Policy & Regulation
Citizen Lab report exposes surveillance abuse in global telecom networks
Citizen Lab identified two spying campaigns likely exploiting global telecom infrastructure, using "ghost" companies to track individuals via known network vulnerabilities.
On Thursday, digital rights organization Citizen Lab published a new report detailing two separate spying campaigns that are abusing well-known weaknesses in the global telecoms infrastructure to track people’s locations. According to the organization, these two campaigns are likely a small snapshot of what researchers believe to be widespread exploitation of surveillance vendors seeking access to global phone networks. The surveillance vendors behind the campaigns operated as “ghost” companies that pretended to be legitimate cellular providers to gain access to these networks.
The campaigns exploited vulnerabilities in Signaling System 7 (SS7)—a set of protocols for 2G and 3G networks used to route calls and messages—and its newer successor, Diameter, which is the protocol for 4G and 5G communications. While Diameter includes security features lacking in SS7, cell providers do not always implement these protections, allowing attackers to exploit the newer protocol or force connections to fall back to SS7. One of the campaigns also used a SIMjacker exploit—a cybersecurity exploit involving SMS messages sent directly to SIM cards, a term dubbed by mobile cybersecurity company Enea. Gary Miller, a researcher who investigated the attacks, stated: “I’ve observed thousands of these attacks through the years, so I would say it’s a fairly common exploit that’s difficult to detect.” Miller added that the attacks appear to be geographically targeted, indicating that actors employing SIMjacker-style attacks likely know the countries and networks most vulnerable to them.
The report identified three specific telecom providers that acted as transit points for the surveillance. These include Israeli operator 019Mobile, which was identified as being used in several surveillance attempts, and British provider Tango Networks U.K., which was used for surveillance activity. The third is Airtel Jersey, a telecom operator on the Channel Island of Jersey owned by Sure, whose networks have been linked to prior surveillance campaigns. In response, Sure CEO Alistair Beak stated that the company does not lease access to signalling directly or knowingly to organisations for the purposes of locating or tracking individuals, or for intercepting communications content. Beak added that Sure acknowledges digital services can be misused, which is why the company has implemented several protective measures to prevent the misuse of signalling services, including monitoring and blocking inappropriate signalling. Meanwhile, Gil Nagar, head of IT and security at 019Mobile, stated that the company cannot confirm that the alleged 019Mobile infrastructure belongs to the company.
Why it matters
The report details how surveillance vendors are exploiting vulnerabilities in global telecom protocols like SS7 and Diameter to track individuals, suggesting widespread abuse of mobile network infrastructure.