SS7 Attacks

Attacking the mobile network to target users

Introduction

Mobile phones depend on a complex network of technologies to make calls, send messages and allow users to move between different mobile networks. One of the most important of these technologies is Signalling System No. 7 (SS7).

SS7 has been used by telecommunications providers for decades and performs many of the functions required to route calls and messages between mobile networks.

However, weaknesses in the trust model used by SS7 can allow attackers with access to the signalling network to manipulate communications, track devices and potentially intercept SMS messages.

What is SS7?

Signalling System No. 7 (SS7) is a collection of telecommunications signalling protocols used by mobile and telephone networks to exchange information.

The development of Signalling System No. 7 (SS7) began during the transition from traditional telephone signalling towards digital telecommunications networks.

1970s – Development of Common-Channel Signalling

Earlier telephone systems often used signalling information carried within the same communications channels as the actual telephone conversation.

SS7 introduced a fundamentally different approach: out-of-band common-channel signalling, where signalling messages were carried over a separate signalling network.

The technology evolved during the 1970s, and SS7 was formally standardised as Signalling System No. 7 in 1980, within the CCITT Q-series recommendations.

These specifications defined the architecture and individual components of SS7, including:

  • Q.700 – General introduction to SS7
  • Q.701–Q.710 – Message Transfer Part (MTP)
  • Q.703 – Signalling links
  • Q.704 – Signalling network functions and messages
  • Q.705 – Signalling network structure
  • Q.706 – Signalling performance

The first versions of several of these recommendations were approved in 1980 and were significantly refined during 1984.

SS7 was designed with a modular architecture, separating the Message Transfer Part (MTP) from higher-level User Parts. This allowed the same signalling infrastructure to support different telecommunications services.

SS7 was also increasingly associated with the development of Integrated Services Digital Network (ISDN) and digital telephone networks.

The SS7 recommendations were revised again in 1988 and provided an updated introduction to the system to reflect the evolving architecture and capabilities. This period helped establish SS7 as a major international signalling standard.

SS7 subsequently became an important foundation for mobile telecommunications around the world.

Additional capabilities were introduced above the basic signalling layers, including:

  • SCCP – Signalling Connection Control Part
  • TCAP – Transaction Capabilities Application Part
  • MAP – Mobile Application Part
  • ISUP – ISDN User Part

These higher-level protocols allowed SS7 networks to perform functions beyond simply setting up telephone calls – Mobile networks could use SS7-based signalling to exchange subscriber information, support roaming, manage mobility and deliver SMS messages.

The 1993 revision of Q.700 explicitly describes components including MTP, SCCP, ISUP, TCAP and OMAP.

SS7 is now responsible for functions such as:

  • Establishing and routing telephone calls
  • Routing SMS messages
  • Identifying subscribers
  • Supporting roaming
  • Determining the location of mobile devices
  • Managing call forwarding
  • Communicating between different mobile networks

When a mobile phone travels between networks, SS7 allows the networks involved to exchange information about the subscriber.

This allows the subscriber to continue making calls and receiving messages while roaming.

Why is SS7 vulnerable?

One of the fundamental problems with SS7 is that it was designed in an environment where participating telecommunications networks were generally trusted. The system was not originally designed to operate in an environment where an attacker could potentially obtain access to the signalling infrastructure.

As a result, some SS7 messages may be trusted once they originate from an apparently legitimate network participant.

This creates an important security problem – If an attacker gains access to the signalling network, they may be able to send signalling messages that the network trusts.

The attacker does not necessarily need to compromise the victim’s phone, instead, the attack can target the mobile network infrastructure itself.

How does an SS7 attack work?

A typical attack begins when an attacker obtains access to an SS7-connected network or signalling service. The attacker can then send specially crafted signalling requests involving a target mobile number.

Depending on the attack and the network configuration, the attacker may attempt to obtain information about the subscriber or manipulate how communications are routed.

The attack takes place within the telecommunications signalling infrastructure rather than directly against the victim’s handset.

What can attackers do?

SS7 attacks can potentially be used to perform several different types of activity.

  • Track a Mobile Device – Attackers may be able to obtain information that helps determine the approximate location of a mobile device. This can potentially allow the movement of a target to be monitored.
  • Intercept SMS Messages – An attacker may attempt to manipulate message routing so that SMS messages are delivered to an attacker-controlled destination. This is particularly significant because SMS is frequently used for two-factor authentication (2FA).
  • Redirect Calls – Attackers may attempt to manipulate call-routing information and redirect telephone calls.
  • Obtain Subscriber Information – SS7 requests can potentially be abused to obtain information about a subscriber or their relationship with a mobile network.
  • Facilitate Account Takeover – If an attacker can intercept SMS authentication codes, they may be able to combine this capability with stolen usernames and passwords to compromise online accounts.

SS7 and SMS authentication

One of the biggest concerns surrounding SS7 attacks is the use of SMS-based authentication.

If a service such as an online banking account is protected by Username + Password + SMS Code, then if an attacker has already obtained the username and password, they may need only the SMS authentication code to complete the login process

An SS7 attack could potentially be used to interfere with the delivery of the SMS message containing the code.

This is one reason organisations increasingly recommend stronger authentication methods that do not depend on SMS, such as authenticator apps, passkeys, or other out-of-bounds channels such as email.

SS7 location tracking

SS7 can also be abused to obtain information about the location of a mobile subscriber.

Mobile networks need to know which network and network area is currently serving a subscriber, particularly when that subscriber is roaming. An attacker who can submit unauthorised signalling requests may attempt to exploit this functionality.

The result can potentially provide information about the victim’s approximate location.

This makes SS7 attacks particularly concerning for:

  • Executives
  • Journalists
  • Activists
  • Law enforcement personnel
  • Intelligence targets
  • High-value individuals

SS7 attacks vs SIM Swapping

SS7 attacks and SIM swapping can both affect mobile communications, but they work differently.

SIM Swapping involves the attacker convincing the mobile provider to transfer the victim’s telephone number to a SIM controlled by the attacker.

SS7 Attacks occur when the attacker abuses telecommunications signalling to manipulate how the network handles the victim’s communications.

The important distinction is that an SS7 attack can potentially occur without physically obtaining or replacing the victim’s SIM card.

Why is SS7 difficult to defend against?

SS7 is not simply a protocol running on an individual’s smartphone – It forms part of the infrastructure used by telecommunications providers.

This means that an individual user has very limited ability to directly protect themselves against an SS7 attack. The responsibility therefore falls heavily on:

  • Mobile network operators
  • Telecommunications providers
  • Signalling service providers
  • Network security teams
  • Industry regulators

Networks can implement filtering and monitoring systems designed to identify suspicious signalling activity and prevent unauthorised requests from reaching sensitive network functions.

How can organisations reduce the risk?

Telecommunications providers can implement controls such as:

  • SS7 signalling firewalls
  • Signalling message filtering
  • Monitoring for anomalous SS7 activity
  • Subscriber-location request controls
  • SMS routing protection
  • Access controls for signalling infrastructure
  • Network segmentation
  • Authentication between trusted network operators
  • Continuous monitoring of signalling traffic
  • Blocking unnecessary signalling operations

Organisations should also avoid relying exclusively on SMS for high-value authentication.

How can users protect themselves?

Individual users cannot directly secure the SS7 infrastructure, but they can reduce the consequences of an attack.

Where possible:

  • Avoid using SMS as the only form of MFA
  • Use authenticator applications
  • Use passkeys or hardware security keys
  • Use strong, unique passwords
  • Enable account-login notifications
  • Monitor financial accounts for suspicious activity
  • Contact your mobile provider if unusual behaviour occurs
  • Treat unexpected authentication messages seriously

For highly sensitive accounts, phishing-resistant authentication is preferable to SMS-based authentication.

Conclusion

SS7 was designed for a trusted telecommunications environment – Modern attackers can potentially abuse that trust when they gain access to signalling infrastructure.

SS7 attacks can potentially allow attackers to:

  • Track mobile devices
  • Obtain subscriber information
  • Intercept SMS messages
  • Redirect communications
  • Circumvent SMS-based authentication
  • Support account takeover

The most important lesson is that a mobile phone number should not be treated as a strong security credential.

If an account can be protected using a passkey, authenticator application or hardware security key, these are generally stronger choices than relying solely on SMS.

The phone may be secure, but the network carrying its communications may be the target.