Researchers say multiple telcos are deploying RCS in ways that expose users to text and call interception, spoofed phone calls, and location data leaks
A standard used by phone carriers around the world can leave users open to all sorts of attacks, like text message and call interception …
Context & Ripple Effects
The RCS finding slots into a multi-year research arc on carrier network insecurity rather than standing alone. Earlier work documented ten possible attacks on LTE networks enabling text and call eavesdropping, and later research showed how signaling protocols used for international roaming can be abused to geolocate devices — the same class of core-network exposure this report extends to a messaging standard most carriers ship by default.
What makes the RCS report distinct is scope: unlike a single operator misconfiguration, RCS is deployed across many telcos worldwide, meaning the vulnerable procedures are likely shared infrastructure choices rather than isolated mistakes.
First-order effects
- Users on affected carriers face direct interception risk today — their texts, calls, and location data are reachable through the flawed RCS implementations, alongside spoofed calls that impersonate trusted numbers.
Second-order effects
- Carriers named or unnamed face pressure to audit and re-secure their messaging deployments, and security researchers now have a template for probing other carrier-run services — following the path of the [[a:949612|SIM swapping weaknesses found in AT&T, T-Mobile, Tracfone, US Mobile, and Verizon support procedures]], where the same pattern of vulnerable customer-facing processes repeated across major operators.
Third-order effects
- If each new protocol audit keeps surfacing the same failures — from LTE attacks to stolen call records at over ten providers worldwide (hackers mass-stealing call records) — regulators and standards bodies will face mounting evidence that carrier core networks need mandatory security certification rather than voluntary compliance.
The trend: Mobile carrier infrastructure is accumulating a consistent record of protocol-level security failures, pushing the industry toward externally audited, standards-enforced network security.