The Iranian government successfully tracked the locations of US military personnel in the Middle East during the onset of the Iran War by exploiting critical vulnerabilities in global telecommunications networks, according to the Financial Times.
How Tehran exploited the SS7 protocol
Tehran reportedly manipulated Signaling System 7 (SS7), a legacy suite of protocols designed for 2G and 3G networks. SS7 serves as the global routing backbone, enabling cellular networks to connect with one another to direct subscriber calls and text messages across international borders. Citing data from the Mobile Surveillance Monitor and anonymous government officials familiar with the espionage campaign, the newspaper revealed how the regime turned this global infrastructure into a tracking tool.
While SS7 has historically been abused by state intelligence agencies to track mobile devices operating overseas, this specific campaign demonstrates its highly destructive potential when weaponised in active conflict zones.
US troops targeted in Middle East bases and hotels
By leveraging these network vulnerabilities, Iranian operatives pinpointed the exact locations of US military forces deployed at various bases and hotels across Iraq, Bahrain, and other Middle Eastern nations. This precise geolocation data enabled the regime to coordinate targeted strikes against these positions, which ultimately caused several casualties and injuries among American service members.
Leveraging adtech for covert surveillance
In addition to exploiting SS7 routing protocols, Iran utilised commercial advertising technology to monitor troop movements. By abusing the digital adtech ecosystem—typically used to deliver personalised advertisements to mobile users—the regime capitalised on another well-documented surveillance vector embedded within everyday consumer technology.
