How Spies Can Use Your Cellphone to Find You

(Jewel Samad/AFP/Getty Images)
(Jewel Samad/AFP/Getty Images)
TT

How Spies Can Use Your Cellphone to Find You

(Jewel Samad/AFP/Getty Images)
(Jewel Samad/AFP/Getty Images)

Surveillance systems that track the locations of cellphone users and spy on their calls, texts and data streams are being turned against Americans as they roam the country and the world, say security experts and US officials.

Federal officials acknowledged the privacy risk to Americans in a previously undisclosed letter from the Department of Homeland Security to Sen. Ron Wyden (D-Ore.) last week, saying they had received reports that “nefarious actors may have exploited” global cellular networks “to target the communications of American citizens.”

The letter, dated May 22 and obtained by The Washington Post, described surveillance systems that tap into a global messaging system that allows cellular customers to move from network to network as they travel. The decades-old messaging system, called SS7, has little security, allowing intelligence agencies and some criminal gangs to spy on unwitting targets — based on nothing more than their cellphone numbers.

“I don’t think most Americans realize how insecure US telephone networks are,” Wyden said in a statement. “If more consumers knew how easy it is for bad guys to track or hack their mobile phones, they would demand the FCC and wireless companies do something about it. These aren’t just hypotheticals.”

Wyden also revealed in a separate letter Tuesday that a major American cellular carrier has referred an “SS7 breach” involving customer data to federal law enforcement officials for investigation. He chastised the Federal Communications Commission in the letter, saying it had “failed to address this ongoing threat to national security.”

The FCC declined to comment on the letter, which was addressed to Chairman Ajit Pai.

SS7, which stands for Signaling System 7, was created in the 1970s as a way for telecommunications carriers to exchange information as they routed calls. Over the years, SS7 expanded to serve a sprawling global cellular system that allowed users to move from network to network — within their own nations and across international borders — without missing calls, losing service or having to make payments to each carrier that routed a signal to their phones.

But as the number of companies with access to SS7 grew from a handful to many thousands, the lack of built-in security became a growing problem. It was easy for anyone with access to the network to pretend to be a carrier making legitimate requests for information about customers.

Early research of SS7 surveillance focused on its use in tracking user locations through cellphones. But in recent years, a more serious issue has emerged around its ability to intercept calls, texts and data.

Researchers say that SS7 tracking systems around the world now create millions of “malicious queries” — meaning messages seeking unauthorized access to user information — each month.

One Israeli surveillance vendor, Ability, said in an online marketing video posted last year that its ULIN interception system can eavesdrop on cellphone calls on targets in New York or Los Angeles while agents are “sitting at your desk . . . anywhere in the world.” A 2016 brochure for the company depicted phones being tracked in Massachusetts.

Ability declined to comment about SS7 interception or where the company conducts surveillance, but a person familiar with its operations, who spoke on the condition of anonymity to describe private corporate details, said that the ULIN system is not used in the United States. The video, this person said, is used “for demonstration purposes.”

The company says on its website that it has had 50 government clients around the world and does not have private-sector clients. Public financial documents listed Ability’s major areas of operation as Latin America, Asia and Africa, but it does not name nations. Forbes has previously reported on Ability’s capabilities and sales, including to a client in Mexico.

The company, which has struggled financially in recent years, according to news reports, has several competitors, including in Israel, in Eastern Europe and in other parts of the world, say experts in SS7 surveillance.

Wyden said the risks posed by SS7 surveillance go beyond privacy to affect national security. American, Chinese, Israeli and Russian intelligence agencies are the most active users of SS7 surveillance, experts say, and private-sector vendors have put systems within the reach of dozens of other governments worldwide. Sophisticated criminals and private providers of business intelligence also use the surveillance technology.

“America is the Number One target, far and away. Everyone wants to know what’s happening in America,” said Brian Collins, chief executive of AdaptiveMobile Security, a cellular security firm based in Dublin. “You will always be a target, whether at home or away.”

Other experts said SS7 surveillance techniques are widely used worldwide, especially in less developed regions where cellular networks are less sophisticated and may not have any protection against tracking and interception. But the experts agreed that Americans are significant targets, especially of rival governments eager to collect intelligence in the United States and other nations where Americans use their cellphones.

Collins said his firm detected a surge in SS7 queries in US networks in late 2014 that it thinks was related to the Office of Personnel Management hack in which intruders — widely reported to be Chinese — gained access to the files of millions of federal workers, including in some cases their phone numbers. (Although publicly reported in 2015, the hack began at least a year earlier.)

AdaptiveMobile Security also detected an uptick in malicious SS7 queries this month in the Middle East, in the days after President Trump announced the U.S. withdrawal from the Iran nuclear agreement, Collins said. This surveillance probably was the work of intelligence agencies studying how the US move would affect oil prices and production, Collins said.

CTIA, a wireless industry group based in Washington, said carriers have worked to implement recommendations from federal officials to protect against SS7 surveillance. “The wireless industry is committed to safeguarding consumer security and privacy and collaborates closely with DHS, the FCC and other stakeholders to combat evolving threats that could impact communications networks,” CTIA said in a statement.

Firewalls installed by carriers in recent years block many of the malicious queries, but many others are successful in eliciting unauthorized information from cellular carriers worldwide.

“It does happen, and it does happen thousands of times a month,” said Karsten Nohl, a telecommunications security expert with Security Research Labs in Berlin.

The most advanced SS7 surveillance systems can monitor the movements of dozens of people for hours at a time, sending alerts if they get close to select areas or to one another, experts say.

German telecommunications researcher Tobias Engel first warned of the potential for SS7 surveillance at a security conference in 2008, during which he demonstrated how to locate a cellphone provided by a volunteer from the audience. Engel also located the cellphone of a Post reporter in 2014, at The Post’s request, for an article about the growing availability and effectiveness of such systems.

Researchers have continued to detail SS7 vulnerabilities in recent years, including call, data and text interception. A site reachable on Tor, an encrypted Internet browsing tool, offers SS7 tracking and interception of cellphones for a few hundred dollars a month.

Criminals last year used SS7 to intercept security codes that a bank texted to its customers in Germany, allowing the criminals to steal money from accounts, according to news reports.

Carriers worldwide have gradually added better security, but SS7 does not have any way to verify that carriers sending data requests are who they claim to be. The firewalls increasingly installed by carriers, meanwhile, protect their own customers but typically not people who are roaming on the network, said Engel, the German researcher who first reported the security and privacy risks of SS7.

“It’s much simpler to protect your own subscribers,” said Engel, now a researcher for GSMK, a mobile communications security company based in Berlin. “It could be that you’re vulnerable as soon as you enter somebody else’s network, domestic or foreign.”

Calls for an aggressive federal response grew after The Post’s 2014 article and a “60 Minutes” report in 2016 in which Nohl, one of the German researchers, demonstrated SS7 surveillance risks by intercepting a call to the cellphone of Rep. Ted Lieu (D-Calif.), with his permission.

DHS, which declined to comment for this article, issued a report on SS7 cellphone security in April 2017 that noted the risk to federal personnel: “SS7 attack types can be used to target key U.S. Federal Government personnel both in the United States and traveling or working overseas.”

The DHS report recommended that carriers adopt new protections. An FCC group, the Communications Security, Reliability and Interoperabilty Council, issued recommendations for improving SS7 security in March 2017 that US carriers have largely adopted.

But Wyden and some other officials say the government must do more to protect American cellphone users by documenting SS7 breaches and commissioning independent testing of the vulnerabilities in national cellular networks — a step that Britain and some other nations have taken.

“The FCC has been studying SS7 vulnerabilities for nearly two years. Enough,” said FCC Commissioner Jessica Rosenworcel, a Democrat. “It’s time for the agency to get serious and come up with a real plan to make sure that our networks are safe and secure.”

(The Washington Post)



SDAIA, World Bank Conclude Int’l Consultations on Data Governance and AI in Belgium and Germany

The program aimed to review leading international experiences in data governance, AI, and digital policy frameworks. SPA
The program aimed to review leading international experiences in data governance, AI, and digital policy frameworks. SPA
TT

SDAIA, World Bank Conclude Int’l Consultations on Data Governance and AI in Belgium and Germany

The program aimed to review leading international experiences in data governance, AI, and digital policy frameworks. SPA
The program aimed to review leading international experiences in data governance, AI, and digital policy frameworks. SPA

The Saudi Data and Artificial Intelligence Authority (SDAIA), in partnership with the World Bank, has concluded an international program held from June 8 to 12 in Belgium and Germany.

The program aimed to review leading international experiences in data governance, artificial intelligence (AI), and digital policy frameworks. It also included consultations with experts in both countries to exchange knowledge and expertise.

During the program, participants reviewed the Kingdom's experience in building a national ecosystem for data and AI. They also highlighted achievements in data governance, digital policy, and regulatory frameworks, as well as Saudi efforts to promote the responsible use of advanced technologies.

The program included a series of meetings and specialized sessions in Brussels and Berlin involving European and international entities, government and non-profit organizations, and think tanks focused on digital policy and AI governance.

Discussions covered international cooperation in AI, regulatory frameworks, data governance and privacy, and cross-border challenges associated with emerging technologies. Participants also examined frameworks that support responsible innovation and digital transformation.

SDAIA and World Bank teams reviewed advanced practices in digital policy development and the design of regulatory frameworks for data and AI. They also discussed mechanisms for strengthening international cooperation and knowledge exchange to support the development of a sustainable national ecosystem for data and AI.

The program is part of SDAIA's efforts to strengthen international cooperation and build partnerships with leading global organizations and institutions. It also seeks to benefit from international expertise and best practices in support of the Kingdom's objectives to strengthen its global position in data and AI.

The initiative aligns with the goals of Saudi Vision 2030 and the Year of AI 2026 and supports efforts to transfer knowledge and expertise to the Kingdom.


SpaceX: Five Key Moments, from First Launch to Starship Megarocket

SpaceX employees celebrate the company's Wall Street debut, the largest initial public offering in US history. TIMOTHY A. CLARY / AFP
SpaceX employees celebrate the company's Wall Street debut, the largest initial public offering in US history. TIMOTHY A. CLARY / AFP
TT

SpaceX: Five Key Moments, from First Launch to Starship Megarocket

SpaceX employees celebrate the company's Wall Street debut, the largest initial public offering in US history. TIMOTHY A. CLARY / AFP
SpaceX employees celebrate the company's Wall Street debut, the largest initial public offering in US history. TIMOTHY A. CLARY / AFP

More than 20 years after its founding, SpaceX made history Friday with its record-high stock market debut, crowning a unique journey marked by dazzling successes but also catastrophic failures and unfulfilled promises.

Here are five key moments in the company's history:

- 2008: The founding myth -

Six years after its founding, SpaceX launched its first rocket into orbit after multiple failures, taking off in September 2008 from a remote archipelago in the Pacific Ocean.

"I messed up the first three launches; the first three launches failed," co-founder Elon Musk recalled years later.

"Fortunately, the fourth launch -- that was the last money that we had -- the fourth launch worked, or that would have been it for SpaceX. But fate liked us that day."

- 2012: Next stop, ISS -

After the successful launch, SpaceX grew and developed more powerful launchers, including its flagship rocket, Falcon 9, which has become the most widely used rocket today.

Among its creations was the Dragon spacecraft, which docked as a cargo vessel at the International Space Station in 2012, a first by a private company.

Eight years later, the Dragon spacecraft carried its first astronaut to the ISS, beating other aerospace companies like Boeing to becoming the main American transport to the space station.

- 2018: A Tesla in space? -

At the same time, SpaceX in 2015 successfully landed the first stage of its Falcon 9 rocket, ushering in the age of partially reusable rockets.

This was followed by Falcon Heavy, a much more powerful launcher with two Falcon 9 boosters.

To mark its first test flight in 2018, Musk decided to place the car made by one of his other companies, a Tesla, on board.

The image of the red Tesla occupied by a mannequin dubbed Starman -- after David Bowie -- was seen around the world.

Not all SpaceX promises were kept though: that same year, Musk said he would send a group which included Japanese billionaire Yusaku Maezawa around the Moon by 2023, but that never came to pass.

- 2020-2023: Starbase's explosive beginning -

The tech trillionaire ended up prioritizing the development of his megarocket Starship, designed to travel to the Moon and, eventually, Mars.

To complete the project, he bought vast amounts of land in Texas and developed an industrial complex known as Starbase, where he would launch a series of Starship prototypes, most of which blew up into spectacular fireballs.

Musk justified the "rapid unscheduled disassembly" of these rockets, to use the entrepreneur's favorite euphemism for explosions, by saying they were part of the learning process.

- 2024: The unprecedented 'Super Heavy' catch -

In October 2024, SpaceX succeeded in recovering the first stage of Starship, its "Super Heavy" booster, in a unique maneuver that had never been achieved before.

After launching the spacecraft, the booster detached and began its descent, returning to the SpaceX launch pad where a pair of "chopsticks" reached out to catch the booster and bring it to a halt.

The feat, while impressive, is only the first part of SpaceX's plan to make Starship a fully reusable rocket -- a goal it remains in pursuit of while dealing with several technical challenges.


India Clears Way for Self-driving, Safety Car Tech to Reduce Road Deaths

A woman crosses street through a dust storm accompanied by rain in Jammu, India, Thursday, June 11, 2026.(AP Photo/Channi Anand)
A woman crosses street through a dust storm accompanied by rain in Jammu, India, Thursday, June 11, 2026.(AP Photo/Channi Anand)
TT

India Clears Way for Self-driving, Safety Car Tech to Reduce Road Deaths

A woman crosses street through a dust storm accompanied by rain in Jammu, India, Thursday, June 11, 2026.(AP Photo/Channi Anand)
A woman crosses street through a dust storm accompanied by rain in Jammu, India, Thursday, June 11, 2026.(AP Photo/Channi Anand)

India has scrapped a license requirement for radar sensors, freeing automakers to adopt technology that helps cars avoid crashes and drive themselves by sensing surrounding objects, in a bid to make some of the world's deadliest roads safer.

The world's third largest car market, India reported more than 177,000 deaths in nearly half a million ⁠road accidents in 2024, the ⁠latest figures show, according to Reuters.

In a notice on Thursday, the government waived the license requirement for radar sensors operating in the frequency band from 77GHz to 81 GHz. That lets companies ⁠enable the technology without the government having to separately assign the airwaves.

Automakers Maruti Suzuki, Tata Motors and Mahindra & Mahindra, stand to benefit from the change, as well the suppliers behind them, such as Germany's Bosch and Continental.

The radar sensors let a car gauge safe distances, and drive features such as emergency braking, adaptive cruise ⁠control ⁠and blindspot warnings, to form a basis for autonomous driving.

The change brings India in line with the United States, the European Union and a global telecoms standard, all of which dedicate the same frequency band to vehicle radar.

That lets carmakers and suppliers tap into the same off-the-shelf hardware worldwide, rather than having to build an India-specific version.