TechNewsReel
Live

Iran Used Cellular Network Flaws to Track US Military Phones in 2026 Conflict

Citizen Lab and Financial Times report reveals Tehran exploited SS7 signaling and ad tech to locate US personnel across the Middle East.

TechNewsReel Newsroom · July 24, 2026

Iran exploited vulnerabilities in global cellular infrastructure to track the real-time locations of US military personnel and contractors throughout the 2026 conflict, according to a Financial Times report on July 14, 2026, and analysis from the University of Toronto's Citizen Lab published July 17, 2026.

The surveillance campaign began in the weeks leading up to the US-Israeli military operation against Iran in late February 2026 and continued during the conflict, leveraging weaknesses in SS7 signaling systems that govern how mobile networks route calls and messages across borders.

Network-Level Exploitation

Unlike traditional hacking that requires malware on a target device, the Iranian operation queried telecommunications infrastructure directly to locate phones roaming on Middle Eastern networks. The Mobile Surveillance Monitor project detected coordinated SS7 ping campaigns targeting devices connected to regional carriers.

"Iran absolutely has capabilities to get real-time, immediate, and continuous location information," said Gary Miller, Senior Research Fellow at Citizen Lab and founder of the Mobile Surveillance Monitor project. "It would surprise me very much if Iran were not using SS7, or mobile network access in the region, to track US users."

At least some tracking attempts were linked to an Iranian mobile phone operator, indicating targeted user surveillance rather than broad data collection.

Ad Tech Component

Beyond cellular signaling exploits, Iran also tapped commercial advertising technology and location data brokers to identify US troop locations. This dual approach—combining telecom infrastructure vulnerabilities with commercially available location data—created multiple pathways for tracking military personnel.

US Central Command acknowledged receiving threat reports about adversary exploitation of commercial location data to target US personnel. However, US officials have disputed claims that the tracked data directly enabled or guided specific Iranian missile or drone strikes on US facilities, calling such assertions "a departure from the facts."

Operational Security Implications

The revelations underscore a critical vulnerability in global telecommunications: state actors can bypass device-level security entirely by weaponizing the network infrastructure itself. Standard mobile phone usage by military personnel in conflict zones poses significant operational security risks, even when devices are properly secured against malware.

For US forces operating in the Middle East, the incident highlights the limits of conventional cybersecurity measures when the telecommunications backbone itself becomes an intelligence collection tool.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.