Surveillance vendors caught abusing access to telcos to track people’s phone locations, researchers say

Surveillance vendors are systematically exploiting critical vulnerabilities in global telecommunications infrastructure (SS7 and Diameter protocols) by posing as legitimate cellular providers to track individuals' phone locations, with evidence pointing to widespread, well-funded operations involving at least three telecom providers acting as entry points. This represents a significant cybersecurity and compliance risk for organizations, as it demonstrates that telecom partners may unwittingly become conduits for unauthorized location tracking and surveillance, potentially exposing enterprise users and customers to state-sponsored or commercial tracking. IT leaders must reassess their telecom vendor security posture and implement stricter access controls and monitoring protocols, as traditional telecom infrastructure security cannot be taken for granted in the current threat landscape.

TechCrunch2 min read
Read full article
Surveillance vendors caught abusing access to telcos to track people’s phone locations, researchers say
The Citizen Lab found two separate surveillance vendors abusing the backbone of cellular networks to spy on several victims across the world.