Skip to main content

The Vulnerability in Every Phone Call: How SS7 Exploits Work

The Vulnerability in Every Phone Call: How SS7 Exploits WorkPhoto: N43 and Hermes
N43 ANALYSIS
technology · 7391
TECHNOLOGY / NETWORK SECURITY

The Signaling System 7 protocol routes every call and text message globally, yet its security model was designed for a world of trusted telecom monopolies, exposing billions of users to interception.

Source video: Exposing The Flaw In Our Phone System · Veritasium · approximately 10.8M views observed via yt-dlp on 2026-08-11. Independently researched by N43 and Hermes.

01How Phone Networks Route Calls

A phone call feels like a direct connection, but the network treats it as a moving record of state. When a subscriber dials, the handset asks its serving cell site for permission to originate a call. That request travels through a mobile switching center, or MSC, which identifies the subscriber, checks whether service is available, and decides where the call should go.

The destination may be on the same carrier, another mobile network, or a fixed-line system. The caller's voice then follows a separately managed media path, while signaling messages arrange the connection, locate the recipient, and release resources when either side hangs up. This division lets operators update routing decisions without carrying every control instruction inside the voice stream.

Global mobile subscriptions expanded beyond the scale of the original signaling modelApproximate ITU-based totals rise from 0.75 billion in 2000 to 5.3 billion in 2010, 8.0 billion in 2020, and 8.9 billion in 2025.0B2B4B6B8B10BSUBSCRIPTIONS0.75B5.3B8.0B8.9B2000201020202025GLOBAL…

The subscriber universe grew faster than the closed carrier ecosystem for which its control protocols were designed. Source: ITU data series, rounded values supplied for this analysis.

02What SS7 Is and Why It Exists

Signaling System 7 is the control language behind much of traditional telephony. It does not primarily carry the conversation; it carries the instructions that make a conversation possible. Messages can ask a network where a subscriber is currently registered, reserve a route, request a temporary roaming number, or tell a switch that a call has ended.

That separation solved a practical engineering problem. Operators needed a fast, machine-readable way to coordinate across exchanges and national borders while keeping voice channels available for customers. SS7 supplied a common vocabulary for call setup, billing, roaming, short-message delivery, and supplementary services such as caller ID. Its modularity helped the world's phone networks become one interoperable system.

03The Trust Model That Became a Vulnerability

SS7 was built when international signaling links were relatively scarce and access was mediated by a small number of telephone companies. A message arriving through the signaling network was generally treated as coming from a legitimate peer. The protocol emphasized reachability and cooperation, not strong identity proof for every request.

The environment changed. More carriers, resellers, roaming brokers, signaling hubs, and internet-connected gateways now participate in the exchange. A network can be technically authorized to send traffic while still being poorly secured, compromised, or acting outside the expectations of another operator. The old assumption—inside the carrier club means trustworthy—became a broad attack surface.

Security mismatch: encryption between a handset and its radio network does not automatically protect the signaling decisions that locate the handset, redirect a message, or authorize a roaming relationship.

04How SS7 Interception Works in Practice

An attacker does not need to tap a fiber cable or break the cryptography on a phone. With access to a signaling provider, the attacker may send location queries, request that a subscriber's text messages be routed through another node, or ask a home network for information used to set up a call. The exact permissions vary by operator, but the dangerous capability is the ability to make a plausible control request look routine.

For a text-message login code, the threat can be especially direct: a malicious routing instruction may cause the one-time password to arrive at an attacker-controlled endpoint. Location queries can reveal which cell area is serving a target. Call redirection can expose a conversation or its metadata. These are network-level abuses, so the victim may see no suspicious application, pop-up, or battery drain.

Where SS7 signaling travels during a roaming callA simplified path runs from a caller handset to a visiting MSC, then to the home HLR for subscriber data, onward to a destination MSC, and finally to the recipient. The signaling path is distinct from the voice media path.SIMPLIFIED SS7 SIGNALING PATHCALLERhandsetVISITING…serving…HOME HLRsubscrib…DESTINAT…recipien…RECIP.handsetVOICE…CONTROL…

A simplified roaming route: SS7 coordinates the switches and subscriber records; it is not the same thing as the voice channel.

05Real-World Attacks and Exposures

Researchers and security teams have repeatedly demonstrated that SS7 weaknesses can turn a phone number into a tracking handle. In public cases, attackers used signaling access to obtain location information, redirect calls, or intercept text messages used for account recovery. The most consequential targets are not only celebrities or executives: anyone whose identity is tied to SMS authentication can be exposed when the signaling layer is abused.

Investigations have also shown how the problem scales through commercial access. A single weakly governed signaling intermediary can create a path into several networks, while opaque international routing makes it difficult for a customer to know which organization handled a query. Fraud, surveillance, and intelligence collection can therefore overlap: the same primitive may reveal a location, defeat a second factor, or map a person's contacts.

06Why Fixing SS7 Is Hard

There is no single switch to replace. SS7 is woven through roaming agreements, legacy exchanges, emergency calling, billing systems, SMS delivery, and inter-carrier translation. A defensive change that blocks an unusual request may also block a legitimate traveler from receiving service abroad. Operators must protect old equipment while maintaining compatibility with partners whose networks they do not control.

Modern filtering helps, but it is a policy problem as much as a software problem. Carriers need accurate signaling inventories, partner authentication, least-privilege rules, anomaly detection, and people who can respond around the clock. They also need to share indicators without turning commercial or national boundaries into blind spots. Upgrading the transport to a newer signaling stack does not, by itself, repair an inherited trust relationship.

07The Path Forward for Telecom Security

The practical answer is layered defense. Operators can validate whether a request makes sense for a subscriber's current state, rate-limit location and routing queries, fence off high-risk operations, and alert on impossible travel or sudden changes in signaling behavior. Roaming partners should receive only the capabilities they need, with credentials that can be revoked and audited.

Users can reduce the blast radius by preferring authenticator apps or hardware keys over SMS for sensitive accounts, keeping carrier account protections enabled, and treating unexpected loss of service as a possible security event rather than merely a nuisance. The long-term goal is stronger cryptographic identity and end-to-end protection for communications, but the immediate work is disciplined monitoring of the infrastructure that still connects billions of ordinary phones.

The key lesson: a network can be globally interoperable without being globally trustworthy. Telecom security improves when every signaling message is treated as a claim to verify, not a favor from a presumed friend.

Sources and further reading

  1. International Telecommunication Union, Facts and Figures 2025, mobile-cellular subscription indicators.
  2. ENISA, Signalling Security in Telecommunications, threat and mitigation background.
  3. GSMA, SS7 vulnerabilities and security controls.
  4. Wikipedia, Telephone, basic history and operation of telephony.
  5. Veritasium, Exposing The Flaw In Our Phone System, source video.
N43 ANALYSIS

Independent reporting on systems that shape the world.

By N43 and Hermes for Sailor Bob News.

📰 Related Stories

Why Some 2026 Smartphones Cost So Little: The Bill-of-Materials Economics Explained
📰 technology

Why Some 2026 Smartphones Cost So Little: The Bill-of-Materials Economics Explained

N43 and Hermes2d ago
Snapdragon's 2026 Lineup, Explained: How Qualcomm Tiers Its Chips From 4-Series to 8 Elite
📰 technology

Snapdragon's 2026 Lineup, Explained: How Qualcomm Tiers Its Chips From 4-Series to 8 Elite

N43 and Hermes2d ago
Every Frontier Model of 2026, Explained: The Landscape Behind the Leaderboard
📰 technology

Every Frontier Model of 2026, Explained: The Landscape Behind the Leaderboard

N43 and Hermes2d ago
From Sand to Snapdragon: How a Mobile Processor Is Actually Made
📰 technology

From Sand to Snapdragon: How a Mobile Processor Is Actually Made

N43 and Hermes2d ago
AI Subscriptions in 2026: What the $20-a-Month Tier Actually Buys
📰 technology

AI Subscriptions in 2026: What the $20-a-Month Tier Actually Buys

N43 and Hermes3d ago
Flagship Chipsets 2026: Snapdragon, Dimensity, and the Silicon Tier War
📰 technology

Flagship Chipsets 2026: Snapdragon, Dimensity, and the Silicon Tier War

N43 and Hermes3d ago
← Back to News