Surveillance vendors caught abusing access to telcos to track people's phone locations, researchers say

The Citizen Lab found two separate surveillance vendors abusing the backbone of cellular networks to spy on several victims across the world.

Surveillance vendors caught abusing access to telcos to track people's phone locations, researchers say

TL;DR

  • Two separate spying campaigns have been uncovered, abusing weaknesses in global telecoms infrastructure to track people's locations.
  • Surveillance vendors operated as "ghost" companies, pretending to be legitimate cellular providers to access networks.
  • The campaigns exploited vulnerabilities in Signaling System 7 (SS7) and Diameter protocols.
  • One campaign used Israeli operator 019Mobile, British provider Tango Networks U.K., and Airtel Jersey (owned by Sure) as entry points.
  • The second campaign used a special SMS message to turn a target's phone into a location tracking device, a known SIMjacker attack.
  • Researchers believe these two campaigns represent a small fraction of widespread exploitation of cellular networks for surveillance.