Back to all lessons
Awareness Lessons
3 days ago

SS7 Telecom Flaws Leave U.S. Military Personnel Exposed to Iranian Surveillance

Iran is actively exploiting decades-old vulnerabilities in the SS7 signaling protocol to track and intercept communications of U.S. military personnel — a threat that has been well-understood since at least 2014 but remains largely unmitigated due to the legacy architecture of global telecom infrastructure. The root problem is a failure of vulnerability management at an industry and governmental scale: the risks are known, the attack techniques are documented, and yet structural inaction has left critical users exposed. This matters because individual operational security measures — such as using encrypted messaging apps — cannot fully protect against network-layer attacks that occur before data ever reaches the user's device. The gap between awareness and action represents a systemic failure that requires coordinated industry, legislative, and Department of Defense intervention, not just personal responsibility.

Tactical Insight

Immediate actions

  • Issue official guidance requiring military personnel to use end-to-end encrypted VoIP and messaging platforms (e.g., Signal) that reduce reliance on SS7-dependent voice and SMS channels.
  • Deploy IMSI-catcher detection tools and SS7 anomaly monitoring on networks used by sensitive government and military users.
  • Restrict SMS-based multi-factor authentication for personnel with access to sensitive systems, replacing it with hardware security keys or authenticator apps.

Long-term improvements

  • Mandate telecom carriers serving government clients to implement SS7 firewalls and adopt 5G standalone architectures that eliminate legacy SS7 dependencies.
  • Establish DoD-level procurement requirements that compel telecommunications vendors to demonstrate SS7/Diameter vulnerability mitigations before contract award.
  • Pursue legislative action requiring the FCC to enforce minimum SS7 security standards across all U.S. carriers, with enforceable compliance timelines.

Detection & monitoring measures

  • Implement continuous SS7 traffic monitoring through specialized telecom security vendors to detect unauthorized location queries or call interception attempts targeting government numbers.
  • Establish a threat intelligence sharing program between the DoD, DHS CISA, and major U.S. carriers to rapidly surface active SS7 exploitation campaigns.
  • Conduct regular red-team exercises simulating SS7-based attacks against personnel communications to validate detection and response capabilities.