Counterintelligence & Tradecraft — 2026-05-03

Citizen Lab Report Reveals Israeli Telecom Infrastructure Weaponized for Global Surveillance

Citizen Lab published a report on April 23 identifying two surveillance campaigns that exploited SS7 and Diameter telecom protocols to track targets across more than ten countries from late 2022 through 2025. The first campaign logged more than 500 tracking attempts routed through Israeli carriers 019Mobile and Partner Communications, both of which denied involvement; Citizen Lab assessed that the operators' network identities may have been forged to gain access. The second campaign, attributed to Swiss firm Fink Telecom Services, used hidden SMS commands to trigger SIM cards into silently reporting device location, with Citizen Lab logging more than 15,700 such attempts. Citizen Lab researcher Gary Miller told The Record that routing analysis in both campaigns traced the signaling traffic to Israel.

Analysis
SS7 and Diameter exploitation has matured into industrialized commercial surveillance infrastructure. The more consequential disclosure is carrier identity spoofing: if licensed carrier identities can be forged, lawful intercept safeguards break at the protocol layer, not just the policy layer. Per a single Citizen Lab research group lacking independent corroboration, the Israeli routing signature may instead reflect transit arbitrage: operators selecting lighter-regulated carrier paths without carrier knowledge. A formal European investigation or enforcement action before October 2026 is possible, though regulators have documented these vulnerabilities since 2014 without binding action, and the political cost of confronting a security-sector-embedded surveillance industry has not shifted.
1 sources
  1. Ghost Operators: How Israeli telecoms were exploited to track citizens worldwide - Haaretz

View in full brief →

UNCLASSIFIED // OPEN SOURCE