First Public Telegraph Line & Wiretap Vulnerability
Samuel Morse transmitted the first message ("What hath God wrought") over the Baltimore–Washington line on May 24, 1844, exposing physical wiretapping along unencrypted DC lines almost immediately.
Samuel Morse transmitted the first message ("What hath God wrought") over the Baltimore–Washington line on May 24, 1844, exposing physical wiretapping along unencrypted DC lines almost immediately.
Alexander Graham Bell was granted US Patent 174,465 for the telephone, introducing analog voice circuits that immediately opened new attack surfaces for inductive and galvanic eavesdropping.
Undertaker Almon Strowger patented the first automated stepping switch after suspecting manual telephone operators were diverting his business calls to a competing undertaker.
Bell Labs and Alan Turing developed SIGSALY (Project X), the world's first digital voice encryption terminal, securing high-level Allied communications between Washington and London during WWII.
Seven-year-old blind boy Joe Engressia discovered that whistling an exact 2600 Hz pitch into a receiver reset AT&T toll trunk lines, founding the phone-phreaking movement.
John Draper ("Captain Crunch"), Steve Wozniak, Steve Jobs and others built Blue Boxes that emitted 2600 Hz plus MF digit tones to make free global calls, industrializing the SF signaling flaw.
Ron Rosenbaum published 'Secrets of the Little Blue Box' in Esquire, exposing the technical mechanics of 2600 Hz phone phreaking, Captain Crunch, and homebrew Blue Box construction to a global audience.
AT&T deployed Common Channel Interoffice Signaling (CCIS) across its toll network, separating call control signaling into a dedicated data network and neutralizing acoustic blue box toll fraud.
Phreakers engineered specialized Red Boxes simulating payphone coin drop frequencies (1700 Hz + 2200 Hz) and Silver Boxes with modified DTMF keypads to seize military Autovon priority override circuits.
Judge Harold Greene ordered the breakup of AT&T's monopoly into 7 Regional Bell Operating Companies (Baby Bells), creating multi-operator interconnects and new signaling boundaries.
Ameritech launched the first commercial 1G AMPS cellular network in Chicago, but cleartext transmission of ESN and MIN identifiers quickly led to widespread over-the-air cellular cloning.
John R. MacDougall overpowered HBO's satellite broadcast feed with a 2,000-watt transmitter to protest unscrambling subscription fees, exposing commercial satellite uplink vulnerabilities.
An unknown pirate broadcaster overpowered the terrestrial microwave Studio-Transmitter Links (STL) of WGN-TV and PBS station WTTW in Chicago, broadcasting distorted Max Headroom audio and video into thousands of homes.
TAT-8 became the first transoceanic fiber-optic cable in service, scaling transatlantic telecommunications capacity to 40,000 circuits and revolutionizing global data connectivity.
A single line of buggy C code in a 4ESS switch patch caused a cascading SS7 recovery storm on January 15, 1990, dropping roughly 60 million calls over nine hours.
The Communications Assistance for Law Enforcement Act (CALEA) forced US telecom carriers to design their networks so that lawful interception could be performed on demand — embedding a permanent surveillance capability into the core of every switch.
Tsutomu Shimomura and the FBI tracked and arrested Kevin Mitnick in Raleigh, North Carolina using direction-finding antennas and cellular switchboard real-time ESN/MIN location triggers.
Underground syndicates commercialized "Clone King" EPROM modification kits, allowing widespread cellular subscription fraud and free international calls across North American carriers.
David Wagner and Ian Goldberg (UC Berkeley ISAAC Group) completely cracked the GSM COMP128-1 algorithm, allowing extraction of SIM master keys (Ki) and physical cloning of SIM cards.
Hackers breached T-Mobile's backend web customer-care interface, gaining unauthorized access to Danger cloud servers and publishing private celebrity phonebooks, SMS logs, and photos.
Court disclosures and Freedom of Information filings revealed the widespread deployment of commercial IMSI-catchers (Harris StingRay) by law enforcement and intelligence agencies to perform unauthenticated mobile tracking.
Dan Kaminsky disclosed a fundamental DNS cache-poisoning flaw affecting core ISP resolvers worldwide, in the same year that BGP origin-validation failures caused the Pakistan Telecom and YouTube hijacks.
The US House Permanent Select Committee on Intelligence published a bipartisan investigative report concluding that Huawei and ZTE equipment posed systemic national security risks to critical telecom backbones.
Joshua Drake (Zimperium) disclosed multiple critical vulnerabilities in Android's Stagefright media engine that allowed attackers to execute remote code on 950 million phones via a single silently received cellular MMS video message.
Security researchers published proof-of-concept exploits showing that WebRTC JavaScript APIs in Chrome and Firefox sent unauthenticated STUN packets that bypassed active VPN tunnels and leaked the user's real public and private LAN IP addresses.
The FCC and ATIS/SIP Forum finalized the STIR/SHAKEN framework, mandating cryptographic digital signature validation on SIP interconnects to combat caller ID spoofing and fraudulent robocalls.
An attacker only had to ring a WhatsApp call. NSO Group's Pegasus implant was delivered to ~1,400 targets through a buffer overflow in the VoIP call stack — the victim never had to answer, and the missed-call log was the only trace.
Federal indictments exposed international cybercrime rings bribing retail store employees at AT&T, Verizon, and T-Mobile to execute unauthorized SIM swaps, stealing tens of millions of dollars in cryptocurrency.
A misconfigured BGP routing filter inside Vodafone Idea (AS5583) leaked over 30,000 global BGP routing prefixes to international transit provider Telstra, rerouting massive volumes of global telecommunications and Google DNS traffic into India.
Attackers executed an unauthorized SIM swap against the phone number tied to the US SEC official X account, broadcasting a fraudulent Bitcoin ETF approval that caused hundreds of millions in market swings.
Chinese APT group Salt Typhoon breached the core networks of major US telecom providers — AT&T, Verizon, Lumen and others — reaching CALEA lawful-intercept systems and sustained metadata and audio collection across at least nine carriers.
Days before the New Hampshire primary, a cloned AI voice of President Biden urged Democrats not to vote. The FCC responded within weeks by ruling that AI-generated voices are "artificial" under the Telephone Consumer Protection Act — making AI voice robocalls illegal outright.
Sophisticated social engineering syndicates deployed zero-shot generative voice-cloning models to synthesize real-time conversational audio of corporate executives, bypassing carrier voice biometrics and executing multimillion-dollar SIM swaps and wire transfers.
SpaceX Starlink and T-Mobile rolled out commercial Direct-to-Cell satellite service, deploying LEO satellites equipped with onboard 3GPP eNodeB cellular base stations connecting standard unmodified LTE/5G smartphones from space.