Executive Summary
In September 2025, the U.S. Secret Service announced it had dismantled a large-scale illicit telecommunications infrastructure across the New York tri-state area, seizing over 300 SIM servers and 100,000 SIM cards. These devices, co-located at multiple sites, were used by unknown malicious actors to facilitate threats against U.S. government officials, particularly near the United Nations. Investigators discovered that this network enabled covert communications and potentially enabled bypasses of monitoring controls, raising national security concerns. The takedown required coordinated federal action to secure the assets, neutralize the risk, and support ongoing intelligence operations.
This incident highlights the ongoing evolution and physical sophistication of threat actor infrastructure, especially targeting high-profile government personnel. The scale and automation facilitated by such hardware underline the growing intersection of physical and cyber threats and serve as a wake-up call for risk teams facing advanced, hybrid attack models.
Why This Matters Now
Organizations must recognize the urgency of securing both digital and physical infrastructure as attackers adapt and deploy covert, high-capacity tools to bypass traditional detection. With increased convergence of physical and cyber assets, proactive risk management is essential to prevent sophisticated, large-scale threats targeting government and sensitive sectors.
Attack Path Analysis
The attack began when adversaries physically compromised infrastructure by deploying covert SIM servers and cards in strategic locations. They then leveraged access to escalate privileges, possibly manipulating connected devices or associated cloud resources. Lateral movement enabled the attackers to link SIM infrastructure, creating resilient internal communications across multiple facilities. They established command and control channels using unencrypted or covert traffic to remotely operate the SIM network. Exfiltration of sensitive data or communications occurred over the unmonitored egress paths, potentially transferring intelligence outside secured environments. Ultimately, the attack posed direct threats to national security by enabling surveillance, data theft, or disruptive operations targeting U.S. officials.
Kill Chain Progression
Initial Compromise
Description
Attackers physically deployed and connected over 300 SIM servers and 100,000 SIM cards to local networks, gaining initial unauthorized access.
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Replication Through Removable Media
Indicator Removal on Host
Phishing
Data from Local System
Obfuscated Files or Information
Native API
Brute Force
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – User Identification and Authentication
Control ID: 8.2.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Art. 11
CISA ZTMM 2.0 – Continuous Asset Discovery
Control ID: Asset Management: Continuous Asset Discovery
NIS2 Directive – Technical and Organizational Security Measures
Control ID: Art. 21(2)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Direct target of SIM server network threatening U.S. officials requires enhanced encrypted traffic monitoring and zero trust segmentation for protective intelligence operations.
Law Enforcement
Physical infrastructure compromise of telecommunications devices near UN demands strengthened east-west traffic security and threat detection capabilities for national security protection.
Telecommunications
SIM server seizure exposes vulnerabilities in mobile infrastructure requiring multicloud visibility, egress security enforcement, and inline intrusion prevention system deployment.
Computer/Network Security
Investigation reveals need for cloud native security fabric and anomaly detection to prevent covert communication networks targeting government officials and facilities.
Sources
- U.S. Secret Service Seizes 300 SIM Servers, 100K Cards Threatening U.S. Officials Near UNhttps://thehackernews.com/2025/09/us-secret-service-seizes-300-sim.htmlVerified
- Secret Service takes down network that could have crippled New York cell servicehttps://www.theguardian.com/us-news/2025/sep/23/secret-service-new-york-networkVerified
- US uncovers 100,000 SIM cards that could have 'shut down' NYC cell networkhttps://arstechnica.com/security/2025/09/us-uncovers-100000-sim-cards-that-could-have-shut-down-nyc-cell-network/Verified
- Secret Service agents dismantle network that could shut down New York cellphone systemhttps://www.aol.com/articles/secret-agents-dismantle-system-used-114945826.htmlVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Core CNSF controls—including Zero Trust Segmentation, East-West Security, traffic encryption, and egress policy enforcement—could have detected, contained, or prevented unauthorized device deployment, privilege abuse, covert lateral movement, and data exfiltration throughout the attack lifecycle.
Control: Zero Trust Segmentation
Mitigation: Unauthorized devices and network segments are isolated by identity-based access policies.
Control: Multicloud Visibility & Control
Mitigation: Central policy and real-time traffic observability reveal and restrict suspicious privilege changes.
Control: East-West Traffic Security
Mitigation: Internal lateral movement attempts between servers are detected and blocked.
Control: Inline IPS (Suricata)
Mitigation: C2 activity is detected and disrupted at the network layer via real-time inspection.
Control: Egress Security & Policy Enforcement
Mitigation: Unapproved outbound data movements are detected and blocked by egress filtering.
Anomalous device behavior and operational threats are rapidly detected and investigated.
Impact at a Glance
Affected Business Functions
- Emergency Services
- Telecommunications
- Financial Services
- Transportation
Estimated downtime: N/A
Estimated loss: N/A
No data exposure reported. The primary risk was the potential disruption of telecommunications services, which could have led to significant operational and financial impacts across various sectors.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce Zero Trust Segmentation to prevent onboarding of unauthorized devices or rogue SIM infrastructure into critical networks.
- • Deploy east-west traffic inspection and microsegmentation to block covert lateral movement between internal assets and suspicious hardware.
- • Mandate centralized multicloud visibility and real-time policy controls to rapidly detect privilege escalations and network misconfigurations.
- • Implement strict egress filtering, threat detection, and network encryption (MACsec/IPsec) to disrupt exfiltration and command & control activity.
- • Regularly baseline, monitor, and investigate anomalous network and device behaviors to enable rapid incident response and containment.



