Skip to main content
Threat IntelligenceEmerging Threats

US Military Left Vulnerable to Telecom Attacks

Telecommunications equipment array on a cell tower against a daytime sky.

"Numerous" successful attempts have stolen location data, monitored voice and text messages, delivered spyware, and influenced American voters from abroad via text messages, an official at the Cybersecurity and Infrastructure Security Agency reported in 2024.

SS7 signaling and the global signaling backbone

The vulnerability at the center of these incidents is not a new malware strain or a zero-day exploit; it is the signaling system that underpins global telephony. Signaling is the machine-to-machine traffic telecom networks use to check billing, verify location, and route a call, message, or web session. Designed in an era when only a handful of large carriers connected to the backbone, those protocols implicitly trusted any participant. Today, thousands of entities can access the signaling system, yet the protocols still accept their messages as legitimate.

That mismatch — outdated security assumptions plus broad access to the backbone — means an attacker with access to the global signaling network, whether via a commercial lease or a compromised operator, can send messages carriers will treat as authoritative. The practical effects include real-time location tracking, interception of calls and texts, spoofed phone numbers, and denial-of-service on target devices, all without installing malware or leaving traces on the handset.

Iran's telecom attacks, Ukraine lessons, and the Financial Times report

Earlier this month, The Financial Times reported that Iran is targeting U.S. military personnel via their smartphones. The broader pattern has precedent: the war in Ukraine supplied multiple reports of Ukrainian and Russian soldiers killed when their cell phones revealed their locations, and Moscow faced a tactical reckoning when Ukraine piloted drones deep inside Russia using Russia’s own cellular networks to destroy billions of dollars of military aircraft.

The author of this piece — a former Army Special Forces communications sergeant who carried both hundreds of pounds of radio gear and a personal cell phone in theater — underscores the operational reality: commercial cellular networks are nearly everywhere, reliable, and embedded into modern combat. That ubiquity makes the signaling backbone a high-value target for technically skilled adversaries.

Carriers, Congress, and regulators: audits, breaches, and "Salt Typhoon"

U.S. carriers have been breached repeatedly, yet the source material notes they have faced "no real consequences." Lawmakers and regulators have sounded alarms across multiple years. After what the source calls the Chinese government's "Salt Typhoon" hacks against major U.S. telecoms, Senators Ron Wyden and Eric Schmitt demanded the government obtain carriers' cybersecurity audits — a request the carriers refused, the source reports.

The proposed remedies in the reporting are procedural and transparency-driven: require carriers to publish security audits, report firewall posture, and submit to annual penetration tests. Standards bodies should also require transparency and safeguards for commercial leases so surveillance operators cannot obtain legitimate signaling credentials. When regulators identify bad behavior, the recommendation is decisive action to terminate problematic agreements.

The Pentagon's Spiral 4 contract and procurement constraints to 2034

The Department of Defense, the piece argues, must provide more secure cellular service for deployed servicemembers. But procurement choices have locked in the status quo. The Pentagon secured a blanket ten-year cellular contract, Spiral 4, last renewed in 2024, the source says — a contract that prevents switching to alternative or improved cellular solutions until 2034. That procurement cadence, according to the author, leaves troops reliant on the existing commercial model even as adversaries exploit signaling-layer vulnerabilities that require no user mistake to attack.

What this means for technologists, Congress, and the Department of Defense

  • Technologists and security teams: Expect attacks that exploit network-level trust, not device-level user behavior. The source suggests that defensive work should focus on controlling access to signaling credentials, auditing leases, and staging regular penetration tests of carrier networks.
  • Congress and regulators: The reporting recommends pressing carriers to accept audits and transparency, and using regulatory authority to terminate risky commercial leases. Senators Ron Wyden and Eric Schmitt are cited as having already sought carriers' cybersecurity audits after "Salt Typhoon."
  • The Department of Defense and procurement leaders: Spiral 4's ten‑year lock-in, renewed in 2024, constrains immediate options. The source urges the Pentagon to pursue more secure cellular services for servicemembers and to avoid procurement timelines that institutionalize vulnerable systems.

The problem the author describes is structural, not cultural: turning off location sharing and tightening personal phone habits does not fix a signaling backbone that will accept a malicious message as legitimate. The remedies proposed are likewise structural — tighter controls on access to signaling credentials, mandatory carrier audits and tests, and procurement that allows the Department of Defense to field more secure commercial cellular alternatives sooner than 2034.

The record in the source is blunt: the vulnerabilities have been known for decades; warnings have gone unheeded; and the tools to harden networks exist. The remaining question the reporting leaves on the table is who will act with the speed and authority the author and the cited officials say the problem requires — industry, Congress, or the Pentagon.

Read the original story