7 ms·
Investigation uncovers two sophisticated telecom surveillance campaigns
https://citizenlab.ca/research/uncovering-global-telecom-exploitation-by-covert-surveillance-actors/ https://citizenlab.ca/research/uncovering-global-telecom-exp...
- aetherspawn 6mo agoYeah, a friend of mine was tracked by a stalker ex boyfriend who worked at a Telco. It was irritatingly difficult to avoid because it seemed he could look up her SIM card by name and then get her location no matter what (new SIM, new phone) Anyone who reports this kind of thing to the police just sounds irrational and crazy and gets ignored.
- therobots927 6mo agoAssuming he had access to a database with (lat, long, SIM) data, if she got a new phone he could just use the known (lat, long pairs) from the old sim and lookup to get the new sim. Then bam, you can get all of the new lat longs. It’s impossible to avoid unless you simultaneously move to a new house / apartment when you get your new phone, and never bring the new phone to any previous low-traffic location you brought the old phone to.
- calvinmorrison 6mo agoit's impossible for your precise location to be tracked by anybody... wow thats crazy
- kenjackson 6mo agoWhat does this mean?
- justinclift 6mo agoIf the person was deep enough into the system to have access to location data, then they'd probably be able to just directly look up customer details (likely easier).
- hocuspocus 6mo agoAbsolutely not. I have access to geo-located network telemetry. CRM data is completely off limit to anyone on my team.
- kakacik 6mo agoWell maybe it wasn't such a well secured company and also this seems story from the past.
- hocuspocus 6mo agoBuilt-in positioning of network traces is relatively recent in mobile network equipment and dedicated probes. If that happened more than 5-6 years ago, it would sound even less likely. Most telcos never bothered doing the processing needed to position raw events based on timing advances. They'd simply offload that to third party companies. These solution providers aren't crazy, they don't touch data that isn't already anonymized. It's even less probable that a random employee would have access to the multiple datasets needed to piece someone's personal data together.
- justinclift 6mo agoAre you in a small company where most people wear lots of hats, or in a big company that has siloed off groups? Am guessing it's more of the big company approach that silos things off?
- hocuspocus 6mo agoAs far as telcos go, I work at a pretty small one. We have fewer subscribers than say, a single Chinese operator would have in a second tier city.
- Padriac 6mo agoSounds like something worth reporting as it is an offence in Australia at least. The police would certainly investigate such an allegation and charges could be laid if there was sufficient evidence and a conviction was possible.
- jimbo808 6mo agoHa. That's what everyone thinks before they've needed the police.
- aetherspawn 6mo agoYeah it was reported, but the telcos systems were such a load of slop there wasn’t any specific evidence recorded (logs etc), and besides nobody knew what to ask for, so it couldn’t be taken seriously. I don’t remember the exact circumstances of how they got a confession years later, I think bragging, but he did get convicted and the Telco eventually fired him, which stopped the stalking.
- boringg 6mo agoWhat no log files of who's accessing records? That seems super sketch.
- aetherspawn 6mo agoI’m spitballing here but it seemed like his job was a kind of ITS/technician job in the core infrastructure, and it seemed like he didn’t need to go through normal channels to get the information he wanted, ie he could just like pcap a tower with a filter or whatever in a routine kind of way that I guess didn’t create any specific logs. If there were any relevant logs they would have had to give them to the police. And I know that at a high level Telcos are heavily regulated, so there should have been logs.
- mr_toad 6mo agoDoesn’t surprise me at all. I signed up for an internet plan with a provider once, but they never let me login to pay the bills. After they started threatening me with collections and several phone calls layer it turned out they were billing someone in a completely different city. Complete shambles.
- hocuspocus 6mo agoI'm sorry but this sounds like bullshit. As someone who has access to such data at a telco: - Very few people have legit business cases requiring access to enriched network telemetry, at least non aggregated. - Of which, only a handful have any reason to see the MSISDN in clear. - Of which, none can get access to clear CRM data. - Lawful interception and emergency services use completely separate paths, exposed via user interfaces that aren't available to employees. And obviously, a simple email to the data governance and privacy office would be taken extremely seriously. Also why not simply switch to a different phone operator?
- hnthrow0287345 6mo agoI'm sure every single telco in the world is perfectly in line with this
- hocuspocus 6mo agoEven in pretty dysfunctional countries, or pro-business ones like the US, where nothing like the GDPR exists, telcos management have a strong interest in not letting just any rank and file employee spy on subscribers.
- throwawaysleep 6mo agoMost breaches are not in the interests of management, but they happen anyway as management wants to save money or doesn't understand how it could happen.
- lostlogin 6mo agoStalker terrorises woman, she reports it, nothing happens, stalker kills her. Queue hand wringing. It’s played out a lot of times, in a lot of places, I don’t know why everyone here is so cynical.
- mistrial9 6mo agoyou are close to a system in a way that those guardrails are clear and present; the story is from the point of view of a victim, and it is possible that they were indeed a victim. Therefore the means of the stalking is not known at all via this story, but somehow, something did occur. It is not surprising on either side, and they do not necessarily contradict each other IMHO
- wil421 6mo agoScammy telcos in poorer countries sell SS7 data for a small fee. It will give you all the location data you need.
- pocksuppet 6mo agoSS7 access - you still have to hack the system to acquire the data yourself, and I believe it creates a log that you roamed to that country, and briefly disconnects your cellphone from the network? It's far from invisible.
- pigggg 6mo agoIt's literally a known thing at telcos in various roles they find people looking up folks dox regularly. If someone registers a complaint that someone access their data they'll look it up and deal with them. I once asked someone on the security /investigations side if you are logging what everyone is doing can't you easily find when folks are looking up stuff unrelated to their job? Their answer: we'd have to fire over half the people here - everyone is constantly looking up people's PII - celebrities, friends, enemies, etc. it's almost considered a unofficial perk of the job. This was from one of the largest US Telco carriers circa 2010. Maybe things have changed, hopefully.
- pocksuppet 6mo agoIn Western Europe they would get fired and go to jail. That's why Western Europe doxx information is considered the most expensive in the world. It wasn't complicated to create that situation. They can just fire a few, drag one to court, and rely on the chilling effect.
- dboreham 6mo agoCalling BS on that story. You don't need to fire anyone. You just rate limit access to lookups where the customer didn't initiate a support call themselves, and require supervisor approval and audit of said approvals on a regular basis. I've also worked on systems where accounts could be marked as sensitive (e.g. the celebrities) and those needed additional sign off to be accessed.
- lostlogin 6mo agoI’ve worked in systems like that too. I can tell you exactly how much privacy the celebrities got. There is no record of the sharing or the breaches.
- tamimio 6mo agoWell, my privacy-o-meter made me have my phone with no sim card and always airplane mode, and the sim card is in a dumb phone in my house, that I also barely turn on unless needed. Not perfect, but still far better than being tracked with telecoms.
- therobots927 6mo agoOh would you look at that: “Israeli-based commercial geo-intelligence provider with specialized telecom capabilities.” Make no mistake, the people of Gaza and Lebanon are being used as guinea pigs for highly invasive surveillance technology that could easily be pointed at any of us if we step out of line. And yes I said people of Gaza, not tellhullists as they’re referred to in Zion.
- thisislife2 6mo agoThat Gaza, the world's largest open prison, is an experiment playground for Israeli surveillance and military tech is a popular theory online that is now finding space in mainstream media too: 1. Gaza: a testing ground for Israeli military technology - https://www.middleeasteye.net/opinion/gaza-testing-ground-israeli-military-technology https://www.middleeasteye.net/opinion/gaza-testing-ground-is... 2. Gaza “laboratory” boosts profits of Israel’s war industry - https://electronicintifada.net/content/gaza-laboratory-boosts-profits-israels-war-industry/25636 https://electronicintifada.net/content/gaza-laboratory-boost... 3. Gaza Becomes Israel’s Testing Ground for Military Robots - https://archive.is/P6mAQ https://archive.is/P6mAQ
- deleted 6mo ago[deleted]
- LePetitPrince 6mo ago[dead]
- throwaw12 6mo ago> ... Israeli-based commercial geo-intelligence provider with specialized telecom capabilities ... why are they good at these kind of things - security, hacks, surveillance, 0-days?
- pjc50 6mo agoThey run a mass surveillance operation so they can target individual people with exploding pagers. It's just another aspect of the longstanding war between Israel and Iran (via Hezbollah etc).
- bakugo 6mo agoWhen your goal is to covertly subvert and take control of foreign nations, these sorts of skills tend to come in handy.
- morellt 6mo agoNo clue why this is getting downvoted, this is literally the purpose.
- red-iron-pine 6mo agomay not even be the deliberate goal. just that the 100% conscription rate + backs-to-the-wall attitude means that the IDF has a lot of well trained signals intelligence guys who need to make money somehow.
- jeroenhd 6mo agoThey are a country surrounded by countries that either dislike them or want them wiped from the face of the earth. It only makes sense that they have a significant intelligence and spying industry. The genocide they're undertaking does place that industry in a whole new light, of course.
- goolz 6mo agoWorth note their leaders and allies are bereft of morality.
- arjunthazhath 6mo agojesus christ!
- rurban 6mo agoThey do have the death penalty now in Israel. So it might get interesting for those bosses
- dewey 6mo agoYou forgot one important detail there.
- pprotas 6mo agoThe death penalty was intended for Palestinians, not Israeli bosses
- rurban 6mo agosure, but when the tide switches to a far-left government they might use it against them.
- tovej 6mo agoI do believe the law was specifically carved out so it could only be used against Palestinian prisoners. And there is no far-left in Israel, at least no far-left party that could ever be in government.
- deleted 6mo ago[deleted]
- Muromec 6mo agoIt doesn't always go as intended.
- Anonyneko 6mo agoThis is just par for the course in Russia. Government has telcos track people, and that data ends up available on the black market for anyone to purchase, for a fairly modest fee. The government has been recently trying (with uncertain degree of success) to crack down on the latter, as this was frequently used by the opposition journalists and investigators to uncover the details of the government's own nefarious plots. The data is cross-referenced with other telcos, other SIM cards, Wi-Fi hotspots (anonymous public hotspots are outlawed), street cams, and many other databases, so it's basically impossible to avoid being tracked. Probably inevitable to become the norm everywhere in the world.
- betaby 6mo ago> Government has telcos track people Yes > and that data ends up available on the black market for anyone to purchase, for a fairly modest fee Probably not. Those DBs are fake most ( all ? ) the time.
- Anonyneko 6mo agoThe Russian leaked ones have proven to be legit many times over by investigative journalists cross-referencing those with other databases (e.g. flight tracking or leaked food delivery databases).
- kikimora 6mo agoIn Russia case no, they are not fake. Navalny tracked his killers by analyzing flight and train travel data identifying people who always travel with him. They used data sold in the black market.
- znort_ 6mo ago> This is just par for the course in Russia nice deflection there, ofc bad russia! you did surely notice that this article is about the uk? oh, and (big surprise!) israeli cell and surveillance companies ...
- Anonyneko 6mo ago
- fchicken 6mo agoColor me shocked
- dfc 6mo agoI get a 404 when I try and view the CitizenLab report: https://citizenlab.ca/research/uncovering-global-telecom-exploitation-by-covert-surveillance-actors/ https://citizenlab.ca/research/uncovering-global-telecom-exp...
- mentalgear 6mo ago> Gary Miller, one of the researchers who investigated these attacks, told TechCrunch that some clues point to an “Israeli-based commercial geo-intelligence provider with specialized telecom capabilities,” but did not name the surveillance provider. Several Israeli companies are known to offer similar services, such as Circles (later acquired by spyware maker NSO Group), Cognyte, and Rayzone.
- walrus01 6mo agoWhy is the citizen lab report URL suddenly a 404?
- Rob_Polding 6mo agoIn my country 95% of people don't mind Meta tracking their location with WhatsApp, so I think the days of people caring about tracking are long gone! I am the exception and believe in privacy, and I've not used a Meta app since I tested Facebook/WhatsApp back in 2010 and soon uninstalled them as I don't want a digital portfolio to be developed on me for advertisers. Same with Google, they can whistle for my personal information, but they won't get it! I'm sure surveillance companies have an even easier time buying data from Meta/WhatsApp so that's even more worrying as people use different ISPs so 95% of people won't be traced by any one ISP, but Meta and Google have the location information of anyone gullible enough to use their services.
- woadwarrior01 6mo agoOne of the first bits of infosec advice I give to my non-technical friends and family, when they ask for it, is to turn off background location access for all apps on their phones. Needless to say, I know plenty of technical people who don't care about it.
- forlorn_mammoth 6mo agobecause someone made background location access a "necessary" part of the the bluetooth stack? The cost of opting out is very high. "Mark of the beast"-- you want to participate in society, you need it.
- everdrive 6mo agoModern people seem to be incredibly weak and dependent. "I can't protect my freedom if it means giving up bluetooth!" It almost reads as satire.
- gruez 6mo ago>In my country 95% of people don't mind Meta tracking their location with WhatsApp Source? Seems unlikely given that both android and ios has location permissions and keeps track of whether it's used. Non-consensual (ie. you're not specifically using some location sharing feature or whatever) is very likely to be caught and cause a publicity shitstorm.
- faxuss 6mo agoEveryone does it, they just got caught.
- DrewADesign 6mo agoI was training to be a 911 dispatcher a while ago. When they told us about getting someone’s location from the cell company outside of what was available automatically from e911 or whatever— which required them to be on the phone with you, so not useful if you get a text saying they just drove off a cliff in the middle of nowhere, or something— you had to sign an affidavit testifying that there were exigent circumstances, fax it to them, and then wait, sometimes for hours, until their legal department approved it. And you always risked being dragged to court if you made the wrong call. That’s the price of privacy, and the potential for abuse is rife, so it makes sense. Yet these jackholes can just snag it whenever because, ya know, profit. That is obviously insane. Our corporate culture has driven our society insane with normalized greed. The unholy alliance of tech and marketing is largely to blame.
- jbxntuehineoh 6mo ago> then wait, sometimes for hours that just sounds pointless, won't they be dead by that point anyways?
- pocksuppet 6mo agoIOW: We must end this "privacy" thing - think of people who might be dying! It's all about power, anyway. The NSA doesn't need a warrant at all. When the police want to get an alleged criminal they can get a warrant in minutes. But when it's your life in danger, it takes hours. The purpose of a system is what it does.
- rdevilla 6mo agoIn 2026, it's Israel. The NSA is so last decade, and isn't even mentioned in this article. Silicon Valley and global communications infrastructure has been compromised by Israel. Quoting TFA: > This analysis identified 4G infrastructure associated with operator networks based in Israel, the United Kingdom, and the Channel Islands. Notably, in prior public reporting these same countries have been linked to CSVs targeting mobile users. > Israel has long been a focal point in the global surveillance industry, with multiple companies developing and exporting advanced spyware, cellular communications interception, and monitoring technologies.
- areoform 6mo agoOne of the biggest lies about the surveillance state is that it'll be professional. NSA employees have used multi-billion dollar American surveillance assets to spy on women they're infatuated with. There's even a cute term for it, LOVEINT. https://www.nbcnews.com/news/world/loveint-nsa-letter-discloses-employee-eavesdropping-girlfriends-spouses-flna8C11271620 https://www.nbcnews.com/news/world/loveint-nsa-letter-disclo... https://www.yahoo.com/news/nsa-staff-used-spy-tools-spouses-ex-lovers-193227203.html https://www.yahoo.com/news/nsa-staff-used-spy-tools-spouses-... In another instance, a foreign woman who was employed by the U.S. government suspected that her lover, an NSA civilian employee, was listening to her phone calls. She shared her suspicion with another government employee, who reported it. An investigation found the man abused NSA databases from 1998 to 2003 to snoop on nine phone numbers of foreign women and twice collected communications of an American, according to the inspector general's report. People aren't able to imagine the ramifications of pervasive surveillance because there never has been such pervasive surveillance in human history. And humans are terrible at predicting how this is going to change things. Especially, with LLMs in the mix. Unless a very strict line is maintained for privacy across the board; the world that's coming will be many, many custom, tailor-made hells co-existing as tumors off of the back of state and corporate surveillance infrastructure.
- 1a527dd5 6mo ago> She shared her suspicion with another government employee, who reported it. And what pray tell do you do if you don't have anyone to report it to inside the government? Reports like that can easily get blackholed.
- nielsbot 6mo agoi’m surprised it went anywhere even inside the government. and imagine all the cases we don’t know about. not only that but - someone in the Senate (Wyden?) recently said it’s worse than anyone thinks and people would be outraged - a judge from the FISA court, said FISA should be revised e.g. https://www.politico.com/live-updates/2026/04/15/congress/wyden-urges-democrats-to-back-fisa-privacy-amendments-00873053 https://www.politico.com/live-updates/2026/04/15/congress/wy...
- lbcadden3 6mo agoI’m shocked, shocked I say!
- voxadam 6mo agoWell, not that shocked.
- matthewqin 6mo ago[dead]
- Fokamul 6mo agoI like I live in country where SIMs can be bought without any verification. Cops and agencies trying to change this, (buuhuuu someone bought anonymous SIMs in bulk and sold them on darknet) Surprisingly, there was major public pushback, pretty unlucky for cops.
- srameshc 6mo agoI was reading news this morning about Lebanese journalist killed in airstrike. I was thinking very likely she was tracked wherever she was taking shelter. These kind of surveillance probably helps track such people on large scale and we most of the time meh at such reports and think what have I to loose. But it is affecting everyone now, not some ambigious high profile targets, they are the people amongst us.
- therobots927 6mo agoComing soon to a city near you. The goal is dominance and control of the poor by the rich.
- aa-jv 6mo agoTracking wasn't necessary in her case, she was already talking to Israeli forces prior to being murdered. They knew where she was by direct personal observation, which was then used to target her.
- Danox 6mo agoOf course they are what could go wrong?
- Barbing 6mo agoHelp our security if you can!— “Contact Us Do you have more information about surveillance vendors that exploit cellphone networks? From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or email[]”
- gosub100 6mo agoOff topic, but is there any black market way I can buy the personal data of the robodialers that flood my number 20x / day? I know they spoof caller ID, and I'm not referring to filing a costly civil suit and getting their names from discovery.
- vinay_ys 6mo agoEven if you are on modern 5G network, and set your phone to never connect to 2G/3G network, your location is still compromised because the overall network is still backward compatible to support someone who might be trying to reach you from a 2G or 3G network which run on the insecure SS7 protocol. This enables protocol downgrade attacks. Only way to insulate yourself from this while still being on mobile networks is to use a "data-only" sim and stick to purely Internet based secure messaging and calling apps and not use the phone number for anything. The way mobile radio/phone networks have evolved (trusted walled garden with backward compatibility) vs Internet has evolved (untrusted with end to end security) is in stark contrast to each other.
- sigbottle 6mo agoSuper interesting stuff, got reading on this?
- LePetitPrince 6mo ago[dead]
- ItsClo688 6mo agothanks for sahding, and i feel like the SS7 thing is such a classic "known unfixed" problem. everyone in telecom knows it's broken, has known for decades. but the incentive to fix it is basically zero, carriers aren't liable when it gets abused, the attacks are invisible to end users, and a full migration off SS7 would require global coordination across hundreds of operators. so nothing happens. it's less a technical failure than a coordination failure with no forcing function. Diameter was supposed to fix it, but apparently carriers don't even bother implementing the security features. which kind of proves the point. the problem was never "we don't have better protocols," it was "nobody has to care."