Iranian hackers are believed to have taken advantage of weaknesses in the Middle East’s telecom infrastructure to track the movements of US military personnel and contractors stationed across the Gulf, according to cybersecurity researchers.
The activity was detected by the Mobile Surveillance Monitor, a research initiative that studies mobile espionage. It found a surge in requests sent through regional telecom networks to determine the location of specific mobile phones that were roaming outside their home networks.
Gary Miller, founder of the nonprofit and a cybersecurity researcher, described the activity as part of a broader campaign.
The data was indicative of a “coordinated attack campaign,” Miller told The New York Times, as reported by NDTV.
Also Read | IRGC claims attacks on US bases in the Gulf, vows Hormuz closure until ‘America’s evils’ end
According to a Financial Times report cited by NDTV, the cyber activity intensified in the lead-up to the US-Israeli conflict with Iran and continued during the early phase of the fighting, when Tehran launched missile and drone attacks on US military facilities in the region.

SS7 system allegedly used to locate devices
Researchers said the activity centred on SS7, a decades-old telecommunications signalling system that allows mobile networks around the world to exchange information.
Miller said telecom networks in Bahrain, where thousands of US military personnel are based, received a large number of SS7 pings; silent requests that can determine whether a phone is active, roaming or reveal its approximate location.
Officials in the Gulf reportedly believe Iran or groups aligned with it may have exploited roaming agreements with regional telecom providers to identify US personnel.

“Iran absolutely has capabilities to get real-time, immediate, and continuous location information. It would surprise me very much if Iran were not using SS7, or mobile network access in the region, to track US users,” said Miller.
He also said investigators found signs linking some blocked tracking attempts to an Iranian mobile operator.
“This appears to be very specific user targeting. They are targeting specific devices,” Miller added.
Also Read | Balochistan declared independent? Here is what their ‘new’ national anthem
Concerns over evolving cyber capabilities
Cybersecurity experts say the reported activity reflects a growing sophistication in Iran’s cyber operations.
🚨 BREAKING — The IRGC announces the complete destruction of U.S. weapons and parts storage facilities in Bahrain during tonight's large-scale strikes. 🇮🇷🇧🇭🇺🇸💥🔥⚡️🚀 pic.twitter.com/VdtkZM0E39
— IRGC (@IRGC_Press) July 14, 2026
Speaking to The New York Times, Nikita Shah of the Centre for Strategic and International Studies said, “Iran has become quite creative in the last couple of years, and especially in this conflict. For me, this signals a step up in sophistication.”
The concerns come after Iran and allied regional militias carried out attacks on US-linked targets across the Middle East during the conflict, including in Bahrain and Iraq.
Satellite imagery reveals Iran's precise strike on the drone command center at the U.S. Fifth Fleet base in Bahrain — a targeted blow to American surveillance and control capabilities in the region. 🇮🇷🇧🇭🇺🇸💥🛰️🛸🔥⚡️ pic.twitter.com/2Dd1LteasM
— IRGC (@IRGC_Press) July 15, 2026
US lawmakers raise alarm
The reports have renewed concerns in Washington over the use of commercial smartphone data for surveillance.
Democratic Senator Ron Wyden said, “For years I’ve warned both Democratic and Republican administrations about the national security threat posed by foreign adversaries tracking the phones of US personnel.”
Republican Congressman Pat Harrigan also warned of the risks posed by commercial location data.

“The capability and the threat . . . exist. If it continues to be exploited, and it’s exploited properly, it could be catastrophic,” Harrigan told the Financial Times.
Meanwhile, US Central Command (CENTCOM) told Congress in April that it had received multiple threat reports about adversaries attempting to exploit commercial location data to monitor American personnel. It said it had adopted additional protective measures but did not disclose details. A US official also told the Financial Times that “any claim suggesting data tracking played a significant role in attacks…is a departure from the facts”.
FAQs:
What is SS7?
SS7 is a telecom signalling system used by mobile networks to exchange information, including device location and roaming status.
What did researchers allege about Iran’s cyber activity?
They said Iran allegedly used telecom infrastructure and mobile tracking methods to locate specific US personnel in the Gulf.





























