Surveillance vendors caught abusing access to telcos to track people's locations
Security researchers have exposed widespread abuse of telecom infrastructure vulnerabilities by surveillance vendors who exploit outdated protocols (SS7 and Diameter) to track individuals' locations globally, with evidence pointing to coordinated campaigns involving compromised cellular providers as entry points. This represents a critical infrastructure security gap that extends beyond traditional IT boundaries, requiring CIOs to reassess their organization's exposure to telecom-dependent services and potential location data vulnerabilities. The findings highlight that enterprises relying on cellular networks for operations or employee tracking face significant risks from both nation-state actors and commercial surveillance vendors abusing legitimate telecom access.
