Iran used unsecured smartphone and ad tech data to target US troops
Iran may be tracking concentrations U.S. troops across the Middle East using a telecommunications vulnerability that security researchers have been screaming about for more than a decade, according to reporting from the Financial Times.
Iranian intel came from a standard practice in the global phone network, first implemented in the 1970s, and a secondary exploit built from the same advertising software that decides which ads follow you around the internet.
Together, they gave Iranian military intelligence a real-time map of where American service members were operating and the Defense Department was informed about it as a potential weakness.
“Iran absolutely has capabilities to get real-time, immediate, and continuous location information,” Gary Miller, a senior research fellow at Citizen Lab, told the Financial Times. “It would surprise me very much if Iran were not using SS7, or mobile network access in the region, to track U.S. users.”
He added that the campaign was “very specific user targeting” and that at least some of it could be traced directly to an Iranian mobile phone operator.
The SS7 Protocol
SS7, or Signaling System 7, is the protocol that makes your phone work across borders. It’s how a call gets routed in other countries, how a carrier knows where its customers are, and how SMS messages find devices anywhere on the planet.
It was also built without a single security mechanism. Its vulnerabilities include zero authentication or encryption, meaning there’s no way to verify that the entity sending commands into the network is who it claims to be.
The nonprofit cyber rights advocate Electronic Frontier Foundation warned the FCC in 2024 that the protocols were designed when the telecom industry was a small club of regulated monopolies that all trusted each other, so nobody would think to add safeguards to the system.
Today, hundreds of mobile operators are interconnected through SS7, along with a web of third-party roaming hubs, messaging aggregators, and virtual network providers, all of which connect to it to run legitimate commercial services. But the honor system that once governed the exchange is a relic of a bygone era.
SS7 can’t tell a legitimate carrier from a hostile intelligence service. If you get access to the network, you can send queries to locate any phone, anywhere in the world, by its number. You can find out which cell tower it’s connected to. You can redirect calls. You can intercept texts. And you can do all of it while appearing, to every network you’re querying, to be a legitimate carrier with a routine reason for asking.
Access to the SS7 network comes through something called a Global Title, a unique identifier assigned to network equipment. Carriers have them, and some lease theirs to third parties. That’s how malicious actors obtain access through commercial arrangements, sometimes without the leasing carrier knowing what it’s being used for.
Once inside, you can find anyone’s physical location with just a phone number.
At least a Decade of Vulnerability
In 2016, mobile security expert John Hering and German researcher Karsten Nohl live-tracked a smartphone the newsmagazine “60 Minutes” lent to Congressman Ted Lieu, using nothing but the phone number and SS7 access. The telecom industry watched it happen, but did nothing about it.
By 2022, it spread to the United States. Kevin Briggs, the top telecom vulnerability expert at the Cybersecurity and Infrastructure Security Agency (CISA), filed comments with the FCC documenting confirmed SS7 exploits on American soil: one subscriber tracked via a Provide Subscriber Information attack in March 2022, three subscribers tracked via Send Routing Information packets in April 2022.
Briggs told the FCC he had additional classified information about further exploits, including attacks that intercepted message content, delivered spyware to devices, and attempted to interfere with elections.
In 2023, Citizen Lab documented millions of SS7 location queries, sent multiple times per hour, every day, for months, targeting Saudi users traveling inside the United States. The requests came from Saudi network infrastructure, and all went through without being blocked.
When the FCC asked Verizon, T-Mobile, AT&T, and their lobbying group, CTIA, about SS7 security in 2024, they all said the same thing: firewalls were working fine, no audit was needed, and no oversight was required.
Oregon Sen. Ron Wyden even wrote a letter to the Biden Administration alleging that CISA was actively hiding information about SS7 threats from the American people.
“For the last decade, cybersecurity researchers and investigative journalists have highlighted how wireless carriers’ failure to secure their networks against rogue SS7 and Diameter requests for customer data has been exploited by authoritarian governments to conduct surveillance,” he wrote.
Then, in April 2026, Citizen Lab published a technical report documenting two long-running surveillance campaigns that used SS7 and its 4G cousin, the Diameter protocol, to conduct persistent location tracking of high-value targets. The campaigns ran infrastructure through operator networks in more than a dozen countries—the UK, Israel, China, Thailand, Sweden, and others—using customized tools designed to spoof legitimate carrier identities and route traffic through trusted network paths to evade detection.
“These vulnerabilities are not the result of software bugs or network misconfigurations,” the report, called “Bad Connection,” concluded. “Rather, they are inherent to global telecommunications design and business practices.”
The person being tracked has no idea it’s happening. It occurs entirely at the network level and is invisible to the target.
Iran Bought the Data Legally
SS7 was one tool. The other was cheaper, and more accessible. Worse yet, it’s watching everyone with a smartphone all the time.
Every free app on your phone is monetized through advertising, but serving you relevant ads requires knowing where you are. Your phone’s operating system (Android or iOS) assigns your device a unique advertising ID. Every time an app shows you an ad, that ID and your approximate location get transmitted to a chain of advertising brokers and data aggregators who buy, package, and resell it.
The end product is a historical record of everywhere your phone has been, sold commercially to anyone willing to pay.
This is all completely legal. Any entity can buy the data: There’s no background check, and no mechanism requires a data broker to verify that the buyer isn’t a foreign military using it to find targets. The U.S. even does the same thing: Customs and Border Protection admitted earlier this year that it used location data from internet advertising.
In Iraqi Kurdistan, after U.S. forces evacuated their main bases and relocated to hotels and civilian office spaces in the early days of the Iran War, Iranian military intelligence used that commercial location data to determine exactly which hotels were housing American troops. Some experts believe that the personnel’s own hotel reviews and social media posts could account for the hotel targeting, however.
The Pentagon Was Aware
In April 2026, a classified Defense Department document confirmed that adversaries were actively using commercial location data against U.S. personnel in an active war zone. Senator Wyden made the memo and its content public.
“Commercial location data can be used to identify where U.S. troops congregate and their pattern of life,” Wyden wrote, “which can be exploited by adversaries to target attacks such as missiles, drones, and roadside bombs.”
He said that DoD leadership had “failed to prioritize this threat and implement common sense cyber defenses recommended by federal cybersecurity experts” for more than a decade.
On May 28, 2026, in the middle of the Iran War, Wired reported that the Department of Defense had been warned for a decade by its own contractors, analysts, and intelligence community that commercial data brokers were selling location trails detailed enough to map the movement patterns of American service members. The Pentagon still did nothing.
A bipartisan group of 14 members of Congress (including Wyden) wrote to Pentagon chief information officer Kirsten Davies with three asks: turn off the advertising ID on military phones, replace Chrome with a privacy-protective browser on government devices, and enroll service members in data broker opt-out programs. All three measures have been recommended by federal cybersecurity experts for years.
A U.S. official told the Financial Times that any claim of data tracking playing a significant role in attacks “is a departure from the facts,” while CENTCOM said only that it took force-protection measures it wouldn’t discuss further.
This Is a Problem for Everyone
Every person carrying a smartphone is vulnerable to SS7 exploitation. Criminal organizations have used it to intercept two-factor authentication codes and drain bank accounts. Authoritarian governments use it to track journalists and dissidents. Intelligence services around the world use it as a standard information collection source.
Data brokers sell location history to whoever pays. Hedge funds use it for economic forecasting. Retailers use it to measure foot traffic. By flooding regional mobile networks with these location requests (also known as “pings”), Iran was able pinpoint which cell towers roaming American devices were connecting to. All it needed was American phone numbers in the Middle East and a credit card.
Don’t Miss the Best of We Are The Mighty
• How this Air Force veteran allegedly spied for Iran • How Iran was able to bruise the US Navy’s 5th Fleet • The F-35 made historic air-to-air kills against Iran
Iran used unsecured smartphone and ad tech data to target US troops
The ‘Maverick Act’ could see an American F-14 Tomcat in the sky once more
American troops drank 2 million energy drinks during Operation Epic Fury
Sailors relive the 1980s ‘Tanker War’ amid today’s Hormuz Crisis
Amos Chapple, Radio Free Europe/Radio Liberty
Ukraine’s JEDI drone hunts Shaheds so your Patriot missiles don’t have to