Flat vector diagram of Salt Typhoon SS7 signaling abuse spreading trusted messages across telecom carrier interconnects

Iran is targeting U.S. military personnel through their smartphones, according to reporting first published by The Financial Times earlier this month. The method is not new: the SS7 signaling attacks involved have been publicly documented for decades, and members of Congress from both parties have raised the issue repeatedly. (Source: Defensescoop)

Signaling is the machine-to-machine traffic carriers use to confirm you pay your bill, verify your location, and route your calls, texts, and web traffic. It runs in the background, invisible to the person holding the phone, and it has connected global carriers for decades as a closed system meant for telecoms only.

That closed-system assumption no longer holds. The protocols were designed when a small number of large carriers were the only participants; today thousands of entities have access, and the protocols still treat any signaling message from any of them as legitimate.

That access allows real-time location tracking, interception of calls and texts, use of fake phone numbers, and denial of service.

Key Insight: An attacker who reaches the global signaling backbone — through a commercial lease or a compromised operator — can send messages that carriers worldwide accept as trustworthy.

The part that matters operationally: none of this requires malware on the device, a phishing link, or any user error. There is no trace left on the handset, so a compromised phone looks and behaves normally to its owner and to your device management tooling.

In 2024, an official at the Cybersecurity and Infrastructure Security Agency reported that "numerous" successful attempts have stolen location data, monitored voice and text messages, delivered spyware, and influenced American voters from abroad via text messages.

The consequences are already documented in Ukraine, where both Ukrainian and Russian soldiers have been killed after their cell phones revealed their positions. Ukraine also flew drones deep inside Russia over Russia's own cellular networks, destroying billions of dollars of military aircraft.

State actors including Iran, Russia, and China treat commercial cellular as attack surface because it is everywhere, reliable, and used by people who have no practical alternative.

Attack Chain: How Salt Typhoon and State Actors Compromise Telecom Networks

The starting point for a signaling attack is access, and that access is often purchased rather than stolen. An operator can lease connectivity to the global signaling backbone, or an attacker can ride in on a compromised carrier — either way, the messages they send arrive with the same trust level as traffic from a national telecom.

That trust is the whole attack. Thousands of entities now touch a system built when only a handful of large carriers could join it, and the protocols still accept signaling messages from any of them as legitimate. There is no authentication step to bypass and no vulnerability to exploit in the classic sense.

From that position, the operational progression is straightforward:

  • Location queries against the target's subscriber records, repeated to produce real-time tracking rather than a single fix (MITRE ATT&CK mobile technique T1450, Exploit SS7 to Track Device Location).
  • Call and SMS redirection, which places the attacker in the path of voice and text traffic (T1449, Exploit SS7 to Redirect Phone Calls/SMS).
  • Caller ID and originating number spoofing, letting messages appear to come from trusted numbers.
  • Spyware delivery through that trusted channel, and denial of service against a specific handset when the goal is to cut a person off rather than listen to them.

The analytic payoff is pattern-of-life data. Repeated location queries over days build a baseline of where a person sleeps, works, and travels, and the valuable signal is the deviation from that baseline — a sudden move, a cluster of devices converging on one location, a phone that goes quiet. Applied to a deployed service member, that is targeting information; applied to a corporate executive, it is advance notice of an acquisition meeting or a site visit.

What separates this from commodity attacks is the absence of anything to find on the device. There is no malicious app, no phishing link clicked, no implant writing to storage, and no process for endpoint tooling to flag. Location tracking and message interception happen inside carrier infrastructure the subscriber does not control and cannot inspect, so the usual investigative starting point — pull the phone, image it, look for artifacts — returns nothing.

Interception of SMS also has a direct bearing on enterprise authentication. If an attacker sits in the delivery path for text messages, one-time passcodes sent by SMS arrive at the adversary's chosen endpoint, and the account takeover that follows looks like a normal login with a valid second factor in your authentication logs.

The operator-compromise path is the one with named precedent. The Chinese government's Salt Typhoon intrusions into major U.S. telecoms show what happens when the attacker owns positions inside carrier networks themselves rather than renting access at the edge — the same signaling capabilities, plus whatever the carrier's internal systems hold. Every major U.S. carrier has suffered breach after breach, which means the pool of potentially compromised operators feeding trusted signaling messages is not small.

Cellular infrastructure also serves as attack infrastructure in its own right. Ukraine piloted drones deep inside Russia over Russia's own cellular networks, destroying billions of dollars of military aircraft — the network became the command-and-control link for the strike. Russia could not turn its network off in response, and that constraint applies to any organization whose operations depend on commercial cellular coverage.

A 2024 statement from a Cybersecurity and Infrastructure Security Agency official described "numerous" successful attempts that stole location data, monitored voice and text messages, delivered spyware, and pushed influence messaging to American voters from abroad. Those four outcomes come from the same access, which is why treating signaling abuse as a niche telecom problem understates its reach.

Operational and National Security Impact for Telecom Providers and Government Agencies

The consequences of signaling compromise show up in casualty reports, not just breach notifications. The war in Ukraine has produced repeated cases of both Ukrainian and Russian soldiers killed after their cell phones revealed their location, and Ukraine flew drones deep into Russia using Russia's own cellular networks to destroy billions of dollars of military aircraft.

That is the operational ceiling for this class of attack: location data converted into targeting data. For a deployed unit, the exposure is not a single position fix but pattern-of-life analysis — daily routines and, more importantly, deviations from them that signal an operation is about to begin.

If you run a carrier network, the collection happening across your signaling interconnects is not something your customers can opt out of. A subscriber who disables location sharing and turns on lockdown mode still has to register with your network to place a call, which means your interconnect posture, not their settings, determines whether they can be tracked.

Read that list as four separate liability categories rather than one. Location theft and message interception expose you to subscriber litigation and law enforcement inquiry. Spyware delivery through your infrastructure makes your network the distribution channel for someone else's implant. Foreign-origin political messaging pulls you into election integrity scrutiny you have no commercial interest in.

The accountability picture is changing more slowly than the threat. All major U.S. carriers have suffered breach after breach while facing no real consequences, and when Sens. Ron Wyden and Eric Schmitt asked the government to obtain carriers' cybersecurity audits after the Chinese government's telecom intrusions, the carriers refused.

That refusal is now the reference point for every future oversight fight. If you are a carrier executive, the practical risk is that the next congressional request arrives with statutory teeth attached, and your answer becomes evidence rather than a negotiating position.

For government and military buyers, the constraint is procurement structure rather than technology. The Pentagon locks in cellular service through Spiral 4, a blanket ten-year contract last renewed in 2024, which means the next opportunity to move to a more secure cellular arrangement arrives in 2034.

If your organization holds a similar long-cycle telecom contract, the same logic applies to you. Technologies that address signaling exposure may reach the market well before your contract permits you to buy them, and the gap between the two is measured in years.

The exposure also reaches leadership communications, not only tactical ones. Senior U.S. officials with dedicated teams for classified equipment have gotten in trouble using personal smartphones for sensitive discussion, which tells you that convenience wins even where secure alternatives are fully funded and physically present.

Three consequences follow for planning purposes:

  • Communications security cannot be delegated to users, because the vulnerability requires no spyware, phishing link, or user error to exploit.
  • Operational capability degrades quietly, since interception and location tracking leave no trace on the target device.
  • Strategic advantage transfers to whoever holds signaling access, whether that access came from a commercial lease or a compromised operator.

Adversaries including Iran, Russia, and China all operate in this space, and the underlying weakness has been documented for decades.

Detection and Response for Compromised Telecom Networks

The most useful move you can make is to stop treating SMS and voice calls as a trusted delivery channel for anything. Signaling attacks intercept texts and calls without touching the handset, so any account whose second factor or password reset arrives by text is protected by a channel the attacker already controls. Move those accounts to hardware security keys or an authenticator app with number matching, starting with email, VPN, remote access, and any administrator account.

Because there is nothing to find on the device, your detection has to sit at the identity layer and at the carrier boundary. Hunt for these patterns in your authentication and telecom records:

  • Successful logins where the one-time code was delivered to a number belonging to a traveling or deployed employee, but the session originated somewhere else entirely.
  • Calls and texts that recipients say they never received, or that arrived twice — consistent with redirection through a third party.
  • Unexplained loss of service on a specific handset, which is one of the outcomes signaling access permits.
  • Account recovery attempts that fall back to phone-number verification, especially for executives and staff with published numbers.
  • SIM swap, port-out, or number-reassignment requests you did not authorize.

In environments Capstone manages, Adlumin ITDR correlates these authentication anomalies across accounts, so a code-delivery pattern that looks unremarkable on one login stands out when the same number shows repeated location-inconsistent sessions. That matters commercially because the credentials still work and the logins still look valid — nothing in the event log says "compromised" until you compare behavior across time.

For containment, work the phone number as if it were a leaked credential. Revoke active sessions on any account that used SMS verification during the suspect window, rotate those passwords, and strip phone-number recovery from the account entirely rather than just adding a second factor on top of it. Place a port freeze and a carrier account PIN on every corporate line, and restrict which named individuals can authorize a SIM or plan change with your carrier.

For staff who travel to or operate in high-risk regions, separate the number used for authentication from the number that appears in directories, signature blocks, and public filings. Interception of a widely known number is far cheaper for an adversary than discovering an unpublished one.

Longer term, push the requirements into your carrier contracts, because the source of this problem is commercial rather than technical. Ask your provider in writing for its published security audits, its signaling firewall reporting, and evidence of annual penetration testing — the same three items Congress and regulators have been urged to demand of major carriers. Ask specifically how the provider vets and monitors third parties that lease access to its signaling connectivity, and what triggers termination of those agreements.

The procurement lesson is worth taking directly from the Pentagon's example. Cellular service there is locked in through Spiral 4, a blanket ten-year contract last renewed in 2024, with no opportunity to switch to a more secure offering until 2034. When you sign multi-year telecom agreements, include a security review cadence and an exit clause tied to failed audits so a contract term does not become the reason you cannot adopt a better option.

Document all of this in your incident response plan as a distinct scenario: interception without malware, no endpoint indicators, response driven by identity controls and carrier action.

Compliance and Disclosure Obligations for Affected Organizations

Signaling interception leaves nothing on the handset, which creates a specific compliance problem: you may have a reportable incident with no device artifact to point to. Your obligations still trigger on reasonable belief that data was accessed, not on forensic confirmation, so the absence of malware on a phone does not pause any clock you are subject to.

If you operate a carrier or resell connectivity, your exposure starts with customer data rules rather than the signaling protocols themselves. FCC breach-notification requirements cover customer proprietary network information — the call, text, and location records that signaling abuse targets — and they require notice to the Commission and federal law enforcement alongside customer notification. State attorney general statutes apply in parallel, and the two regimes rarely align on definitions or timing.

The accountability push described in the source article matters here because it changes what regulators will expect you to have on hand. Senators Ron Wyden and Eric Schmitt demanded that the government obtain carriers' cybersecurity audits and the carriers refused. Proposals now under discussion would require carriers to publish security audits, report on their signaling firewalls, and undergo yearly penetration tests — meaning documentation you treat as internal today may become a disclosable artifact.

For defense contractors, the operative language is contractual, not regulatory. DFARS 252.204-7012 obligates you to report cyber incidents affecting covered defense information or your ability to perform, submit the report through DoD's reporting portal, preserve system images and relevant monitoring data for the period the clause specifies, and support the government's damage assessment. CMMC assessment results now flow into award decisions, so an inaccurate or omitted report is not only a contract issue — the Justice Department has pursued cyber misrepresentation under the False Claims Act.

Where signaling attacks complicate this, your logs are not the relevant evidence. The records that show location queries, routing manipulation, or message interception sit with carriers and transit providers.

  • Send preservation requests to your carrier and any roaming or messaging aggregator in the path, because signaling records age out on their retention schedules, not yours.
  • Capture identity-side artifacts you do control — authentication logs, SMS-delivered reset events, session anomalies — since these may be the only evidence you can produce for investigators.
  • Route the matter to the FBI or your DoD counterintelligence element rather than handling it as a routine IT ticket, because targeting of personnel by a foreign service is a counterintelligence reporting matter.
  • Document your notification decisions and their timing, including decisions not to notify, so you can defend the reasoning later.

Agencies carry an additional layer. Incidents affecting federal information systems require reporting to CISA under FISMA, and suspected foreign-intelligence approaches against personnel carry separate reporting duties through security and counterintelligence channels. If contractor employees or servicemembers are the targets, your obligations run through both the personnel security chain and the contract's incident clause at the same time.

One constraint you should record honestly in your risk documentation: the Pentagon locks in cellular service through Spiral 4, a blanket ten-year contract last renewed in 2024, with the next opportunity to change providers arriving in 2034. If you support DoD programs that depend on that service, the risk is real, known, and not something your contract lets you remediate through procurement. Write it down as an accepted risk with the reasoning attached, and make sure your reporting procedures name who files with which authority before you need them.

Immediate Priorities for Telecom and Government Security Teams

The takeaway from this class of attack is that accountability sits with buyers and regulators, not with the person carrying the phone. No amount of user training changes a protocol that trusts any participant's signaling messages, so the questions worth asking are contractual ones.

Start with what your carrier will tell you in writing. Ask your cellular and connectivity providers for their most recent third-party security audit, their signaling firewall configuration reporting, and the results of their annual penetration test. "Done" here is a written response in your vendor file — and a refusal counts as an answer. When Sens. Ron Wyden and Eric Schmitt pressed the government to obtain carrier cybersecurity audits after the Salt Typhoon intrusions, the carriers declined to hand them over.

Second, find out who else has access to the networks you depend on. Your provider almost certainly leases connectivity to third parties, and those leases are how surveillance operators obtain legitimate credentials on the signaling backbone. Ask which downstream resellers hold access, what vetting they passed, and what triggers termination of the agreement. If your provider cannot name a process, you know the answer.

Third, check the expiration date on your own cellular contracts. The Pentagon's Spiral 4 blanket contract was last renewed in 2024 and runs ten years, which means the next opportunity to move to something better arrives in 2034. If your organization has signed a comparable multi-year arrangement, the length of that lock-in determines how long you carry the current risk regardless of what better technology reaches the market.

In This Article

Top hits