Old Protocol, New War: How Iran Tracked US Military Phones Through a 1970s Telecom Flaw- 267
July 19, 2026
In the days surrounding the February air campaign against Iran, a wave of signals swept across Middle Eastern telecommunications networks seeking the precise location of specific mobile devices — a coordinated tracking campaign that multiple cybersecurity researchers and Western officials now believe targeted US military personnel and contractors stationed across the region, exploiting a telecommunications standard that has carried known security flaws for decades.
The technical mechanism at the center of the campaign is SS7, a signaling protocol developed in the 1970s that remains foundational to how mobile networks route calls and data across carriers internationally, and whose weak security has made it a persistent target for state-linked surveillance operations from Iran, Russia, and China alike. Gary Miller, who founded the Mobile Surveillance Monitor research initiative and also holds a senior research fellowship at Citizen Lab, detected a surge in SS7 location-request pings directed at devices across the region, concentrated in Gulf states including Bahrain where tens of thousands of US personnel are stationed. Two independent cybersecurity experts who reviewed the data told the Financial Times the pattern reflected deliberate, specific-device targeting rather than indiscriminate scanning, with at least some blocked tracking attempts traced to an Iranian mobile operator through a shared technical fingerprint. Nikita Shah of the Center for Strategic and International Studies characterized the campaign as marking a genuine escalation in Iranian cyber sophistication, distinct from the country's typically less advanced tradecraft relative to Russian or Chinese operations. The targeting extended beyond SS7 alone: separate reporting indicates Iran-linked actors also exploited commercial advertising-technology metadata and device identifiers, both to track individual phones without any direct network intrusion and, according to one account, to identify specific hotels housing US government employees and contractors in Iraqi Kurdistan — a technique that requires no compromise of the phone itself, only access to the legitimate commercial data streams that advertising networks already collect.

The institutional response reveals a gap between warning and acknowledged action. US Central Command told Congress in April that it had received multiple threat reports concerning adversaries exploiting commercial location data against US personnel, and separately stated it had implemented what it called unprecedented force-protection measures, while simultaneously telling reporters it had no evidence that location tracking played a significant role in any actual targeting of forces. That qualified position did not satisfy lawmakers: Senator Ron Wyden and Representative Pat Harrigan, joined by a dozen other members of Congress, sent a formal letter to the Defense Department in May raising concern that the military had not adequately protected personnel from these threats during the conflict, with Harrigan specifically calling for legislation to prevent data brokers from selling location data tied to government employees. When asked directly about the SS7 findings in July, a CENTCOM spokesman said he was not tracking such reports and declined to discuss defensive measures — a response that, set against the April congressional testimony acknowledging the threat reports existed, underscores how much of the government's actual defensive posture against commercial-data-enabled tracking remains undisclosed even to the legislators asking about it.

The campaign sits within a broader pattern of Iranian cyber activity that CISA separately flagged in April, when the agency warned that Iran-based attacks on US government services, water systems, and energy infrastructure had caused operational disruption and financial losses. It also connects to Handala, an Iran-linked hacking group that claimed in March to have breached the personal email account of FBI Director Kash Patel, publishing photographs and documents, then claimed in June to have compromised FBI drone systems and threatened the World Cup — activity serious enough that the State Department has since offered a $10 million reward for information identifying the group's members. Notably, the same phone-tracking playbook Iran is accused of deploying against US forces mirrors a technique Tehran has used domestically: following the lethal crackdown on protests that began the previous December, Iranian authorities used location data to identify and send intimidating messages to suspected participants, suggesting the underlying tracking capability was refined against Iran's own population before being turned outward against a foreign military presence in the same theater of operations.