to respond to inquiries regarding these claims. The Citizen Lab report suggests that the first surveillance vendor facilitated global spying campaigns lasting several years, leveraging the infrastructure of multiple cellular providers, hinting at substantial government backing. Researcher Gary Miller noted that there are indications of an Israeli-based commercial geo-intelligence provider potentially being behind these operations. However, he refrained from naming any specific surveillance vendor. The first campaign primarily relied on exploiting SS7 vulnerabilities, switching to Diameter when necessary, while the second campaign employed different tactics, including sending specialized SMS messages to a particular high-profile target. These messages were designed to communicate with the target’s SIM card without any visible alerts to the user, effectively turning the phone into a location tracking device. This method, termed SIMjacker, has been recognized as a common yet challenging-to-detect exploit. Miller emphasized that these two campaigns are merely a glimpse into a much larger landscape of surveillance attacks, stating, "We only focused on two surveillance campaigns in a universe of millions of attacks across the globe."

Sources : TechCrunch

Published On : Apr 23, 2026, 12:25

Startups
Revolutionizing Startup Living: Inside London's Unique Lift House

In East London, a group of six young entrepreneurs is redefining the concept of collaborative living for tech founders. ...

TechCrunch | Jul 26, 2026, 17:10
Revolutionizing Startup Living: Inside London's Unique Lift House
AI
Hugging Face CEO Calls for Action Following AI Security Breach

In a dramatic turn of events within the AI landscape, Hugging Face faced a significant security breach involving an AI a...

Business Insider | Jul 25, 2026, 20:30
Hugging Face CEO Calls for Action Following AI Security Breach
Startups
The Future of Work: Executives Weigh In on AI's Impact on Gen Z Careers

As generative artificial intelligence continues to rise, uncertainty looms for the incoming Gen Z workforce. Leaders fro...

Business Insider | Jul 26, 2026, 10:15
The Future of Work: Executives Weigh In on AI's Impact on Gen Z Careers
AI
Navigating the AI Landscape: Insights from a Former OpenAI Intern

As the demand for expertise in artificial intelligence surges, many are seeking ways to break into this dynamic field. H...

Business Insider | Jul 26, 2026, 10:10
Navigating the AI Landscape: Insights from a Former OpenAI Intern
AI
The Rise of AI Distillation: A Controversial Technique Sparks Debate in Tech and Government

In recent discussions, a once-obscure topic in artificial intelligence has surged to the forefront of debates among tech...

CNBC | Jul 25, 2026, 12:15
The Rise of AI Distillation: A Controversial Technique Sparks Debate in Tech and Government
View All News