Protecting UK Families & Businesses Knowledge is power — we make sure you have it
Menu ☰
CyberAware UK CyberAwareUK Stay Aware · Stay Secure
𝕏 💼 🎧
Menu
Home 🔍 Search
Live Threat Intel
Been Scammed? Start Here
Child Safety Hub
Lock It Down
Scams & Money
Reviews & Tests
Know Your Stuff
Go Deeper
Careers
About Us
© 2026 CyberAware UK
📡
📡

SS7 Signal Hacking — Research & Protection Guide

SS7 is the 50-year-old hidden backbone of global telecoms — and it has a critical flaw: it was built when every network trusted every other network. Today, criminals and state actors exploit SS7 to intercept SMS codes, redirect calls, and track phones. This page explains the research, the risk, and how to protect yourself.

🛡️ What this page is: an educational research guide on the SS7 protocol, how it is exploited, and what UK consumers can do to reduce their risk. It is not a hacking tutorial — it is defensive knowledge, the same way knowing how a lock works helps you buy a better one.

🧠 What Is SS7?

Signaling System 7 (SS7) is the protocol that lets mobile networks talk to each other. Every time you make a call, send a text, or roam abroad, SS7 messages travel between operators to set up, route, and bill that communication. It was designed in the 1970s and 1980s, when only a handful of trusted telecom companies existed — so it has almost no authentication or authorisation built in.

That design decision, made half a century ago, is the root of the problem: any operator connected to the SS7 network can send messages that other operators will obey, including messages that intercept your texts or track your location.

🔬 The Research: Documented SS7 Attacks

SS7 vulnerabilities are not theoretical — they have been demonstrated repeatedly by security researchers and exploited in the real world:

  • 2014–2017 SMS interception (2FA theft): researchers (including Karsten Nohl of Security Research Labs) showed that an attacker with SS7 access can silently redirect a target's SMS messages to their own device — including the one-time passcodes banks and apps send for two-factor authentication. This directly defeats SMS-based 2FA.
  • 2017 O2 Germany real-world case: a criminal group used SS7 exploits to intercept SMS verification codes and drain victims' bank accounts, stealing hundreds of thousands of euros. This was the first widely reported criminal (not state) use of SS7 for financial fraud.
  • 2019 WhatsApp hack: a spyware implant was delivered via an SS7-style flaw — attackers placed calls to victims' phones that triggered the spyware before the call rang. The case showed SS7 and related telecom signalling flaws being used for targeted surveillance.
  • 2020–2025 Location tracking: multiple researchers and journalists demonstrated that SS7 can be used to triangulate a phone's location within metres, without the carrier's knowledge or the user's consent. Used by states and, increasingly, commercial trackers.
  • 2021–2025 Ransomware-adjacent & SMS fraud: SS7 access is sold on dark web markets (the "Signaling" underground), enabling scam networks to spoof SMS senders, intercept codes, and fuel "smishing" campaigns at industrial scale.

Sources: Security Research Labs (SRLabs), published conference research (DEF CON, Chaos Communication Congress), public reporting by investigative journalists and security firms. Figures are indicative of documented cases, not UK-specific statistics.

🎯 What Can an Attacker Actually Do?

📩 Intercept SMS

Redirect your texts to the attacker's device — including bank codes, password resets, and delivery codes. Your phone never receives them.

📞 Redirect Calls

Forward your calls to a number the attacker controls, then answer them as you — used in phone-based fraud and account recovery attacks.

📍 Track Location

Query the network for your current cell tower or triangulate your position — without touching your phone. Silent, invisible, and hard to detect.

👤 Impersonate You

Because SS7 trusts sender identity, attackers can make messages and calls appear to come from your number — fuelling vishing and courier fraud.

🔓 Bypass SMS 2FA

Steal the SMS codes that banks, email, and social platforms send — then reset passwords and take over accounts. This is why security experts say "SMS 2FA is better than nothing, but not enough."

⛔ Deny Service

Flood the network with signalling messages to knock a target's device offline — a mobile equivalent of a denial-of-service attack.

🛡️ How to Protect Yourself (UK Consumer)

You cannot fix SS7 yourself — only operators and regulators can. But you can make yourself a much harder target:

🔑 1. Ditch SMS 2FA for Authenticator Apps

Use Google Authenticator, Microsoft Authenticator, Authy, or 1Password for two-factor codes. These are generated on your device and never travel over the mobile network — SS7 cannot touch them.

🛡️ 2. Use Passkeys or Security Keys

Passkeys (Apple, Google, Microsoft) and hardware keys (YubiKey) are phishing- and interception-proof. Enable them wherever banks and email providers offer them.

📱 3. Use Encrypted Messaging

Signal and WhatsApp encrypt message content end-to-end — so even if signalling is intercepted, the message itself stays unreadable. Use them for anything sensitive.

🔒 4. Lock Your SIM & Accounts

Set a SIM PIN or account passcode with your UK provider (O2, EE, Vodafone, Three). Add extra verification for account changes — this limits SIM swap and number-porting attacks.

⚠️ 5. Watch for "No Service" Out of Nowhere

Sudden, unexplained loss of signal while other phones work can indicate SMS interception or SIM fraud. Contact your provider immediately from another device.

🏦 6. Use Banking Apps, Not SMS Codes

Most UK banks now use in-app approval and biometrics. Enable in-app confirmation and disable SMS-only verification where your bank allows it.

📶 7. Use Wi-Fi Calling Where Possible

Wi-Fi calling routes calls over the internet instead of the cellular signalling network, reducing exposure to SS7 interception for voice.

📡 SS7 at a Glance

🔹 What: the 1970s-era protocol that routes calls and texts between telecom networks
🔹 The flaw: no built-in authentication — networks trust each other by default
🔹 The risk: SMS interception, call redirect, location tracking, 2FA bypass
🔹 Who's at risk: anyone using SMS-based two-factor authentication or unencrypted calls/texts
🔹 Who's fixing it: mobile operators and regulators; newer signalling protocols (SIGTRAN, Diameter) add some controls but are not universally deployed
🔹 Your defence: authenticator apps, passkeys, encrypted messaging, SIM PIN, in-app banking

🛡️ Bottom Line

SS7 is a real, documented, and actively exploited weakness in the global phone network — but it mostly targets SMS codes and unencrypted communication. Move your two-factor authentication off SMS, use encrypted messaging for sensitive chats, and you remove yourself from the vast majority of SS7 attack paths. For more on phone-number fraud, see our SIM Swap guide and phone scam guide.