We know how to protect our troops from telecom attacks. We’re just not doing it.
As the fight with Iran intensifies, the revelation earlier this month, first reported by The Financial Times — that Iran is targeting U.S. military personnel via their smartphones — should not surprise us. The war in Ukraine has supplied numerous stories of both Ukrainian and Russian soldiers killed when their cell phones revealed their location. And yet, U.S. servicemembers in the Middle East will likely continue to use their cell phones, just like Ukrainian and Russian soldiers in Europe do.
I know, because a generation ago in the Iraq war, I was an Army Special Forces communications sergeant, tasked with keeping my team in contact with command. I carried over 100 pounds of radio equipment in my rucksack, but also always kept a cell phone in my pocket. Despite tens of thousands of dollars worth of communications gear, the thing I knew would always work every time I turned it on was my cell phone.
Cell phones have only gotten better since then, and adoption (including military adoption) has expanded. Commercial cellular is nearly everywhere, reliable, and woven into our lives. Even top U.S. officials — who have teams dedicated to hauling classified communications equipment — have gotten in trouble using their personal smartphones for sensitive communication.
Modern warfare, much like the rest of modern life, runs on commercial cellular networks, which work beautifully but are easily compromised by our adversaries. Moscow learned this when Ukraine piloted drones deep within Russia, using Russia’s own cellular networks to blow up billions of dollars of military aircraft. But Russia can’t permanently shut down its cellular network any more than we can get our soldiers to stop using cell phones.
Iran’s telecom attacks are not particularly new or inventive. Knowledge of the SS7 signaling attacks used by Iran has existed for decades. Members of Congress from both parties have repeatedly sounded the alarm through the years, and in 2024, an official at the Cybersecurity and Infrastructure Security Agency reported that “numerous” successful attempts have stolen location data, monitored voice and text messages, delivered spyware, and influenced American voters from abroad via text messages.
Signaling attacks leverage the machine-to-machine messages that telecom networks use to check that you pay your bill, verify your location, and route your call, message, or web traffic. Signaling happens in the background, invisible to users, and has connected global carriers for decades — think of it as a private system exclusively for telecoms. Telecom engineers designed the protocols that enable signaling in an era when only a small number of large telecoms could join the system, and the security model reflects that legacy. Today, thousands of entities have access, yet telecom protocols still accept any of their signaling messages as legitimate.
The result is that an attacker with access to the global signaling backbone, whether through a commercial lease or a compromised operator, can send messages that carriers worldwide treat as trustworthy. This lets them track a target’s location in real-time, intercept calls and texts, use fake phone numbers, and deny service. For the deployed service member, this means adversaries can quickly analyze their daily patterns and any changes to them — without installing malware, sending a phishing link, or leaving any trace on their device.
So what to do? Telecom network attacks are especially dangerous because users can’t protect themselves through better security habits or caution. Even if you turn off location sharing and put your phone on lockdown mode, your phone still has to connect to cellular networks in order to work. The design itself lets adversaries access it remotely. The solution requires not the individual, but industry, lawmakers, and the Pentagon.
First, the global telecom industry should tighten control over network access leased to poorly vetted third parties. Standards bodies should require transparency and safeguards for commercial leases to stop surveillance operators from acquiring legitimate credentials. When regulators find bad behavior, they should act fast to end those agreements.
Second, Congress and regulators should press major carriers to strengthen their defenses. Right now, they have little reason to fix their vulnerabilities. All major U.S. carriers have suffered breach after breach while facing no real consequences. To hold them accountable, carriers should publish security audits, report on their firewalls, and undergo yearly penetration tests. After the Chinese government’s “Salt Typhoon” hacks against major U.S. telecoms, Sens. Ron Wyden and Eric Schmitt demanded the government obtain carriers’ cybersecurity audits. The carriers refused — an unacceptable answer now that lives have been lost because the industry ignored this problem.
Third, the Department of Defense should equip our servicemembers with more secure cellular service. Cell phones will always be on the battlefield, and no training or procedures can fix a problem that requires no spyware or user error to exploit. Innovative technologies can address this vulnerability, but as I’ve previously called out, our soldiers cannot use them because the Pentagon locks in cellular service through a blanket, ten-year contract, Spiral 4, that was last renewed in 2024. The next chance to switch to something better won’t come until 2034.
This age of connected warfare with technically skilled adversaries like Iran, Russia, and China makes telecom infrastructure vulnerabilities a matter of life and death. We’ve known about this for decades, and industry, Congress, and the Pentagon can fix it. I know the comfort and the danger of that phone in my cargo pocket, and we must secure the network this generation of soldiers depends on.