/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Researchers say multiple telcos are deploying RCS in ways that expose users to text and call interception, spoofed phone calls, and location data leaks

A standard used by phone carriers around the world can leave users open to all sorts of attacks, like text message and call interception …

VICE Joseph Cox

Context & Ripple Effects

The RCS finding slots into a multi-year research arc on carrier network insecurity rather than standing alone. Earlier work documented ten possible attacks on LTE networks enabling text and call eavesdropping, and later research showed how signaling protocols used for international roaming can be abused to geolocate devices — the same class of core-network exposure this report extends to a messaging standard most carriers ship by default.

What makes the RCS report distinct is scope: unlike a single operator misconfiguration, RCS is deployed across many telcos worldwide, meaning the vulnerable procedures are likely shared infrastructure choices rather than isolated mistakes.

First-order effects

  • Users on affected carriers face direct interception risk today — their texts, calls, and location data are reachable through the flawed RCS implementations, alongside spoofed calls that impersonate trusted numbers.

Second-order effects

  • Carriers named or unnamed face pressure to audit and re-secure their messaging deployments, and security researchers now have a template for probing other carrier-run services — following the path of the [[a:949612|SIM swapping weaknesses found in AT&T, T-Mobile, Tracfone, US Mobile, and Verizon support procedures]], where the same pattern of vulnerable customer-facing processes repeated across major operators.

Third-order effects

  • If each new protocol audit keeps surfacing the same failures — from LTE attacks to stolen call records at over ten providers worldwide (hackers mass-stealing call records) — regulators and standards bodies will face mounting evidence that carrier core networks need mandatory security certification rather than voluntary compliance.

The trend: Mobile carrier infrastructure is accumulating a consistent record of protocol-level security failures, pushing the industry toward externally audited, standards-enforced network security.

Discussion

  • @josephfcox Joseph Cox on x
    Here are more details about the attacks on RCS, which telecos are rolling out as the replacement to SMS https://srlabs.de/... pic.twitter.com/SInuDDgSq5
  • @yangrunenberger Yan on x
    « SRLabs didn't find an issue in the RCS standard itself, but rather how it is being implemented by different telecos. » https://www.vice.com/...
  • @vice @vice on x
    “All of these mistakes from the 90s are being reinvented, reintroduced.” https://www.vice.com/...
  • @kylebaker Kyle Baker on x
    For as long as it took to introduce RCS, one would've hoped they took that time to improve security. Looks not. https://twitter.com/...
  • @geeknik @geeknik on x
    Researchers from SRLabs found that telecos are implementing the RCS standard in vulnerable ways, which bring back techniques to attack phone networks. https://www.vice.com/...
  • @caparsons Christopher Parsons on x
    SMS Replacement is Exposing Users to Text, Call Interception Thanks to Sloppy Telecos // It would be good to have some Canadian reporters determine the security statuses of RCS deployments on the Rogers, Fido, and Freedom networks https://www.vice.com/...
  • @vice @vice on x
    “I'm surprised that large companies introduce a technology that exposes literally hundreds of millions of people, without asking them, without telling them.” https://www.vice.com/...
  • @vice @vice on x
    A standard used by phone carriers around the world can leave users open to all sorts of attacks, new research reveals. https://www.vice.com/...