SS7 attack

An SS7 attack abuses the signaling protocols that interconnect mobile networks to intercept calls and SMS or track location, by sending network-internal queries from a rogue interconnect. Because the attack operates below the handset, neither the victim nor their apps see anything; an SMS one-time passcode can be read in transit without touching the victim's device.

The attack's significance is what it proves about the channel rather than how common it is. Interception at the signaling layer means the phone network cannot be treated as a private channel to a specific handset, which is the assumption an SMS passcode rests on. That holds whether or not any particular victim was targeted this way.

The defensive conclusion is about the channel rather than the attack's frequency. If signaling-layer interception is possible at all, then a code delivered over the phone network is not guaranteed to reach only the intended handset, and every control built on that guarantee inherits the uncertainty. This is part of why SMS OTP is treated as a restricted authenticator rather than a strong one.

Operators have deployed signaling firewalls and home-routing controls, and interconnect agreements have tightened, so this is not an unmitigated problem. What has not changed is that the relying party cannot verify any of it: a service sending a code has no way to know which interconnects its user's traffic traverses, and no way to detect an interception that leaves no trace on the handset.

That asymmetry is the reason to prefer factors whose security does not depend on the transport, such as origin-bound passkeys, and to check the state of the line itself where a phone-based factor is unavoidable.

Naming the attack precisely also matters when arguing about controls, since interception at the signaling layer, endpoint malware and real-time phishing all defeat an SMS code, and they call for different responses.

PasskeyBridge verifies identity signals like these inside the request, with zero PII stored. See how the platform works or test the live API.