Hackers could track you across the globe due to this worrying smartphone security flaw

Cell tower
Også i udlandet er udruldningen af 5G i fuld gang (Image credit: Pexels)

Hackers can use the technology that makes cellphone roaming possible to pinpoint user locations and track people around the world, a new report from University of Toronto’s Citizen Lab has claimed.

The researchers argue that the underlying technology is so full of holes that it’s practically inviting malicious actors to abuse it, which can be both illegal organizations or nation-states.

“Foreign intelligence and security services, as well as private intelligence firms, often attempt to obtain location information, as do domestic state actors such as law enforcement,” the paper reads. “Notably, the methods available to law enforcement and intelligence services are similar to those used by the unlawful actors and enable them to obtain individuals’ geolocation information with high degrees of secrecy.”

IP Exchange

The vulnerability Citizen Lab’s researchers emphasized is in the IP Exchange (IPX), a network that helps telecom companies swap data about their customers. As per the report, more than 750 mobile networks in almost 200 countries around the world use it. Furthermore, the companies can sell (and resell) access to the IPX, meaning the total number of users is probably much, much larger. 

None of this is visible to the end-user.

This isn’t purely theoretical, either. Citizen Lab found multiple examples of how the network’s been abused, from Vietnam, to the African continent. One particular case describes “likely state-sponsored activity” used to identify behavioral patterns of users in Saudi Arabia who were traveling to the United States. 

The researchers didn’t blame any one company or country, but rather said this is the fault of the entire telecommunications industry that lacks proper security standards, as well as legislators as there’s an acute lack of legal or regulatory consequences.

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Data breach
Privacy of millions worldwide compromised as huge data location broker got hacked
Photograph of a hand holding a smartphone with two googly eyes
Every tap, every message – how to stop your smartphone spying on you
Kaspersky Report on Stalkerware
Security flaw in popular stalkerware apps is exposing phone data of millions
Find My app logo displayed on an iPhone 11 screen
This Find My exploit lets hackers track any Bluetooth device – here’s how you can stay safe
Stalkerware
New spyware found to be snooping on thousands of Android and iOS users
 In this photo illustration a Google Play logo seen displayed on a smartphone.
Why is there so much spyware hidden in the Play Store?
Latest in Security
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Latest in News
Oura Ring 4
Activity tracking on Oura Ring is about to get a whole lot better, but I've got bad news about your step count
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
Millwall FC The Den
The UK's first football club mobile network is here - but you probably won't guess which team has launched it
Android Auto
Android Auto 14.0 is rolling out now – and it'll soon swap Google Assistant for the smarter Gemini
The Witcher 4
You're probably not playing The Witcher 4 until 2027 at the earliest, per CD Projekt's latest financial update