A surveillance vendor was caught exploiting a new SS7 attack to track people’s phone locations
ID: ff8f3e6a-1c96-5d20-b8ce-f4a7a0588c3e
STIX ID: report--ff8f3e6a-1c96-5d20-b8ce-f4a7a0588c3e
Feed Name: TechCrunch Security News
Security researchers observed a Middle East-based surveillance vendor exploiting a new SS7 bypass attack (since late 2024) to query carriers for subscribers' cell-tower locations without their knowledge; Enea reported the technique targeted a small number of subscribers and its success varied by carrier. The report highlights that while many carriers deploy SS7 firewalls and mitigations, the global patchwork of defenses leaves some subscribers vulnerable and mitigation responsibility rests primarily with telecom operators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
