Operator networks differ enormously, so an industry benchmark tells you very little about yours. We measured live networks through gsmmap.org and scored each on interception, impersonation and tracking separately instead of as one composite, and none protected well in all three dimensions. The individual protections were rare: A5/3 encryption appeared in 5 of 107 networks, strict per-call authentication in 8, home routing in 12. We refreshed that infrastructure in 2023 but have published no new network-population figure since, so we test your network.
Each bar is the count of networks with that one protection, out of the 107 we measured. The three were counted separately, so the figure does not show how often they occur together.
An operator has two perimeters: the internet-facing one, and the subscriber-facing one over LTE. Behind them sit the interfaces that carry the risk: SS7 and Diameter interconnect, SIM and binary SMS, RAN configuration over the air, IMS/RCS/VoLTE, and the core. Mobile networks have been our subject since 2010. A5/1 fell to rainbow tables: a 2TB table set recovers a call key from recorded traffic in seconds, about nine times in ten. SIM cards proved rootable over binary SMS, their 56-bit DES keys recovered in roughly two minutes. SIMtester and gsmmap went out publicly so operators could run the tests themselves. Those are the tests we bring to your interfaces.
What we found
Of 800 SIM cards collected over several years and tested with SIMtester, our own public tool, 9.4% carried the S@T applet and 10.7% the WIB applet, with 9.1% exploitable through one or the other. The WIB attack was a second bug class, previously unreported, and it surfaced while the first was being investigated. Eight SnoopSnitch users reported 29 real attack SMS going back to 2016.
Three shapes these engagements take, scoped to the interfaces you run. Most operators start with the two perimeters and add interfaces from there.
Exposure scan
We find which telco systems are reachable from the internet and from a subscriber handset over LTE.
—Both perimeters: internet (IP) and subscriber (IP over LTE)
—Network segregation between them
—Architecture review against what the segregation is supposed to achieve
Interconnect pentest
We test SS7 and Diameter for the remote attacks they still carry: fraud, tracking and interception.
—SS7 and Diameter message-level testing
—Interconnect firewall rule coverage against the attacks it claims to stop
—Remote fraud, location tracking and interception paths
RAN, SIM and over-the-air
We collect your RAN configuration over the air and test the SIM and binary-SMS paths behind it.
—RAN parameters collected over the air, compared to GSMA and 3GPP practice
—SIM file-system permissions and applications
—Whether binary SMS is correctly blocked
—IMS, RCS and VoLTE configuration
Also available: telco platform pentesting against legacy, 5G, NFV and private-cloud nodes, with end-to-end attack testing per node.
How we work
We start from the outside and work inward, because that is the order an attacker has available: both perimeters first, then each internal interface behind them. A protection you believe is in place is not the same as the one running. Scoring 107 networks separately on interception, impersonation and tracking is what showed that, because the composite score every operator quotes hid it. Where we find a gap we say which of interception, impersonation or tracking it enables, and what it would cost to close, using the technology you already own before anything new.
Tell us what you are building and what you need looked at. You will get an answer
from the people who would run the engagement, and if another firm is the better
fit for what you are asking, we will name one.