/

Ghost Operators: Telecom Infrastructure Turns Into a Global Surveillance Web

How Israeli-linked telecom systems and legacy mobile protocols are being exploited in covert tracking operations spanning multiple countries, raising urgent questions about modern network security and spyware markets

3 mins read
A Representational Illustration

Israeli telecommunications infrastructure has been implicated in global surveillance operations that reportedly enabled the tracking of mobile users across more than ten countries over a three-year period, according to findings by the digital research group Citizen Lab. The investigation, reviewed and reported by Haaretz in recent weeks, reveals how both outdated and modern mobile network protocols can be manipulated to transform smartphones into precise location-tracking devices without users’ awareness. The revelations highlight how the global shift from legacy telecom systems to 4G and 5G networks has not eliminated surveillance vulnerabilities, but in some cases expanded them.

At the center of the findings are two distinct tracking operations that Citizen Lab believes were likely conducted by commercial surveillance firms selling services to government clients. One of the operations allegedly exploited Israeli geolocation and telecom infrastructure through networks associated with 019Mobile and Partner Communications, though both companies have denied any involvement. According to the report, dozens of suspicious routing requests passed through these systems, appearing consistent with surveillance activity rather than legitimate telecommunications traffic. Another route was traced through Exelera Telecom, an Israeli communications and cloud services provider linked to international fiber-optic infrastructure. Exelera did not respond to requests for comment cited by Haaretz.

The investigation suggests that the surveillance ecosystem relies heavily on manipulation of global telecom signaling protocols originally designed for basic connectivity rather than security. One of the most widely abused systems is SS7, a decades-old mobile signaling protocol that enables international roaming, call routing, and text message delivery between operators. Researchers found that this system can be exploited to silently query a phone’s location anywhere in the world. In response to long-standing concerns over abuse, British regulators recently moved to ban certain uses of SS7-based tracking practices, calling them a major source of malicious telecom traffic after years of investigative reporting into their misuse.

More concerning, according to Citizen Lab, is evidence that newer mobile infrastructure designed to replace SS7 vulnerabilities is also being exploited. Systems such as Diameter, used in 4G roaming and core to many 5G networks, were intended to improve security and streamline communication between carriers. However, the report indicates that spyware operators have adapted their methods to exploit these newer protocols as well. This suggests a persistent cycle in which each generation of telecom security upgrades is rapidly tested and repurposed for surveillance rather than protection, leaving little meaningful reduction in global tracking capabilities.

The first operation detailed in the report involved more than 500 confirmed location-tracking attempts between November 2022 and 2025. These incidents spanned countries including Thailand, South Africa, Norway, Bangladesh, Malaysia, and several African states. The investigation began with a single target, a Middle Eastern businessman whose phone was tracked repeatedly over a four-hour period. That case led researchers to identify a broader pattern of systematic querying of international mobile networks, suggesting a coordinated commercial service operating on behalf of clients seeking real-time location intelligence. The data indicated that telecom routing identifiers linked to Israeli carrier 019Mobile appeared in the requests, alongside infrastructure tied to Partner Communications and Exelera Telecom.

019Mobile’s head of security, Gil Nagar, denied any involvement, stating that the company operates as a virtual mobile provider without its own roaming agreements and that any such traffic would have been rejected. Citizen Lab, however, noted that the identity of the carrier may have been forged, a technique sometimes used in telecom exploitation to disguise the origin of surveillance queries. Partner Communications also rejected any connection to the operation, while Exelera Telecom did not respond. Despite these denials, researchers say the patterns of traffic are consistent with deliberate exploitation rather than accidental routing errors.

The report also points to a broader ecosystem of commercial surveillance vendors that may be involved in enabling such operations. Among those flagged as potential suspects is Cognyte, an Israeli-American company that develops intelligence tools for government agencies. Internal documents reviewed by Haaretz indicate that Cognyte’s parent company, Verint, previously sold an SS7-based tracking product known as SkyLock to a government client in the Democratic Republic of Congo. The same documents show commercial ties with telecom operators in Thailand, Malaysia, Indonesia, Vietnam, and Congo—several of which appear in the tracking dataset identified by Citizen Lab. One of these operators, AIS Thailand, was also present in the traffic associated with the surveillance campaign.

A second operation is linked to Fink Telecom Services, a Swiss firm previously exposed in a 2023 investigation by Haaretz and Lighthouse Reports for providing SS7-based surveillance capabilities to commercial spyware vendors. The company allegedly enabled clients to impersonate mobile carriers and query global telecom networks as if they were legitimate operators. This capability allowed surveillance firms to extract location data from mobile devices worldwide. Researchers also identified an emerging technique known as SIMjacking, in which hidden SMS messages containing coded commands are sent to target devices, triggering SIM cards to disclose location data without user interaction or visible alerts.

Citizen Lab estimates that more than 15,700 SIM-based tracking attempts have been detected since late 2022, indicating a rapid expansion in the use of stealth mobile exploitation techniques. Unlike earlier methods exposed in previous Haaretz reporting, this newer approach leaves no obvious trace on the phone, making detection significantly more difficult. Researchers warn that the convergence of legacy SS7 vulnerabilities, modern Diameter protocol weaknesses, and SIM-based exploits demonstrates a layered surveillance architecture that evolves alongside telecom upgrades rather than being constrained by them.

The findings paint a picture of a global, commercially driven surveillance environment in which telecom infrastructure itself has become a tool of intelligence gathering. While companies involved deny wrongdoing or knowledge of abuse, the patterns identified by Citizen Lab and reported by Haaretz suggest that mobile networks across continents may be quietly enabling persistent, large-scale tracking of individuals without consent or visibility.

Sri Lanka Guardian

The Sri Lanka Guardian is an online web portal founded in August 2007 by a group of concerned Sri Lankan citizens including journalists, activists, academics and retired civil servants. We are independent and non-profit. Email: editor@slguardian.org

Leave a Reply

Your email address will not be published.

Latest from Blog