In the ongoing conflict between the United States and Iran, a new layer of complexity has emerged: the use of mobile location data to track US personnel. This revelation not only underscores the sophistication of cyber warfare but also raises critical questions about the vulnerabilities of commercial location data and the potential implications for global security. While the US Central Command has acknowledged receiving threat reports concerning adversary exploitation of commercial location data, the specifics of these threats and their impact remain shrouded in secrecy. However, the Financial Times (FT) has shed some light on this issue, citing data from the Mobile Surveillance Monitor research project. According to the report, regional telecom networks in West Asia fended off a wave of requests, called SS7 pings, which sought to pin down the locations of specific phones roaming outside their home networks. This coordinated campaign, potentially led by Iran or its allies, exploited a loophole in the early infrastructure of phone networks, allowing operators to obtain a rough location of phones. The implications of this are far-reaching. For one, it highlights the ease with which adversaries can exploit commercially available advertising databases to track phones in Iraqi Kurdistan, where US military personnel and contractors are based. This raises a deeper question: how secure are our personal data when it comes to location tracking, and what steps are being taken to protect it? From my perspective, the use of SS7 pings by Iran to track US users is particularly concerning. It underscores the need for robust cybersecurity measures and the importance of protecting personal data. The fact that Iran has the technical ability to send SS7 pings beyond its borders is a stark reminder of the global reach of cyber threats. What many people don't realize is that this is not an isolated incident. Iran has been known to exploit the SS7 pings in the past, and the Department of Homeland Security has highlighted Iran as among the primary countries using SS7 to target US subscribers. This raises a broader question: how effective are our current cybersecurity measures in the face of such threats? In my opinion, the use of mobile location data to track US personnel is a wake-up call for both governments and individuals. It is a stark reminder of the importance of cybersecurity and the need to protect personal data. The implications of this incident extend beyond the immediate conflict between the US and Iran. It raises questions about the security of personal data in an increasingly interconnected world. As we move forward, it is crucial to address these vulnerabilities and implement robust cybersecurity measures to protect against future threats. The use of mobile location data to track US personnel is a complex issue with far-reaching implications. It is a reminder of the need for vigilance and the importance of protecting personal data in an increasingly digital world.