Observed Signal · Apr 23, 2026 · Security Disclosure · Source: techcrunch · Impact: 3/5 · Sentiment: Negative
Surveillance Vendors Abused Telco Access to Track Phones
Citizen Lab published a report detailing two separate spying campaigns that abused weaknesses in global telecom signaling to geolocate individuals. The campaigns used vulnerabilities in SS7 and, where available, Diameter, and in one case used SIM-targeted messages (SIMjacker-style) to turn a target’s phone into a tracking device. Researchers say the surveillance vendors operated as “ghost” companies that piggybacked on three telecom providers — 019Mobile, Tango Networks U.K., and Airtel Jersey (now owned by Sure) — which acted as entry and transit points. Targets included ‘high-profile’ individuals. Citizen Lab did not name the vendors; researchers said clues point toward an Israeli-based geo-intelligence provider profile but provided no definitive attribution. Sure issued a statement denying knowingly leasing signalling access for tracking. TechCrunch updated the story to include 019Mobile’s responses to Citizen Lab.
The report exposes systemic weaknesses in global telecom signaling and active misuse of operator access to geolocate individuals. While not a major platform policy change, the findings have material implications for privacy, telco security practices, and any industry (including advertising) that relies on location signals.
Track Real-Time Privacy Signals & Market Shifts
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- Citizen Lab published a report describing two espionage campaigns that exploited telecom signaling to locate phones.
- The campaigns leveraged known vulnerabilities in SS7 and fallback/exploitation of Diameter when protections were absent.
- Three telecom providers identified as abused infrastructure were 019Mobile, Tango Networks U.K., and Airtel Jersey (owned by Sure).
- One campaign used SIM-targeted SMS commands (SIMjacker-style) that communicate with a device’s SIM card without user visibility to obtain location data.
- Sure publicly stated it does not knowingly lease signaling access for locating or intercepting individuals and described mitigation steps; 019Mobile said it “cannot confirm” that the identified infrastructure belongs to the company.
Ontology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Iran Exploited SS7 and Ad Tech to Locate U.S. Forces
A TechCrunch report says the Iranian government exploited known vulnerabilities in global telecom infrastructure—notably Signaling System 7 (SS7)—to locate U.S. military personnel in the run-up to and early stages of the Iran War. Research cited by the Financial Times and attributed to the Mobile Surveillance Monitor and anonymous officials found Iran used SS7-based tracking to identify U.S. forces at military bases and hotels in Iraq, Bahrain and other Middle East locations. The campaign also reportedly leveraged advertising technology that delivers tailored mobile ads as a surveillance vector. Attacks enabled by these location techniques led to strikes that caused multiple injuries.
Salt Typhoon: Global Espionage Campaign Targets Telecom Giants
Security researchers and U.S. officials attribute a broad espionage campaign to a China-linked hacking group known as Salt Typhoon. The group has targeted telecom and internet providers worldwide, exploiting Cisco routers at network edges and compromising surveillance devices that enable lawful intercept. Researchers and the FBI say Salt Typhoon has hacked at least 200 companies and stolen tens of millions of phone records, including call records, texts and captured phone audio from senior U.S. officials. Confirmed U.S. victims include AT&T, Verizon, CenturyLink (now Lumen), Viasat, Charter Communications (Spectrum), Windstream and Consolidated Communications; T-Mobile reported it was targeted but said customer communications were not accessed. Security firms Recorded Future and Trend Micro have observed activity across the Americas, Europe, Asia, Africa and Oceania, and the FBI urged U.S. users to adopt end-to-end encrypted messaging.
BR exposes data leak in German mobile networks
A Bayerischer Rundfunk (BR) investigation found that during call setup German mobile networks transmitted technical smartphone data to the caller side. In tests, networks operated by Telekom, Vodafone and Telefónica forwarded identifiers and device information—including IMEI, device model and sometimes OS version—before the called party answered. Regulators and security agencies said these fields are unnecessary for call setup and create risks for fingerprinting-based targeted attacks. Netzbetreiber reported technical adjustments: Telefónica implemented changes, Vodafone limited transmitted information and Deutsche Telekom announced network adjustments. The GSMA informed its global membership and recommended removing unnecessary signalling data to enforce data minimisation in modern IP-based telephony stacks.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
