Mobile networks rely on signaling protocols for routing calls, delivering messages, and supporting services such as roaming. One of the most widely used of these protocols is SS7, a technology that was designed long before cybersecurity threats emerged.
Relying on outdated technologies is one of the main reasons behind an alarming rise in cyberattacks. As attackers continue to target weaknesses in digital infrastructure, flaws in legacy telecommunications technologies such as SS7 can turn into a major security issue. SS7 attacks are particularly concerning as they can enable location tracking, call and message interception, and service manipulation, which can compound into more severe consequences.
This guide will help you understand how an SS7 attack works, what risks they pose, and whether it’s possible to prevent them.
What Is SS7?
Signaling system no. 7, commonly known as SS7, is a set of long-standing international telecommunications protocols that enable phone networks worldwide to:
- Set up and route calls
- Exchange information
- Bill phone calls and short message service (SMS)
- Enable mobile phone roaming and tracking
- Support features such as call forwarding, caller ID, or call waiting
SS7 was developed in the 1970s and quickly became the industry standard. While the protocols underwent some revisions, they weren’t significant. The technology has remained largely unchanged in its core design for decades, although it’s still used worldwide. This makes it especially vulnerable to hackers, who can exploit the technology’s flaws to access sensitive user information, surveil network activities, or commit fraud.
Over time, newer mobile network protocols, such as the Diameter protocol used in 4G and 5G networks, were developed to replace SS7. As a result, SS7 became more closely associated with 2G and 3G systems, which could lead some users to assume that modern networks are unaffected by SS-related risks.
Are 4G and 5G Immune to SS7 Attacks?
The short answer is no—the transition to 4G and 5G has reduced reliance on SS7, but it hasn't eliminated SS7-related risks entirely.
Many mobile operators still maintain SS7 interconnections for legacy functions and roaming, so users can inherit the vulnerabilities depending on network architecture, roaming paths, and carrier mitigations. This lingering dependency can make even 4G and 5G systems vulnerable to SS7 attacks in certain scenarios, particularly when one participant in the communication remains connected to a 2G or 3G network that still relies on SS7 signaling.
SS7 roaming security represents another key concern as international roaming depends on inherent trust between multiple carrier networks. Since some less-secure operators may still rely on legacy SS7-based roaming infrastructure, attackers may be able to easily exploit signaling vulnerabilities for activities such as location tracking, eavesdropping, and intercepting texts.
What Is an SS7 Attack?
An SS7 attack exploits vulnerabilities in SS7 protocols to conduct numerous malicious activities, from location tracking to traffic interception.
SS7 protocols contain several well-documented vulnerabilities because they were developed at a time when encryption and modern authentication methods weren’t in use. In the 1970s and 1980s, the telecommunications industry relied on mutual trust. With no significant cybersecurity threats, SS7 network security was not a major design consideration.
During that period, the key strength of SS7 protocols was that they enabled worldwide interoperability. Mobile carriers worldwide can access the network to deliver calls and messages, as well as exchange signaling information.
Today, the same trust-based model has become a weakness, triggering several security challenges. Because the SS7 infrastructure isn’t built around robust security mechanisms, malicious actors can potentially abuse the trust model to impersonate legitimate users and access the system.
What SS7 Vulnerabilities Allow Attacks?
SS7 is often targeted by hackers due to its critical security flaws, including:
SS7 Flaw | Explanation |
Weak, trust-based authentication between network nodes | A mobile carrier sends a signaling message via SS7 to a part of its own infrastructure or to another carrier to route calls and texts or exchange information. These messages historically relied on trust rather than authentication, which creates the opportunity for exploitation. The receiving network trusts them by default, enabling hackers to send messages that appear to be from legitimate sources. |
Open network architecture | Once malicious actors gain access to the SS7 ecosystem, its highly connected architecture can help them exploit additional network functions or signaling requests. |
Lack of encryption | SS7 protocols were designed before modern built-in encryption became the standard. Since they still rely on legacy infrastructure, this can lead to signaling manipulation, routing abuse, and unauthorized access to sensitive information. |
Weak access controls | Mobile providers often allow their partners and third-party providers to use their SS7 networks for roaming and signaling purposes. While carriers may implement protections such as monitoring and SS7 firewalls, even these safeguards have their weaknesses and are prone to abuse. |
What Are the Potential Goals of SS7 Attacks?
SS7 vulnerabilities can be targeted for different reasons. Below are the five most common goals of SS7 attacks:
- Access to user information: Hackers often exploit an SS7 vulnerability to gain access to sensitive user data, such as their account details and location. This information can be leveraged for further attacks or even be sold on the Dark Web.
- SS7 surveillance: In some cases, attackers can track a user’s location using only their phone number. Because SS7 relies on inherent trust between networks, and operators must route calls and messages to the correct serving network, the home network has to maintain the signaling information about the user’s approximate location. Attackers can then query the network to obtain the victim’s visited location or serving area, potentially compromising their privacy and security.
- Traffic interception: SS7 weaknesses enable hackers to intercept your calls and text messages, which is risky as many services rely on SMS-based authentication. For example, a malicious actor could intercept an SMS with a one-time password (OTP) used for two-factor authentication (2FA) and gain unauthorized access to your account. Or, they could eavesdrop on your calls and collect sensitive information for future attacks.
- Denial of Service (DoS): By exploiting SS7, hackers can de-register your device from the network, so you’re unable to make or receive calls and messages. This creates an opportunity for hackers to access your accounts or commit fraudulent transactions without triggering alerts.
- SIM swap attacks: In more sophisticated cases, attackers exploit SS7-related vulnerabilities as part of broader scams to facilitate SIM swap attacks, one of the common mechanisms for financial fraud and identity theft. During a SIM swap attack, a victim’s phone number is transferred to a new SIM card without their consent, allowing attackers to receive calls and SMS messages intended for the original owner and potentially gaining access to sensitive accounts.
To defend against these threats, mobile carriers use some security measures, mainly SS7 firewalls.
What Are SS7 Firewalls?
Since SS7 was built on trust, mobile carriers rely on some security controls such as SS7 firewalls to address the infrastructure’s vulnerabilities and protect their networks and end users. SS7 firewalls represent crucial software-based security systems that safeguard against these threats by:
- Monitoring and detecting suspicious activity
- Inspecting signaling messages
- Validating message sources
- Checking if a message complies with configured security rules
SS7 firewalls and monitoring systems can potentially allow, flag, or block a message to protect the network from malicious activity, which makes them important security controls within mobile carrier infrastructure. Their effectiveness depends on how quickly carriers respond to detected suspicious activity and implement security solutions to reduce exposure to SS7-related threats.
Can SS7 Firewalls Offer Full Protection Against SS7 Attacks?
SS7 firewalls can’t completely prevent SS7 attacks as they’re not a universal solution. Common factors that affect the efficiency of protective mechanisms such as SS7 firewalls include:
- Evolving attack methods: Attackers continue developing sophisticated tactics to exploit weaknesses in signaling systems and bypass detection rules. This can limit the effectiveness of static SS7 firewall configurations and require ongoing updates to maintain defenses.
- Inherent trust-based environment: Since SS7 relies on a trust-based relationship between carriers, it can be difficult to detect malicious traffic from legitimate requests, especially when requests appear to be from trusted roaming partners or interconnected networks. This can help attackers evade rule-based detection methods, such as blacklisting.
- Coverage and detection limitations: Many legacy SS7 firewalls primarily focus on Category 1 threats, recognizing only unauthorized sources and missing complex, indirect Category 2 and Category 3 threats. A static monitoring system also relies on manual rule updates after an attack is identified, which can delay detection and response for emerging threats.
How To Detect an SS7 Attack
For end users, determining whether you’ve been targeted by an SS7 attack is tricky because the attack targets the carrier’s network rather than a specific device. If the attack has affected you, you may notice signs such as:
- Inability to make calls or send texts to a specific person
- Unexpected roaming charges
- Inability to complete SMS-based 2FA because the texts never arrive
- No service on your device
Note that these are not telltale signs of SS7 interception as they could also indicate issues with device configurations or other types of malicious attacks. Another problem is timing. By the time you notice the signs, the attack has already occurred, and you’re left dealing with the consequences.
Mobile carriers are far more likely to detect SS7 call or SMS interception or other forms of attack and react before they cause significant damage. This is because carriers have access to the network and can leverage robust tools to identify potential issues through strategies such as:
- Traffic monitoring: Carriers keep an eye on network traffic to spot unusual patterns and requests. For instance, they use a reliable traffic analytics tool for 24/7 traffic analysis, gaining detailed insights into potential network anomalies that enable them to react to threats in real-time.
- SS7 firewall utilization: Firewalls can block or flag suspicious requests to prevent potential threats from entering the system. But because firewalls have their limitations, it’s important that your carrier continuously customizes the detection rules in response to evolving attack techniques.
How To Prevent an SS7 Attack
End users have no control over a carrier’s network and protective measures. You can’t install firewalls or monitor and flag suspicious signaling requests to thwart an SS7 attack. There isn’t much you can do to prevent SS7 tracking or other forms of network exploitation except turn off your device.
The two main actions you can take to protect yourself against an SS7 attack are:
- Avoid SMS-based 2FA
- Choose a reliable mobile provider
1. Avoid SMS-Based 2FA
SMS-based 2FA delivers a one-time password (OTP) or another unique piece of information as a text message to verify your identity and enable you to log into an app or complete an action.
Although it’s widely used, SMS-based two-factor authentication isn’t secure and can be bypassed by hackers exploiting SS7 vulnerabilities.
To enhance protection, use alternative authentication methods, such as:
- Authenticator apps: Apps like Google Authenticator or Authy generate unique one-time codes that serve as a secondary verification method. These apps offer functionalities like offline access, backups, and multi-device sync to maintain your security and enhance convenience.
- Biometric authentication: This type of authentication utilizes your unique physical characteristics, such as fingerprints or facial features, to verify your identity. This method is convenient for those who may struggle with remembering multiple passwords or managing additional authentication apps.
2. Choose a Reliable Mobile Provider
While SS7 protocols support global communication, their inherent security weaknesses have become a liability. That’s why it’s important to choose a mobile carrier that doesn’t have SS7 as a fundamental vulnerability—but your options are limited.
With SS7 being flawed, there is a growing concern around the security controls carriers implement to prevent SS7 attacks. In 2024, the Federal Communications Commission (FCC) issued a request for comments from U.S. networks on the security of SS7 and Diameter (a protocol that was developed as a successor to SS7, but also comes with security issues).
In response to the FCC’s request, the three major providers in the U.S., Verizon, AT&T, and T-Mobile, provided more insight into their safety protocols and asserted that their firewalls are fully effective. However, a comment by Kevin Briggs, the Chief of Continuity Assessment and Resilience at the Cybersecurity and Infrastructure Security Agency (CISA), raised concerns. Briggs claims that there have been numerous examples of hackers leveraging SS7 and Diameter vulnerabilities to access user location data through U.S. telecommunications service providers.
This discourse highlights a critical vulnerability: despite their assurances, major commercial carriers remain exposed to SS7 attacks.
If you’re looking for an alternative designed to sidestep SS7 attacks, switch to Cape.
Cape is designed from the ground up to limit the vulnerabilities triggered by outdated protocols. We protect subscribers from SS7 attacks by eliminating SS7 dependencies entirely, and blocking any malicious signaling attach requests.
Cape: The Carrier Built for Security and Privacy
Cape is a privacy-first mobile carrier designed to keep your communications safe from surveillance and misuse. Unlike traditional cell phone plan providers, our business model centers around providing you with premium and secure call, text, and data, rather than harvesting and selling your information.
Our service is built from the ground up with privacy and security at its core, offering unique features like:
Feature | Description |
Cape doesn’t ask for your name, address, or Social Security number. We collect only what’s required to provide service—and keep it for the shortest time possible. | |
Cape nullifies the threat of SIM swapping by completely removing humans from the loop. During signup, you receive a 24-word phrase that generates a private key tied to your number. Only you, not even Cape, can move your number to a new device or carrier. | |
Traditional carriers use a fixed International Mobile Subscriber ID (IMSI), making your device trackable. Cape automatically rotates your IMSI every 24 hours, which makes tracking a lot more harder. | |
Most U.S. carriers store your call and text metadata for years, sometimes indefinitely. Cape is built to forget, so call data records (CDRs) are deleted after just 24 hours. | |
Legacy protocols like SS7 enable tracking and interception. Cape verifies your device’s physical location before network attachment and automatically blocks suspicious connections. | |
Many services ask for your phone number, but sharing it exposes you to spam, scammers, data brokers, and a variety of other risks. VoIPs, on the other hand, don’t work with 2FA, cost extra, and aren’t encrypted. Cape gives you two free SMS/MMS lines that are end-to-end encrypted. You can reserve your primary number for communicating with your close friends and family, and use Secondary Numbers for anything from shopping and signing up for discounts, to receiving secure OTPs. | |
Traditional voicemail systems are outdated, unencrypted, and another security hole bad actors can exploit to gain access to your sensitive information. Cape encrypts all voicemails, ensuring only you can access them. | |
While roaming, your phone connects to local telecom providers to enable service that’s prone to interception. Cape provides you with peace of mind by routing your traffic through our U.S.-based mobile core to keep your identity and communications private. |
Ditch Legacy Carriers: Get Cape Today
Cape is a “Heavy” Mobile Virtual Network Operator (MVNO), meaning we own our mobile core and provision our own SIMs. This gives us full control over how accounts are authenticated and what data is collected (and for how long), and is how we are able to provide privacy and security features no other carrier on the market can offer.
Get started with Cape today and enjoy the peace of mind, knowing you are fully protected against scammers, hackers, bad actors, and other mobile threats.
To help protect more than just your phone, we’ve partnered with Proton. As a new Cape subscriber, you can choose between Proton Unlimited and Proton VPN Plus for just $1 for six months.
Share it

