A surveillance vendor was caught exploiting a new SS7 attack to track people's phone locations:
Security researchers say they have caught a surveillance company in the Middle East exploiting a new attack capable of tricking phone operators into disclosing a cell subscriber's location.
The attack relies on bypassing security protections that carriers have put in place to protect intruders from accessing SS7, or Signaling System 7, a private set of protocols used by the global phone carriers to route subscribers' calls and text messages around the world.
SS7 also allows the carriers to request information about which cell tower a subscriber's phone is connected to, typically used for accurately billing customers when they call or text someone from overseas, for example.
Researchers at Enea, a cybersecurity company that provides protections for phone carriers, said this week that they have observed the unnamed surveillance vendor exploiting the new bypass attack as far back as late 2024 to obtain the locations of people's phones without their knowledge.
Enea VP of Technology Cathal Mc Daid, who co-authored the blog post, told TechCrunch that the company observed the surveillance vendor target "just a few subscribers" and that the attack did not work against all phone carriers.
Mc Daid said that the bypass attack allows the surveillance vendor to locate an individual to the nearest cell tower, which in urban or densely populated areas could be narrowed to a few hundred meters.
[...] Surveillance vendors, which can include spyware makers and providers of bulk internet traffic, are private companies that typically work exclusively for government customers to conduct intelligence-gathering operations against individuals. Governments often claim to use spyware and other exploitative technologies against serious criminals, but the tools have also been used to target members of civil society, including journalists and activists.
In the past, surveillance vendors have gained access to SS7 by way of a local phone operator, a misused leased "global title," or through a government connection.
But due to the nature of these attacks happening at the cell network level, there is little that phone subscribers can do to defend against exploitation. Rather, defending against these attacks rests largely on the telecom companies.
Related Stories
Privacy is prerequisite for free thought, dissent, experimentation, and innovation, which are in turn prerequisites for democracy. At NBTV, Naomi Brockwell has posted four reasons why limits on privacy are absolutely not a price worth paying for mainstream adoption.
Today I participated in a Privacy Salon in Denver where we debated a proposition that cuts to the core of the modern privacy movement:
"Limits on privacy are a price worth paying for mainstream adoption of cryptographic privacy."
I was on the "no" side alongside Matt Green, with Evin McMullen and Wei Dai arguing "yes."
It was a lively, thoughtful exchange that forced us to confront a deeper question: is weakening privacy simply the cost of scale?
Below is my opening statement from the debate.
The false argument about having nothing to hide does not hold water. As Ed Snowden observed years ago, "arguing that you don't care about the right to privacy because you have nothing to hide is no different than saying you don't care about free speech because you have nothing to say."
Previously:
(2026) Ring Cancels Flock Deal After Dystopian Super Bowl Ad Prompts Mass Outrage
(2026) Discord Will Require a Face Scan or ID for Full Access Next Month
(2026) "ICE Out of Our Faces Act" Would Ban ICE and CBP Use of Facial Recognition
(2025) Big Tech Wants Direct Access to Our Brains
(2025) Discord Customer Service Data Breached; Government-ID Images, and User Details Stolen
(2025) A Surveillance Vendor Was Caught Exploiting a New SS7 Attack to Track People's Phone Locations
... and many more
(Score: 1, Touché) by Anonymous Coward on Thursday July 24 2025, @07:06PM (1 child)
Without a name the story is bullshit clickbait
(Score: 0) by Anonymous Coward on Sunday July 27 2025, @02:46AM
Plus it doesn't matter that much in the big picture - the Gov/crooks can already get the location AND other info from the telcos directly.
Maybe only helps those "higher profile targets" who are getting targeted by the Mossad or similar?
Lots of telcos leak subscriber info like a sieve. Just google for telco data breach...