SS7 Signal Hacking — Research & Protection Guide
SS7 is the 50-year-old hidden backbone of global telecoms — and it has a critical flaw: it was built when every network trusted every other network. Today, criminals and state actors exploit SS7 to intercept SMS codes, redirect calls, and track phones. This page explains the research, the risk, and how to protect yourself.
🛡️ What this page is: an educational research guide on the SS7 protocol, how it is exploited, and what UK consumers can do to reduce their risk. It is not a hacking tutorial — it is defensive knowledge, the same way knowing how a lock works helps you buy a better one.
🧠 What Is SS7?
Signaling System 7 (SS7) is the protocol that lets mobile networks talk to each other. Every time you make a call, send a text, or roam abroad, SS7 messages travel between operators to set up, route, and bill that communication. It was designed in the 1970s and 1980s, when only a handful of trusted telecom companies existed — so it has almost no authentication or authorisation built in.
That design decision, made half a century ago, is the root of the problem: any operator connected to the SS7 network can send messages that other operators will obey, including messages that intercept your texts or track your location.
🔬 The Research: Documented SS7 Attacks
SS7 vulnerabilities are not theoretical — they have been demonstrated repeatedly by security researchers and exploited in the real world:
- 2014–2017 SMS interception (2FA theft): researchers (including Karsten Nohl of Security Research Labs) showed that an attacker with SS7 access can silently redirect a target's SMS messages to their own device — including the one-time passcodes banks and apps send for two-factor authentication. This directly defeats SMS-based 2FA.
- 2017 O2 Germany real-world case: a criminal group used SS7 exploits to intercept SMS verification codes and drain victims' bank accounts, stealing hundreds of thousands of euros. This was the first widely reported criminal (not state) use of SS7 for financial fraud.
- 2019 WhatsApp hack: a spyware implant was delivered via an SS7-style flaw — attackers placed calls to victims' phones that triggered the spyware before the call rang. The case showed SS7 and related telecom signalling flaws being used for targeted surveillance.
- 2020–2025 Location tracking: multiple researchers and journalists demonstrated that SS7 can be used to triangulate a phone's location within metres, without the carrier's knowledge or the user's consent. Used by states and, increasingly, commercial trackers.
- 2021–2025 Ransomware-adjacent & SMS fraud: SS7 access is sold on dark web markets (the "Signaling" underground), enabling scam networks to spoof SMS senders, intercept codes, and fuel "smishing" campaigns at industrial scale.
Sources: Security Research Labs (SRLabs), published conference research (DEF CON, Chaos Communication Congress), public reporting by investigative journalists and security firms. Figures are indicative of documented cases, not UK-specific statistics.
🎯 What Can an Attacker Actually Do?
Redirect your texts to the attacker's device — including bank codes, password resets, and delivery codes. Your phone never receives them.
Forward your calls to a number the attacker controls, then answer them as you — used in phone-based fraud and account recovery attacks.
Query the network for your current cell tower or triangulate your position — without touching your phone. Silent, invisible, and hard to detect.
Because SS7 trusts sender identity, attackers can make messages and calls appear to come from your number — fuelling vishing and courier fraud.
Steal the SMS codes that banks, email, and social platforms send — then reset passwords and take over accounts. This is why security experts say "SMS 2FA is better than nothing, but not enough."
Flood the network with signalling messages to knock a target's device offline — a mobile equivalent of a denial-of-service attack.
🛡️ How to Protect Yourself (UK Consumer)
You cannot fix SS7 yourself — only operators and regulators can. But you can make yourself a much harder target:
Use Google Authenticator, Microsoft Authenticator, Authy, or 1Password for two-factor codes. These are generated on your device and never travel over the mobile network — SS7 cannot touch them.
Passkeys (Apple, Google, Microsoft) and hardware keys (YubiKey) are phishing- and interception-proof. Enable them wherever banks and email providers offer them.
Signal and WhatsApp encrypt message content end-to-end — so even if signalling is intercepted, the message itself stays unreadable. Use them for anything sensitive.
Set a SIM PIN or account passcode with your UK provider (O2, EE, Vodafone, Three). Add extra verification for account changes — this limits SIM swap and number-porting attacks.
Sudden, unexplained loss of signal while other phones work can indicate SMS interception or SIM fraud. Contact your provider immediately from another device.
Most UK banks now use in-app approval and biometrics. Enable in-app confirmation and disable SMS-only verification where your bank allows it.
Wi-Fi calling routes calls over the internet instead of the cellular signalling network, reducing exposure to SS7 interception for voice.
📡 SS7 at a Glance
🛡️ Bottom Line
SS7 is a real, documented, and actively exploited weakness in the global phone network — but it mostly targets SMS codes and unencrypted communication. Move your two-factor authentication off SMS, use encrypted messaging for sensitive chats, and you remove yourself from the vast majority of SS7 attack paths. For more on phone-number fraud, see our SIM Swap guide and phone scam guide.