1976
AT&T deployed Common Channel Interoffice Signaling (CCIS) across its toll network, separating call control signaling into a dedicated data network and neutralizing acoustic blue box toll fraud.
1988
CCITT standardized the SS7 protocol suite in 1988 across mobile and fixed networks, built on implicit operator trust with no authentication — the root cause of every later signaling attack.
1997
Underground syndicates commercialized "Clone King" EPROM modification kits, allowing widespread cellular subscription fraud and free international calls across North American carriers.
1998
Attackers spoofed ICMP Echo Requests to IP directed-broadcast addresses — including Portuguese academic backbones FCCN/RCTS — producing 100x amplification floods that downed victims' uplinks.
2005
Hackers breached T-Mobile's backend web customer-care interface, gaining unauthorized access to Danger cloud servers and publishing private celebrity phonebooks, SMS logs, and photos.
2008
Dan Kaminsky disclosed a fundamental DNS cache-poisoning flaw affecting core ISP resolvers worldwide, in the same year that BGP origin-validation failures caused the Pakistan Telecom and YouTube hijacks.
2014
Tobias Engel and SRLabs demonstrated at 31C3 that SS7 design flaws allow global subscriber location tracking, call interception, and SMS 2FA theft using legally obtainable access to the signaling network.
2015
Security researchers demonstrated that 4G LTE Diameter signaling networks inherited the unauthenticated trust vulnerabilities of SS7, allowing subscriber tracking and denial-of-service over IPX interconnects.
2017
Cybercriminals abused SS7 roaming interfaces to intercept bank-issued SMS one-time passcodes (OTPs), draining accounts of customers at O2 Germany and Metro Bank UK.
2017
Positive Technologies disclosed critical architectural flaws in GTP (GPRS Tunnelling Protocol) across 2G, 3G, and 4G networks, demonstrating how attackers on IPX roaming networks could hijack subscriber data sessions and execute over-the-air fraud.
2018
Attackers announced rogue BGP routes for Amazon Route 53 IP prefixes through Russian and Nigerian ISP transit, hijacking DNS traffic for MyEtherWallet to steal $150,000 in cryptocurrency.
2021
Federal indictments exposed international cybercrime rings bribing retail store employees at AT&T, Verizon, and T-Mobile to execute unauthorized SIM swaps, stealing tens of millions of dollars in cryptocurrency.
2021
A misconfigured BGP routing filter inside Vodafone Idea (AS5583) leaked over 30,000 global BGP routing prefixes to international transit provider Telstra, rerouting massive volumes of global telecommunications and Google DNS traffic into India.
2024
Attackers executed an unauthorized SIM swap against the phone number tied to the US SEC official X account, broadcasting a fraudulent Bitcoin ETF approval that caused hundreds of millions in market swings.