Red-lit cell tower antennas against a dark sky at dusk
Photo via Unsplash

TL;DR: On April 23, Citizen Lab published “Bad Connection,” a report exposing two separate surveillance campaigns that created fake telecom companies to exploit decade-old flaws in the global phone network. The attackers posed as legitimate carriers to send location-tracking queries through SS7 and Diameter protocols, rotating through 11 fake operator identities across 9 countries to disguise the traffic as normal roaming. One campaign sent invisible commands directly to targets’ SIM cards, silently turning their phones into location beacons. Three telecom providers (Israel’s 019Mobile, the UK’s Tango Networks, and the Channel Islands’ Airtel Jersey) served as gateway networks. The suspected operators: Israeli surveillance vendors linked to companies like Circles, Cognyte, and Rayzone. The phone industry has known about these vulnerabilities for over a decade. They still haven’t fixed them.

Fake Phone Companies, Real Surveillance

Here’s the setup. Your phone connects to cell towers using signaling protocols: SS7 for 2G/3G networks, and Diameter for 4G/5G. These protocols let carriers talk to each other so your calls connect when you roam between networks. They were designed in the 1980s when every phone company was a government monopoly and nobody imagined bad actors on the network.

That trust model is still in place. And surveillance vendors exploit it.

Citizen Lab identified two distinct campaigns (dubbed STA1 and STA2) that created shell companies posing as mobile operators. These ghost companies obtained access to the global signaling network through agreements with real carriers, then used that access to fire off location-tracking queries against targets [1].

Gary Miller, the report’s co-author, put it bluntly: “These are massive, massive amounts of unauthorized traffic and 90 plus percent of them are being generated by third parties accessing the mobile signaling environment” [2].

The first campaign (STA1) alternated between SS7 and Diameter attacks. When SS7 queries failed, the operator switched to Diameter. When Diameter got blocked, they rotated to a different fake identity and tried again. Citizen Lab tracked them cycling through 11 operator identities in 9 countries, masquerading as legitimate roaming traffic from the UK, Israel, China, Thailand, Sweden, Italy, Liechtenstein, Cambodia, and Mozambique [1].

Your Phone Became a Tracking Beacon. You Never Knew.

The second campaign (STA2) used something worse. Instead of querying the network about a target’s location, it sent a special SMS message directly to the target’s SIM card.

Not a normal text. This was a SIM toolkit command, a machine-level instruction that communicated directly with the SIM card’s processor. No notification appeared on the phone. No record showed in the message inbox. The command instructed the SIM card to report its location back to the attacker [1].

The target’s phone was turned into a covert tracking device. The target never knew.

Citizen Lab identified one specific victim as a “VVIP” company executive who was designated a high-value surveillance target. The researchers didn’t disclose names for privacy reasons [1].

Three Networks That Kept the Door Open

Both campaigns routed their surveillance traffic through the same three telecom providers, which Citizen Lab described as “surveillance entry and transit points within the telecommunications ecosystem” [1]:

  • 019Mobile (Israel): A privately owned Israeli operator under the brand “Telzar 019” that started providing mobile services in 2013. Citizen Lab found it was used repeatedly as both originating network and intermediary proxy for surveillance queries. 019Mobile’s IT head Gil Nagar said he “could not confirm” the identified infrastructure belonged to the company [2].
  • Tango Networks UK: Assigned Mobile Network Code 053 under UK’s MCC 234. Used in multi-year surveillance activity. Did not respond to requests for comment [2].
  • Airtel Jersey (Sure): A Channel Islands operator owned by Sure, previously linked to other telecom surveillance investigations. Sure CEO Alistair Beak claimed the company “does not lease access to signalling directly or knowingly” and has implemented “monitoring and blocking” measures [2].

These providers let surveillance vendors “hide behind their infrastructure,” according to the report. Whether through negligence or complicity, the result was the same: the attackers had a reliable pipeline into the global signaling network [1].

The Usual Suspects

Citizen Lab stopped short of naming specific clients. But the evidence points toward the commercial surveillance industry’s usual players.

The report describes “likely involvement of a commercial surveillance platform supporting state-sponsored intelligence activities.” Traffic analysis traced operations back to Israel. The techniques match known capabilities of Israeli surveillance vendors including Circles (acquired by NSO Group), Cognyte (formerly Verint), and Rayzone [1][2].

This isn’t new. In December 2020, Citizen Lab published “Running in Circles,” exposing how Circles sold SS7 surveillance to 25 countries including Australia, Mexico, Nigeria, Thailand, and the UAE [3]. The “Bad Connection” report shows the same playbook is still running six years later, with more sophisticated techniques and broader infrastructure.

Miller said he has observed “thousands of these attacks through the years” and that the two campaigns documented in this report represent “a small snapshot” of much wider exploitation [2].

A Decade of Warnings. Zero Fixes.

SS7 vulnerabilities have been publicly known since at least 2014, when German researcher Tobias Engel demonstrated live location tracking at the Chaos Communication Congress. The GSMA (the global telecom industry body) has published guidelines. The FCC has held hearings. European regulators have issued warnings.

The Diameter protocol was supposed to fix SS7’s security problems for 4G networks. It includes authentication and encryption features. But as Citizen Lab documents, many operators simply don’t implement the protections. The new protocol inherited the old protocol’s laziness [1].

Why hasn’t the industry fixed this? Because fixing it costs money. Implementing proper signaling firewalls, validating the source of every query, and cutting off unverified operators would require every carrier on the planet to invest in infrastructure upgrades. The carriers making money from roaming agreements have little incentive to police who’s on their network.

The surveillance vendors know this. That’s why the ghost company playbook works. Set up a shell operator, sign a roaming agreement with one of the three gateway networks, and you’re in.

What You Can Do

Be realistic: if a government-backed surveillance vendor targets you specifically through SS7 or Diameter, there’s no consumer-level fix. These attacks happen at the network layer, below your phone’s operating system. But you can reduce your exposure:

  • Use encrypted messaging apps: Signal, Session, or other end-to-end encrypted messengers protect message content even if your location is tracked via SS7
  • Disable 2G/3G where possible: On Android, you can restrict your phone to 4G/5G in network settings. SS7 attacks specifically target older protocols. iPhone users on iOS 17+ can enable “Lockdown Mode” which restricts some network-level attacks
  • Use a VPN: Won’t stop SS7 location tracking (which operates at the cell network level), but blocks other surveillance vectors that could be combined with location data
  • Watch for SIM swaps: If your service suddenly drops, contact your carrier immediately. SIM toolkit attacks and SIM swaps use similar infrastructure
  • Demand carrier accountability: Ask your carrier whether they’ve implemented SS7/Diameter firewalls and whether they validate the source of signaling queries. Most won’t answer. That silence tells you something

The real fix is regulatory. Governments need to mandate signaling firewalls, require telecom providers to verify third-party access, and hold gateway networks accountable when their infrastructure is used for surveillance. Citizen Lab’s recommendations include stronger authentication mechanisms, enhanced enforcement of security configurations across roaming partners, and national accountability frameworks for telecom leasing arrangements [1].

The Pattern

This is the third major Citizen Lab telecom surveillance report in two years. In October 2023, they published “Finding You,” documenting how the same network vulnerabilities enable mass location tracking [4]. Two weeks ago, they exposed Webloc, Penlink’s system for turning advertising data into a government tracking tool covering 500 million devices.

Different techniques. Same outcome. Your phone is a tracking device for anyone willing to pay for access, whether through the ad network, the signaling network, or both.

The telecom industry has known this for over a decade. The surveillance industry has profited from it for just as long. And the phone in your pocket is still broadcasting your location to anyone with a roaming agreement and a fake company name.

References

  1. Citizen Lab: Bad Connection: Uncovering Global Telecom Exploitation by Covert Surveillance Actors (April 23, 2026)
  2. TechCrunch: Surveillance vendors caught abusing access to telcos to track people’s phone locations, researchers say (April 23, 2026)
  3. Citizen Lab: Running in Circles: Uncovering the Clients of Cyberespionage Firm Circles (December 2020)
  4. Citizen Lab: Finding You: The Network Effect of Telecommunications Vulnerabilities for Location Disclosure (October 2023)
  5. The Record: Surveillance companies exploiting telecom system to spy on targets’ locations (April 23, 2026)