Threats · 144 days ago
The weak point is not the phone. It is the trust between carriers. Surveillance vendors can pose as legitimate cellular providers, then use interconnect access to query location data across global networks. Standard defenses that focus on device security miss this operator-level abuse path.
Citizen Lab says it found two separate campaigns using fake “ghost” carriers and telecom signaling flaws to track victims worldwide. The report points to SS7, and to Diameter where protections are not fully deployed, with some cases falling back to SS7. The abuse ran through access to three telecom providers that repeatedly acted as the surveillance gateway.
The risk is persistent because the same signaling trust model still underpins global roaming and location lookups. As long as carriers accept weakly authenticated interconnect requests, location tracking remains available to operators that can buy or fake network access.
3 sources covering this story
Citizen Lab reveals how surveillance vendors exploit mobile network signaling protocols like SS7 and Diameter to track targets, highlighting severe global telecom risks.
The Record from Recorded Future
Surveillance companies exploiting telecom system to spy on targets’ locations, research shows
The campaigns exploited a weakness in telecom infrastructure to allow the unnamed vendors to secretly pose as real cellular providers and pinpoint victims’ locations.
The Citizen Lab found two separate surveillance vendors abusing the backbone of cellular networks to spy on several victims across the world.
Part of the PlainSec briefing for 2026-04-23