Citizen Lab details two spying campaigns that abuse weaknesses in the SS7 and Diameter protocols across 2G, 3G, 4G, and 5G networks to track people's locations
Security researchers have uncovered two separate spying campaigns that are abusing well-known weaknesses in the global telecoms infrastructure to track people's locations.
Context & Ripple Effects
The new findings extend a long-running Citizen Lab record on telecom surveillance: its 2023 work described roaming-signaling geolocation risks, while earlier coverage documented SS7 weaknesses and SIM-based monitoring used by actors working with governments.
What makes this episode consequential is the persistence of exposure across successive mobile generations. The coverage links legacy signaling weaknesses to contemporary location-surveillance campaigns rather than treating the transition to newer networks as a clean security reset.
First-order effects
- People targeted by the two campaigns can be located through weaknesses in SS7 and Diameter signaling, spanning networks from 2G through 5G.
- Mobile operators and their roaming connections are the immediate defensive boundary, because the abused protocols sit in the infrastructure used to exchange signaling information.
Second-order effects
- Operators face pressure to scrutinize signaling traffic and roaming relationships, since a weakness in inter-operator connectivity can expose subscribers beyond a single carrier's own network controls.
- Commercial surveillance vendors and government customers face greater attribution and reputational risk as repeated research ties telecom-layer access to location monitoring.
Third-order effects
- If such cases continue, mobile-security strategy will increasingly center on securing cross-network trust and legacy interoperability, not simply deploying newer radio generations.
- The pattern strengthens the case for ecosystem-level telecom defenses: security outcomes depend on the practices of roaming partners and signaling intermediaries as well as an individual operator.
The trend: Persistent telecom signaling abuse is turning mobile location privacy into an ecosystem-security problem that survives network-generation upgrades.