Sources and telecom data: a coordinated campaign of SS7 pings was used to track the locations of US personnel during the US-led strikes on Iran in late February
Context & Ripple Effects
Related coverage describes Iran expanding cyber activity for intelligence gathering and target identification, alongside a longer-running Israel-Iran cyber confrontation. Separately, research has documented Iranian state integration of communications and internet surveillance.
This report places a legacy mobile-network weakness inside that wider conflict: SS7 flaws can expose location data and enable interception or account-takeover paths, making telecom infrastructure relevant to operational security rather than only consumer fraud.
First-order effects
- US personnel using exposed mobile-network paths faced a location-disclosure risk during the February operations, adding a communications-security concern to physical-force protection.
- Mobile operators and security teams responsible for relevant signaling routes face immediate pressure to detect, block, or constrain suspicious SS7 location requests.
Second-order effects
- Military and government users may tighten handset-use, roaming, and authentication practices, since the same SS7 weaknesses can support both geolocation and interception of SMS-based two-factor codes.
- Telecom operators, roaming partners, and security vendors face stronger incentives to harden signaling controls and share indicators of abusive requests, because a weakness in cross-network connectivity can affect high-value users beyond one carrier.
Third-order effects
- If state-linked actors continue to exploit SS7 during active conflict, mobile-network signaling security will increasingly be treated as critical-infrastructure and national-security exposure, not merely a telecom fraud issue.
- The episode underscores a structural mismatch between globally interconnected legacy signaling and modern threat models; remediation is likely to depend on coordinated operator practices, since an individual user or carrier cannot fully control risks originating elsewhere in the network.
The trend: Cyber conflict is broadening from attacks on digital systems to exploitation of underlying communications infrastructure for real-world targeting and intelligence collection.