US Troops Tracked Through Mobile Phones During Iran Conflict: Report
US military personnel were reportedly tracked through their mobile phones during the conflict with Iran, according to the Financial Times.
Citing telecom network data and sources familiar with the matter, the newspaper said the campaign relied on both telecommunications’ infrastructure and commercially available location data to locate US troops and contractors across the Middle East.
The suspected tracking campaign began before the US-Israeli strikes on Iran in February and continued during Tehran’s retaliatory missile and drone attacks against US military facilities in the region.
US Central Command said in April that it had received multiple threat reports indicating adversaries were attempting to exploit commercially available location data to surveill or target deployed US personnel.
The Financial Times noted that further investigation is needed to determine whether the reported digital surveillance directly contributed to specific attacks.
Cybersecurity experts said such tracking would likely represent only one source of intelligence among several, including human surveillance, social media activity, and other operational information that could be used to identify potential targets.

Location Data Exposure
One method reportedly involved SS7, a decades-old signaling protocol used by mobile operators to manage international roaming.
SS7 contains a long-known vulnerability that allows operators and other entities with legitimate network access to obtain the approximate location of mobile phones.
According to the report, telecom networks across the Gulf blocked a wave of SS7 location requests targeting specific devices in recent months.
Officials in the region reportedly suspected that Iran or affiliated groups were attempting to exploit existing roaming agreements with local mobile operators to identify the location of US personnel.
A second tracking method is believed to have relied on commercial location data collected through the mobile advertising ecosystem.
This approach analyzes location information associated with smartphone advertising identifiers to estimate where individual devices are located.
A US official told the Financial Times that actors linked to Iran were believed to have used commercially available datasets to identify hotels housing US government personnel and contractors in Iraq’s Kurdistan region.

Military Data at Risk
The US intelligence community has been grappling with the risks posed by commercial location data for more than a decade, according to WIRED.
In late 2024, the news outlet obtained a sample from a US-based data broker containing 3.6 billion location records linked to about 11 million devices in Germany over two months.
The dataset included 12,313 devices that had passed through at least 11 US military sites, including the Army’s European headquarters in Wiesbaden, Büchel Air Base, and the Grafenwöhr training area.
Some devices were also linked to schools attended by children of US service members.
A 2023 Duke University study cited by WIRED and funded by the US Military Academy at West Point found thousands of data-broker listings targeting military personnel and their families.
Posing as buyers, researchers purchased names, addresses, health information, and financial details on active-duty personnel for as little as 12 cents per record.









