Iran Used SS7 Vulnerability to Track US Military in Middle East

Key Points
- Iran abused SS7, a 2G and 3G network protocol, to track U.S. military at bases and hotels across the Middle East.
- The Iranian government also exploited mobile advertising technology as a surveillance tool against American forces.
- The Mobile Surveillance Monitor research documented the campaign that resulted in injuries from Iranian strikes.
Intelligence agencies have long abused SS7 to track cellphones abroad, making the technique well-established in the espionage toolkit. The vulnerability exists because SS7 lacks robust authentication mechanisms, allowing those with network access to request and intercept location data from carriers worldwide.
Iran's Multi-Layered Surveillance Approach
Read Next

Meta Reports Q2 Earnings Amid AI Investment Concerns
7 days ago

Nvidia Launches Cybersecurity Initiative for Open-Source AI Defense
8 days ago
Beyond SS7 exploitation, Iran also abused advertising technology used to serve tailored ads to cellphone users, another well-known surveillance method that relies on everyday commercial infrastructure. This dual approach—combining telecommunications protocol vulnerabilities with mobile advertising systems—gave Iranian operatives multiple pathways to track and identify U.S. military targets.
The campaign represents a sophisticated application of known vulnerabilities rather than the deployment of novel hacking techniques. SS7's structural weaknesses have been public knowledge for years, with researchers and security experts repeatedly warning that the protocol's age and design limitations make it inherently vulnerable to abuse by state actors with access to telecom networks.
Related coverage: Meta Reports Q2 Earnings Amid AI Investment Concerns
The Financial Times investigation relied on technical analysis from the Mobile Surveillance Monitor, which tracks such surveillance activities, combined with accounts from government officials familiar with Iranian operations. The reporting connects specific targeting methods to measurable military outcomes—the location intelligence directly enabled strikes against identified U.S. personnel.
This case mirrors previous instances where state actors exploited telecommunications infrastructure for military advantage. In 2013, for example, Edward Snowden's revelations showed that U.S. intelligence agencies used similar SS7 vulnerabilities to track foreign targets, demonstrating that this exploitation method crosses multiple national security operations.
The vulnerability of SS7 has long posed a dilemma for telecommunications regulators and security experts. Replacing the aging protocol globally would require massive investment and coordination among thousands of carriers worldwide, making the infrastructure remain exposed despite decades of known weaknesses. Many carriers continue operating 2G and 3G networks alongside newer infrastructure, perpetuating SS7's use and vulnerability.
The Iranian operation demonstrates how state actors can weaponize civilian telecommunications infrastructure without sophisticated zero-day exploits or advanced hacking capabilities. Standard network access combined with knowledge of SS7 protocols proved sufficient to conduct military targeting operations across multiple countries.
For civilians and military personnel traveling in regions where hostile states operate, the implications are direct. Attackers can locate mobile phones in real time using only the phone number, regardless of whether location services are disabled or encryption is enabled. The vulnerability operates at the network level, beneath the protections that users believe they have enabled on their devices.
The use of mobile advertising technology for surveillance adds another layer, as this infrastructure operates largely outside public visibility and regulatory oversight. Advertising networks collect and process location data as a core function, making them attractive targets for state surveillance without requiring specialized technical breaches.
Why This Matters
If you travel internationally for work or leisure, particularly to regions where you could be a target, understand that your phone's location can be tracked through your mobile carrier's fundamental infrastructure—not through app permissions or software exploits. The SS7 vulnerability cannot be patched on individual devices; it requires carriers to upgrade their core network architecture, something that remains incomplete in most countries. This gap between known risks and slow infrastructure upgrades means the surveillance method Iran used remains viable against any mobile user globally.
What This Means
The documented Iranian exploitation of SS7 will likely accelerate pressure on telecommunications regulators to mandate migration from legacy 2G and 3G networks, though carriers will resist given infrastructure costs. Other state actors will increasingly adopt similar techniques against military and civilian targets, making telecommunications protocol vulnerabilities a persistent national security concern for the next 5-10 years.
Sources: AP, Reuters, ESPN, Bloomberg, BBC and other international news outlets.
Disclaimer: This article is for informational purposes only. Content is based on publicly available news sources.
Tech Desk
The NewsOracle Tech Desk covers breaking technology news including AI, Apple, Google, Tesla, Meta, OpenAI and product launches.
Latest coverage: Cybersecurity


