Cyber Security News

U.S. Secret Service Shuts Down 300 SIM Servers and 100K SIM Cards Disabling Cell Towers

The U.S. Secret Service has dismantled a sophisticated network of electronic devices scattered across the New York tri-state area.

These devices posed an imminent threat to protective operations for senior government officials.

During a protective intelligence investigation, agents identified over 300 co-located SIM servers and 100,000 SIM cards deployed at multiple locations.

The servers and cards were assembled in clusters within a 35-mile radius of the United Nations General Assembly meeting now underway in New York City.

Discovery of the Device Network

The investigation began after the Secret Service received reports of anonymous telephonic threats directed at senior U.S. officials.

These calls appeared to originate from a vast network of SIM servers designed to conceal the true source of communication.

Further probing revealed that each server could host hundreds of SIM cards, enabling seamless rotation of numbers and identities.

This setup made it nearly impossible for standard telecom tracking methods to trace calls back to their origin. Agents discovered clusters of these servers hidden in homes, office buildings, and other nondescript sites.

Beyond facilitating anonymous threats, the network could carry out a range of telecom attacks.

Early analysis indicates the devices could disable cell phone towers, launch denial-of-service attacks on critical communications infrastructure, and support encrypted messages between nation-state threat actors and criminal enterprises.

Forensic examination of the seized hardware is ongoing, but initial data points to communications between known federal law enforcement targets and foreign operatives.

“The potential for disruption to our country’s telecommunications posed by this network of devices cannot be overstated,” said U.S. Secret Service Director Sean Curran.

To swiftly neutralize the threat, the Secret Service’s Advanced Threat Interdiction Unit led the operation. This new division focuses on the most significant and immediate dangers to protectees.

Key partners in the takedown included the Department of Homeland Security’s Homeland Security Investigations, the Department of Justice, the Office of the Director of National Intelligence, and the New York Police Department.

State and local law enforcement agencies also offered critical technical advice and assistance. While most of the network has been disabled, the investigation remains active.

Officials are analyzing data extracted from the servers and SIM cards to uncover the identities of those involved and any further plans they may have had. The swift action underscores the Secret Service’s commitment to prevention.

By dismantling this network before the UN meeting escalated, the agency sent a clear message: imminent threats to protected individuals will be traced and stopped without delay.

As forensic teams continue their work, the agency expects to reveal more details on how the network operated and who was behind it.

Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…

3 hours ago

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

4 hours ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

4 hours ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

4 hours ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

5 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

6 hours ago