logo

A surveillance vendor was caught exploiting a new SS7 attack to track people’s phone locations

ID: ff8f3e6a-1c96-5d20-b8ce-f4a7a0588c3e

STIX ID: report--ff8f3e6a-1c96-5d20-b8ce-f4a7a0588c3e

Feed Name: TechCrunch Security News

Threat Score
70/100

Date Published: 2025-07-18

Date Updated: 2026-04-23

Author: Zack Whittaker

...
...

Security researchers observed a Middle East-based surveillance vendor exploiting a new SS7 bypass attack (since late 2024) to query carriers for subscribers' cell-tower locations without their knowledge; Enea reported the technique targeted a small number of subscribers and its success varied by carrier. The report highlights that while many carriers deploy SS7 firewalls and mitigations, the global patchwork of defenses leaves some subscribers vulnerable and mitigation responsibility rests primarily with telecom operators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.