:

SURVEILLANCE VENDORS ABUSE TELECOM ACCESS TO TRACK PHONES

SECURITY DESK2 MIN READ
THU, APR 23, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Researchers at the Citizen Lab have identified two surveillance vendors exploiting direct access to cellular networks to track phone locations across multiple countries without authorization.

The Citizen Lab's investigation uncovered a significant security breach in how telecom operators manage third-party access to their networks. Two separate surveillance vendors gained unauthorized ability to track individuals' real-time locations by leveraging their connection to the cellular backbone infrastructure. The research reveals how location data—typically restricted to authorized carriers and emergency services—became accessible to commercial surveillance firms. These vendors exploited legitimate telecom partnerships to perform location tracking on several victims globally, raising critical questions about access controls and operator oversight. Cellular networks maintain complex systems that allow authorized parties to query location information for legitimate purposes. However, this investigation demonstrates vendors bypassed standard restrictions to conduct surveillance operations beyond their authorized scope. The Citizen Lab did not disclose the specific vendors or victims involved, citing security concerns. The organization has reported findings to affected telecom operators and relevant authorities. This discovery highlights vulnerabilities in telecom infrastructure that extends beyond typical cybersecurity concerns. Location data represents one of the most sensitive forms of personal information, capable of revealing patterns about individuals' movements, relationships, and daily routines. Telecom operators worldwide face renewed pressure to audit third-party access and implement stronger controls over location data. The incident underscores the gap between technical capabilities built into networks and the safeguards designed to protect against misuse. Experts note that telecom operators often grant access to various commercial and government entities for legitimate services, including emergency response and fraud prevention. This investigation suggests current verification and monitoring systems are insufficient to prevent abuse. The findings add to mounting concerns about location tracking infrastructure. Previous research has documented how location data obtained through cellular networks can be weaponized against activists, journalists, and vulnerable populations.

■ SOURCES

TechCrunch

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

PaperCut has released a second emergency security update for its NG and MF print management software after researchers discovered bypass methods for the initial fixes. The vulnerabilities are currently being exploited in the wild.

3H AGOSecurity Desk

A 68-year-old has been sentenced to over six years in prison in the U.K. for operating an illegal IPTV service that generated £980,812 ($1.3 million) over three years.

6H AGOIndustry Desk

A detailed analysis examines how the internet has shifted toward predatory practices, drawing significant engagement from tech community members on Hacker News with 227 points and 120 comments.

7H AGOIndustry Desk

A critical vulnerability in the popular GiveWP WordPress donation plugin allows unauthenticated attackers to execute arbitrary commands on hosting servers. The maximum-severity flaw requires immediate patching.

7H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.