Iranian state actors exploited well-known vulnerabilities in the global telecommunications infrastructure—specifically the Signaling System 7 (SS7) protocol suite—to locate and target U.S. military personnel stationed in the Middle East during the build-up to and early stages of the Iran War, according to research by the Mobile Surveillance Monitor and unnamed government officials familiar with the operation. The campaign, which resulted in multiple injuries, represents a significant escalation in the use of legacy telecom flaws for battlefield intelligence and direct kinetic action.
SS7 Exploitation and the Tracking of US Military Personnel
At the core of this operation was the abuse of SS7, a set of protocols originally designed in the 1970s to allow 2G and 3G cellular networks to communicate and route calls and text messages globally. This infrastructure, while foundational for international roaming, contains fundamental security flaws, primarily a lack of authentication or authorization checks for location queries. Intelligence agencies and surveillance vendors have long abused these weaknesses to track the physical location of mobile phones globally.
The Iranian government reportedly leveraged this exact blind spot to geolocate U.S. military personnel. The tracking was not limited to personnel on military bases; it extended to individuals staying in hotels in Iraq, Bahrain, and other nations across the Middle East. By identifying the location of a specific handset, Iranian forces were able to coordinate strikes against these positions. These attacks, as reported by Reuters, resulted in numerous injuries among U.S. troops.
Ad Tech: A Secondary Vector for Surveillance
In addition to exploiting SS7, the campaign incorporated the abuse of advertising technology (ad tech). This technique, which is also a well-documented method for civilian surveillance, involves using mobile advertising identifiers and real-time bidding data to infer a user’s location. The combination of telecom infrastructure flaws and commercial data pipelines allowed for a multi-layered surveillance effort, demonstrating the operational maturity of Iranian cyber capabilities in the region.
Why SS7 Remains a Persistent Military Threat
The SS7 protocol was developed at a time when network trust was assumed, and its core functions were not built with modern security requirements in mind. Despite the global transition to 4G and 5G networks, SS7 and its successor, Diameter, remain critical for interoperability and roaming. Patching these vulnerabilities is extraordinarily difficult, as they are intrinsic to the protocol’s design rather than a simple software bug that can be updated. This makes SS7 a persistent and attractive vector for state-level attackers seeking to track high-value targets.
For military and government personnel, this incident underscores a critical operational security risk. Any mobile phone connected to a cellular network in a region with compromised or untrusted infrastructure can be located. The failure of the telecom industry and regulatory bodies to enforce robust security measures on signaling networks has created a battlefield advantage for adversaries.
Broader Implications for Digital Privacy and National Security
This event is a stark demonstration of how foundational flaws in civilian technology can be weaponized in modern conflict. It is not a zero-day exploit or a sophisticated piece of malware; it is the use of a known, decades-old vulnerability in a strategic manner. For citizens in the US, UK, Australia, and Canada, the security of mobile networks is not merely a matter of personal privacy but a component of national security. The same techniques used to track a soldier in the Middle East could theoretically be redeployed to monitor diplomats, journalists, or defense contractors in foreign countries.
What This Means for Mobile Security Standards
The exploitation of SS7 for military targeting amplifies long-standing calls for the retirement of legacy signaling protocols and for the urgent implementation of security gaps such as the SS7 Filtering guidelines developed by the GSMA. Until carriers globally enforce strict filtering and access controls on their signaling networks, these types of attacks will remain feasible. For individual users, the threat is asymmetric: there is no client-side software that can fully protect a phone from SS7 location tracking, as the attack operates on the network level, not on the device.
How to Protect Against SS7-Based Tracking
What is SS7 tracking and how does it work? It is a method by which an attacker sends a location request to a mobile network using the SS7 protocol, which the trusting network answers by providing the cell tower and sector the phone is currently connected to. Protecting against this is complex for the average user.
Recommendations for High-Risk Individuals
- Use end-to-end encrypted communication apps: While they do not prevent location tracking, apps like Signal and WhatsApp prevent the interception of call and message content, which is another known SS7 vulnerability.
- Utilize a reputable no-log VPN service: Using a VPN with a kill switch and AES-256 encryption can help obscure IP addresses and some network-level data, though it does not stop SS7 location queries.
- Disable cellular data and use Wi-Fi only: When possible, putting a device in airplane mode and relying on secure Wi-Fi severs the connection to the cellular network, making SS7 tracking impossible.
- For organizations: Deploy a multi-layer endpoint protection solution and implement mobile threat defense (MTD) systems that can detect suspicious network activity indicators on a device level.
What Affected Users and IT Security Teams Should Do Now
While this campaign specifically targeted U.S. military personnel, the methodology is applicable to any mobile user. For IT security teams managing overseas personnel, the immediate action is to assess the use of personal mobile devices in high-threat environments and implement strict operational security protocols. For individual users traveling internationally to high-risk regions, using a burner phone with limited data functionality or leaving smartphones at secure locations remains the most reliable mitigation. The most critical takeaway is the need for regulatory pressure on telecom carriers to finally secure the signaling networks that underpin global mobile communications.