WASHINGTON (Diya TV) — Mobile phone networks across the Middle East were repeatedly targeted in an apparent cyber campaign to track the locations of U.S. military personnel and contractors during the recent Iran conflict, according to a Financial Times report citing telecom data and multiple people familiar with the matter.
The suspected tracking attempts began in the buildup to the U.S.-Israeli assault on Iran in late February and continued into the early days of the war, as Tehran retaliated with missile and drone strikes against U.S. forces and installations across the Gulf region.
Data shared with the Financial Times by the Mobile Surveillance Monitor research project showed regional telecom networks fending off a surge of so-called SS7 pings — requests exploiting Signaling System 7, a decades-old set of protocols that handles subscriber calls, texts and roaming, to determine the approximate location of phones roaming outside their home networks. Two cybersecurity experts who reviewed the data said it suggested a coordinated campaign. A person familiar with the matter said Gulf officials suspected Iran or its allies of exploiting roaming agreements with local phone providers rather than relying solely on traditional cyber espionage methods.
Gary Miller, a senior research fellow at the cybersecurity watchdog Citizen Lab, who reviewed the data, said Iran has the technical capability to conduct such tracking. “Iran absolutely has capabilities to get real-time, immediate, and continuous location information,” Miller said. “It would surprise me very much if Iran were not using SS7, or mobile network access in the region, to track US users.”
Separately, a U.S. official told the Financial Times that actors linked to Iran had also abused commercially available smartphone advertising databases to track phones belonging to U.S. personnel in Iraq’s semi-autonomous Kurdistan region, exploiting location data harvested through ordinary mobile advertising technology.
During the conflict, Tehran and Iran-backed militias struck several hotels in Iraq, Bahrain — home to the U.S. Navy’s Fifth Fleet — and other locations across the Gulf, in some cases injuring U.S. contractors and personnel. Experts cautioned that further investigation would be needed to directly attribute specific attacks to the digital surveillance, noting that such tracking would represent only one of several possible intelligence streams used to locate targets, alongside human informants and personnel’s own hotel reviews or social media activity.
U.S. Central Command told Congress it had “received multiple threat reports concerning adversary exploitation of commercial location data to target or surveil US personnel in theatre.” A separate U.S. official pushed back on the report’s implications, saying any claim that data tracking played a significant role in the attacks “is a departure from the facts.”
The revelations have drawn a response from U.S. lawmakers. Rep. Pat Harrigan, R-N.C., said legislation is needed to prevent tech companies from selling location data tied to government personnel. Sen. Ron Wyden, D-Ore., said he has warned successive administrations for years about the national security risks posed by commercial location-data brokers.