A surveillance vendor was caught exploiting a new SS7 attack to track people’s phone locations

Surveillance Vendor Caught Using New SS7 Exploit to Track Phone Locations
Photo: TechCrunch

Surveillance Vendor Caught Using New SS7 Exploit to Track Phone Locations

A cybersecurity company, Enea, has discovered that a surveillance vendor in the Middle East has been exploiting a new attack to bypass security measures on mobile networks. This SS7-based attack allows the vendor to track phone locations by accessing data about which cell towers phones are connected to. Though it was observed only targeting a limited number of people, this technique could pinpoint someone’s location within hundreds of meters, especially in urban areas. The attack highlights vulnerabilities in the Signaling System 7 (SS7) protocols, which are used globally by telecom carriers to route calls and texts. Even with recent firewall improvements, some telecom networks remain susceptible to such attacks. Governments and private companies in various countries, including China, Russia, and Saudi Arabia, have previously exploited SS7 vulnerabilities for surveillance. The attack emphasizes the growing risk of privacy breaches due to poorly protected global telecom infrastructure, which leaves individuals vulnerable to surveillance without their knowledge. Enea has notified the affected carrier but has refrained from naming the vendor behind the exploit.

Leave a Reply

Your email address will not be published. Required fields are marked *