Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > US Military Personnel Targeted Through SS7 Mobile Tracking During Iran Conflict

US Military Personnel Targeted Through SS7 Mobile Tracking During Iran Conflict

By: Morgan Cipher Senior Privacy Journalist

Last updated: July 16, 2026

Human Written
US Military Personnel Targeted Through SS7 Mobile Tracking During Iran Conflict
  • Attackers reportedly tried to track US military personnel by sending location requests through mobile roaming systems during the Iran conflict.

  • Officials also suspect actors linked to Iran abused commercial advertising data to locate US government staff and contractors.

  • Lawmakers say the incidents highlight growing security risks tied to smartphones, mobile networks, and location data.

Attackers reportedly tried to track the phones of US military personnel and contractors during the recent conflict involving Iran. The activity targeted people using mobile networks across the Middle East. The suspected tracking attempts happened before the fighting began and continued during the early days of the conflict.

According to information shared with the Financial Times, telecom data showed repeated attempts to locate specific smartphones connected to regional mobile networks. Security experts who reviewed the data said the activity appeared organized and focused on selected targets.

The reported tracking attempts happened before the United States and Israel carried out military operations against Iran in late February. The activity also continued after Iran responded with missile and drone attacks against US forces and military sites across the region.

The reports have raised concerns among American lawmakers. Some believe weaknesses in international mobile roaming systems and smartphone advertising technology could expose military personnel to surveillance.

Mobile Network Requests Raised Security Concerns

The telecom data came from the Mobile Surveillance Monitor research project. It showed a sharp rise in requests called SS7 pings. These requests can help determine the rough location of a mobile phone while it is connected to a foreign network.

Two cybersecurity experts who examined the data said the pattern suggested a coordinated effort to track certain devices instead of random network activity. One person familiar with the matter said Gulf officials believed Iran or groups linked to Iran may have used roaming agreements between mobile providers to send those location requests.

A separate US official, who spoke anonymously, also said they believed actors connected to Iran had used commercial advertising databases to follow smartphones in Iraqi Kurdistan. Gary Miller, a senior research fellow at Citizen Lab, reviewed the telecom data. He said Iran already has the tools needed to collect live location information from mobile devices.

According to Miller, it would be surprising if Iran did not use SS7 or access to regional mobile networks to monitor US users. He also said the evidence pointed to very targeted surveillance instead of broad network scanning. He added that the activity appeared focused on specific users because the attackers seemed to follow selected devices rather than searching for large numbers of phones.

Amid the conflict, groups that support Iran and the country itself launched attacks against various locations all over the region. Some strikes hit hotels in Bahrain, Iraq, as well as other Gulf countries. In several cases, US contractors and military personnel suffered injuries.

Security experts said more work is still needed before linking any individual attack directly to digital tracking. Military targets can also be identified through human sources, social media, hotel reviews, and other intelligence.

Still, US Central Command told Congress in April that it had received several threat reports about enemies using commercial location data to monitor or target US personnel in the region. Sen. Ron Wyden said he had warned Republican and Democratic administrations about this risk for years.

The targeting of US interests is also evident in the cyberattack on a major hotel chain, where NightSpire released internal data on the dark web.

Wyden said foreign rivals tracking the phones of American personnel had remained a serious national security concern for a long time. He added that this could be the first reported case where commercial location data may have helped target US personnel during a war.

US Central Command said it introduced special force protection measures to keep its personnel safe. Officials said they could not discuss those measures publicly. Another US official also pushed back against suggestions that location tracking played a major role in the attacks. The official said those claims did not match the known facts.

Advertising Data Created Another Possible Tracking Risk

SS7 is part of the older technology that supports mobile phone networks. It allows mobile operators and others with approved access to exchange information needed for international roaming. Iranian mobile providers have roaming agreements across parts of the Middle East.

Those agreements give them the technical ability to send SS7 requests outside their own country. Wyden has previously pointed to a presentation from the US Department of Homeland Security that identified Iran among the countries known for using SS7 to target US mobile subscribers.

Miller said at least some blocked tracking requests appeared connected to an Iranian mobile operator. He said the requests shared technical characteristics that matched other known activity. The Iranian embassy in London did not immediately respond to requests for comment. During the conflict, the US moved some personnel away from major military facilities. Many stayed in hotels or smaller locations to reduce the risk of attack.

One example involved the Crowne Plaza hotel in Manama, Bahrain. The hotel has received contracts to provide lodging, laundry, and other services for the US Department of Defense. During the conflict, a missile struck the hotel.

A spokesperson for Bahrain said the country’s telecom systems remained strong despite constant threats. The spokesperson explained that all mobile operators must use firewalls and other security measures to protect their networks. The spokesperson also noted that attempts to break into telecom systems happen around the world every day.

Officials also suspected another form of surveillance during the conflict. One person familiar with the matter said Iran may have used commercial advertising software to identify hotels where US government employees and contractors were staying in Iraqi Kurdistan.

Advertising systems collect information from smartphones so companies can deliver targeted adverts. Those systems often rely on advertising IDs that device makers assign to phones. For years, those identifiers have allowed organizations to estimate the location of a single phone or even groups of devices.

Lawmakers Push for Better Protection

Pat Harrigan, a Republican member of the House Armed Services Committee, said he had not received briefings about specific cases involving Iran. Even so, he said the reported threat remained serious. Harrigan said the ability already exists to misuse this type of data. He warned that if attackers continue taking advantage of it correctly, the results could become disastrous.

He is now proposing legislation that would stop technology companies from selling the digital location records of US government employees. A 2024 review by the Department of Defense Office of the Inspector General found that the US military had not fully closed this security gap on phones issued to service members.

Michael Stokes, a former CIA official and now vice president at Veilant, said intelligence agencies have dealt with this issue for more than ten years. He explained that attackers do not always need to break into a smartphone. Modern devices constantly produce information during normal use. That information can reveal where people travel, who they contact, and even how much they move.

Stokes also said many government employees choose to carry their personal smartphones instead of relying only on secure government devices. Some even carry both phones at the same time. That can leave extra digital clues behind.

According to Stokes, this problem comes from several risks meeting at once. He said unmanaged phones, commercial advertising systems, location data, and the realities of military operations have combined to create a serious national security concern.

Share this article

About the Author

Morgan Cipher

Morgan Cipher

Senior Privacy Journalist

Morgan combines a journalist’s curiosity with a security specialist’s precision. His reporting on data breaches, privacy laws, and encryption tech has been featured in several tech publications. At TorWire, he focuses on real-world threats and how to counter them, always with an eye on what’s next in digital privacy.

Comments (0)

No comments.