The report said the alleged surveillance campaign before and during the conflict has raised fresh concerns among US lawmakers over the digital security of American troops and government personnel.
According to Financial Times, citing telecommunications data, cybersecurity experts, and officials familiar with the matter, Iran conducted a coordinated effort to monitor the movements of US military personnel and contractors in the region through mobile phone tracking methods.
The report said several telecommunications networks in the Middle East blocked suspicious signals known as SS7 pings, which can potentially be used to determine the geographic location of mobile phones operating on international roaming services.
Two cybersecurity experts told the newspaper that available evidence suggested these activities were aimed at tracking specific mobile devices rather than conducting broad surveillance.
The reported tracking efforts allegedly began before US and Israeli strikes on Iran in late February and continued into the early days of the war, when Iran launched missile and drone attacks against US military bases and facilities in the region.
Use of Commercial Data
The Financial Times reported that officials in some Gulf countries suspected Iran or its allies may have used local mobile operators’ roaming agreements to identify the locations of US military personnel and contractors.
The report also cited a US official as saying that Iran-linked groups used commercially available advertising databases to track the locations of US personnel’s mobile phones in Iraq’s semi-autonomous Kurdistan region.
Gary Miller, a senior researcher at cybersecurity group Citizen Lab, told the Financial Times that Iran has the capability to obtain real-time location data of individuals.
He said it would not be surprising if Iran was using access to mobile networks or SS7 systems to monitor US users in the region.
US Central Command Response
According to the report, US Central Command (CENTCOM) informed Congress in April that it had received multiple reports of hostile actors attempting to monitor or target US personnel using commercially available location data.
CENTCOM said it had taken necessary protective measures to safeguard its personnel.
A US official told the Financial Times that there was no evidence so far proving that location data obtained through mobile phone tracking was decisively used in any attack.
The report also claimed that Iran was suspected of using commercial advertising technology to identify hotels where US government employees and contractors were staying.
Such technology can track smartphones through advertising identification numbers without directly hacking the devices.
Calls for Regulation in US
US Senator Ron Wyden said he had warned successive administrations for years about national security risks linked to commercially available location data.
Republican Congressman Pat Harrigan called for legislation to prevent technology companies from selling location information of government employees.
Meanwhile, Iran’s embassy in London did not immediately respond to a request for comment from the Financial Times.
SEO Keywords:
