Two sophisticated telecom surveillance campaigns exposed by investigation
Key point
Citizen Lab identified 2 surveillance campaigns exploiting SS7, Diameter, and SIMjacker.
Details
Citizen Lab identified 2 distinct surveillance campaigns that exploited well-known vulnerabilities in global telecom networks to track mobile phone location data.
These vendors secured network access in the form of shell companies disguised as legitimate mobile carriers, then used SS7 and Diameter to track targets.
The commonly exploited relays were 019Mobile, Tango Networks U.K., and Airtel Jersey, and it was found that surveillance vendors and government clients operated hidden behind carrier infrastructure.
- The first campaign first attempted SS7 attacks, and switched to Diameter if they failed.
- The second campaign communicated directly with SIM cards using special SMS that leaves almost no trace, effectively turning mobile phones into location tracking devices.
- Researchers observed thousands of cases of this type of attack over several years, and estimated that the scale of abuse worldwide could reach millions of cases.
The report shows that the telecom industry has failed to adequately block the structural vulnerabilities in SS7 and Diameter, which continue to be exploited as tracking tools by surveillance vendors and their government clients.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.