Surveillance Firm Uncovered for Exploiting New SS7 Vulnerability to Track Mobile Locations
Security professionals have uncovered that a surveillance company operating in the Middle East is using a new attack technique that tricks phone carriers into disclosing the locations of mobile users.
This technique exploits weaknesses in the security protocols that telecom companies have established to prevent unauthorized access to SS7, or Signaling System 7. SS7 is a private suite of protocols used by telecom operators globally to manage voice calls and text messaging for their subscribers.
Moreover, SS7 allows carriers to gather information on which cell tower a subscriber’s phone is connecting to, a function frequently employed for accurate billing on international communications.
Enea, a cybersecurity firm dedicated to protecting telecom carriers, disclosed this week that they have detected the unidentified surveillance firm employing this new bypass technique since late 2024 to track mobile users’ locations without their consent.
Cathal Mc Daid, Enea’s VP of Technology and co-author of the blog post, informed TechCrunch that the surveillance company was found targeting “only a few subscribers” and that the method was not universally effective across all telecom carriers.
Mc Daid explained that the bypass attack allows the surveillance firm to locate an individual down to the closest cell tower, narrowing it to within a few hundred meters in urban or densely populated areas.
Enea informed the telecom provider where the vulnerability was detected but did not disclose the identity of the surveillance firm, only noting its location in the Middle East.
Mc Daid cautioned TechCrunch that this attack is indicative of a rising trend of malicious operators using such techniques to locate individuals, adding that the companies behind these tactics “would not be employing them if they weren’t effective somewhere.”
“We anticipate that more such techniques will be discovered and implemented,” Mc Daid stated.
Surveillance firms, typically encompassing spyware developers and bulk internet traffic providers, are private organizations that often operate solely for government clients to conduct intelligence-gathering operations. Though governments maintain that spyware and similar technologies are intended for targeting serious criminal activity, these tools have frequently been misused against members of civil society, including journalists and activists.
Historically, surveillance firms have acquired access to SS7 through local carriers, misappropriated leased “global titles,” or via governmental ties.
Nonetheless, the nature of these attacks at the cellular network level leaves subscribers with limited means for self-protection. The onus of safeguarding against these threats primarily falls on telecom companies.
Recently, telecom providers have introduced firewalls and other cybersecurity measures to defend against SS7 attacks. Regrettably, inconsistent security protocols across the global cellular network mean not all carriers, including those in the United States, are equally fortified.
A letter sent to Senator Ron Wyden’s office last year revealed that the U.S. Department of Homeland Security previously indicated, as early as 2017, that several nations, notably China, Iran, Israel, and Russia, have exploited vulnerabilities in SS7 to “exploit U.S. subscribers.” Additionally, Saudi Arabia has been implicated in abusing SS7 weaknesses to surveil its citizens living in the United States.


