:

SURVEILLANCE VENDORS ABUSE TELECOM ACCESS TO TRACK PHONES

SECURITY DESK2 MIN READ
THU, APR 23, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Researchers at the Citizen Lab have identified two surveillance vendors exploiting direct access to cellular networks to track phone locations across multiple countries without authorization.

The Citizen Lab's investigation uncovered a significant security breach in how telecom operators manage third-party access to their networks. Two separate surveillance vendors gained unauthorized ability to track individuals' real-time locations by leveraging their connection to the cellular backbone infrastructure. The research reveals how location data—typically restricted to authorized carriers and emergency services—became accessible to commercial surveillance firms. These vendors exploited legitimate telecom partnerships to perform location tracking on several victims globally, raising critical questions about access controls and operator oversight. Cellular networks maintain complex systems that allow authorized parties to query location information for legitimate purposes. However, this investigation demonstrates vendors bypassed standard restrictions to conduct surveillance operations beyond their authorized scope. The Citizen Lab did not disclose the specific vendors or victims involved, citing security concerns. The organization has reported findings to affected telecom operators and relevant authorities. This discovery highlights vulnerabilities in telecom infrastructure that extends beyond typical cybersecurity concerns. Location data represents one of the most sensitive forms of personal information, capable of revealing patterns about individuals' movements, relationships, and daily routines. Telecom operators worldwide face renewed pressure to audit third-party access and implement stronger controls over location data. The incident underscores the gap between technical capabilities built into networks and the safeguards designed to protect against misuse. Experts note that telecom operators often grant access to various commercial and government entities for legitimate services, including emergency response and fraud prevention. This investigation suggests current verification and monitoring systems are insufficient to prevent abuse. The findings add to mounting concerns about location tracking infrastructure. Previous research has documented how location data obtained through cellular networks can be weaponized against activists, journalists, and vulnerable populations.

■ SOURCES

TechCrunch

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Anthropic has signed out some Claude users and removed saved payment methods after infostealer malware on their computers hijacked active sessions to drain API usage credits. The company is issuing refunds for unauthorized charges.

9H AGOAI Desk

Former NYC Traffic Commissioner Sam Schwartz warns that autonomous vehicle expansion creates significant cybersecurity risks, including the potential for bad actors to seize control of connected cars and weaponize them.

9H AGOSecurity Desk

More than a decade of Steam files, including beta builds and finished games from Valve and third-party developers, have been exposed in a major data leak totaling over 12 terabytes.

14H AGOIndustry Desk

A new vulnerability called Omarchy allows any user-level process to gain root privileges through privilege escalation. The flaw has sparked significant discussion in security circles.

16H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.