BroadForward SEPP powers the world’s first live 5G standalone roaming connection
Achieving the highest GSMA recognition as the leading signaling experts
World-class signaling products: when progress matters to you
Providing network functions to the world’s leading MNOs, MVNOs, IoT, MNP and IPX providers

Industry perspectives: The Ghost in the machine: Why Telecoms can no longer trust the past

The Global System for Mobile Communications, the invisible infrastructure underpinning our digital lives, was built on a foundation of trust. Decades ago, when national telephone companies were the only players, the Signaling System No. 7 (SS7) protocol was designed as a closed-off handshake between trusted partners. It was a gentleman’s agreement, never intended to be part of a bigger centralized information network such as 4G or 5G. Today, this legacy of trust is the gaping security hole that puts every mobile user at risk irrespective of the generation of a telecom network they reside on.

The commercial rollout of SS7 in the early 1990s gave us the world of global roaming and instant SMS, but some of its inherent, decades-old security flaws have persisted, transforming an essential network bridge into the weakest link in our global security chain. Even as the industry marched toward 4G (Diameter) and now 5G (HTTP/2), SS7 remains an indispensable bridge, vital for ensuring everyone can call and text across borders. This essential reliance is precisely why its vulnerabilities are a persistent global threat.

The chilling investigative work of Lighthouse Reports recently provided yet another undeniable proof that this threat is not hypothetical, but a deeply weaponized reality. Through a meticulous journalistic collaboration, Lighthouse exposed a surveillance firm, First Wap, that had built a global tracking software application which did not need to hack networks; the software simply exploited the protocol’s flawed design and allowed its users to take advantage of their findings. And those primary users and targets of the surveillance tools were various national governments and intelligence agencies, often in countries with poor human rights records.

The enemy within

The method was insidious in its simplicity: First Wap acquired valid SS7 access credentials – in some cases, leased from a seemingly trusted EU-based operator. Using these credentials, their tool, Altamides (acronym for Advanced Location Tracking and Deception System), launched a flurry of secret signaling messages, such as “Any Time Interrogation” or “Provide Subscriber Info,” to target networks worldwide. A phone network, built on that decades-old principle of trust, blindly processed the request, assuming it came from a legitimate phone company needed to address any of its subscribers. The reply: A simple Cell ID, which the surveillance firm instantly converted into precise latitude and longitude coordinates, revealing the phone’s location. The victim never saw a notification; the attack left no trace on their device.

The result of this mass exploitation was a vast and dangerous database of surveillance intelligence, a dataset that Lighthouse reports confirm was later weaponized, used to target individuals for everything from digital attacks to assassinations. The network designed to connect the world was being used to track and endanger its citizens.

Gaping security hole

This exposure makes it painfully clear that the industry’s response to SS7’s vulnerabilities can no longer be voluntary or half-hearted. The GSMA, the mobile industry’s governing body, has long recognized this threat, stressing the need for active monitoring and the mandatory implementation of a dedicated SS7 firewall at every network edge (as detailed in their FS.11 guidelines). However, as Lighthouse warns, even a basic firewall is not enough when rogue requests are cleverly engineered to look legitimate, often originating from Global Titles (GT) that are technically “trusted.” Spotting the difference requires the latest standard in protection.

The modern challenge is to move beyond simple GT filtering to deploy a sophisticated guardian capable of multi-layered, cross-referencing scrutiny. This is crucial technology required to validate if the requestor and requestee match (verifying that the request is indeed for its own subscriber) The BroadForward Signaling Firewall can not only perform this function for SS7 but also for the newer network technologies in 4G and 5G.

Tightly integrating protection across network generations is equally crucial – from SS7 to Diameter to HTTP/2 – as it ensures that an attacker blocked on the old 2G/3G layer cannot simply switch protocols to exploit the 4G or 5G network. 

The need to secure SS7 is not about protecting legacy hardware; it is about protecting human rights, national security, and the integrity of the most essential communication platform on earth. Lighthouse Reports has done its part by shining a light on the vulnerability. Now, the burden of implementation rests squarely on the shoulders of the global MNO community to deploy the intelligent, multi-layered firewall technology required to finally banish the ghost of the past.

 

Also see:

Kaleido gives top rating for BroadForward Signaling Security and Firewall products

GSMA nominates BroadForward signaling Firewall for the Global Mobile (GLOMO) Awards in the category Best Mobile Security

Rationalizing legacy 2G STP: A necessary step for the future