Home / Blog / TSCM

Mobile networks and attorney-client privilege: risks and secure communication

13 min read TSCM
Mobile networks and attorney-client privilege: risks and secure communication
An ordinary phone call seems to be one of the simplest ways for a lawyer to communicate with a client. Yet mobile communication is a complex technical system in which the handset, the SIM card, base stations, the operator's network, and inter-operator infrastructure all interact at once. That is why, when discussing information covered by attorney-client privilege, it is important to understand not only how convenient such a channel is, but also its potential technical risks.

From 2G to 5G: networks change, older technologies remain

Mobile communication has gone through several generations of development: from the earliest networks to 2G, 3G, 4G, and today's 5G. Each new generation brought changes in speed, network architecture, and security mechanisms.
However, the arrival of a new technology does not mean that the previous one stops working overnight.
In Ukraine, the pilot rollout of 5G is already under way. Test networks have been launched in several cities, and in July 2026 the pilot was extended to Kyiv as well. At the same time, a full-scale nationwide transition to 5G has not yet taken place.
In parallel, operators are gradually phasing out 3G and reallocating those frequencies in favour of 4G. During 2026, for example, such shutdowns have already taken place in individual localities in Ukraine.
At the same time, 2G still has practical significance. Legacy networks may be used for voice calls, SMS, the operation of certain devices, and to maintain compatibility across mobile infrastructure.
Where coverage of a more modern network is insufficient, a handset may also fall back to an older technology that is available, provided both the operator and the device support it.
This is precisely where an important information-security point arises: a modern smartphone does not always mean that every communication session takes place exclusively over the newest standard.

Why legacy protocols remain a problem

Mobile networks and attorney-client privilege: confidential communication
When discussing information covered by attorney-client privilege, it is important to weigh not only the convenience of a call but also the technical risks of the channel
2G was created in a completely different technological environment. Many architectural decisions of that period were based on a far higher level of trust between the participants in telecommunications infrastructure than is realistic today.
Signalling System No. 7 — SS7 — deserves particular attention. This signalling system has been used for decades to enable interaction between telecommunications networks, including for routing certain services, subscriber mobility, and roaming.
The problem is that SS7 was designed at a time when access to operator infrastructure was limited to a much narrower list of trusted participants. Today's global telecommunications system has become far more complex.
The GSMA states directly that the legacy SS7 architecture carries known security risks, and that its characteristics can be exploited for attacks involving subscriber location, SMS, and other telecommunications services.
In addition, international roaming requires the networks of different operators to interoperate. For that reason, the problem cannot always be solved simply by upgrading the equipment of one particular mobile provider.
An operator may deploy filtering, anomaly-detection systems, and other protective measures, yet it still operates as part of an international telecommunications ecosystem.

Where mobile communication can be compromised

The risks are not limited to weaknesses in a particular communication standard. Potential compromise can arise at different levels of mobile infrastructure.
One of them is unauthorised insider access.
Depending on their duties, an operator's employees may have different levels of access to technical systems. Operators therefore have to apply separation of privileges, activity logging, internal controls, and other information-security measures.
The human factor, however, can never be eliminated entirely. If a person with the relevant authority abuses their access, or if their account is compromised, that creates a distinct risk.
Another vector is cyberattacks aimed directly at the operator's infrastructure.
A mobile operator is a large information and telecommunications system. Like any complex infrastructure, it can become a target for attackers.
So when a lawyer uses an ordinary mobile call, they are in effect relying not only on their own smartphone, but on the security of the entire infrastructure through which the communication passes.

Fake base stations

Another well-known class of threats is equipment capable of imitating elements of a mobile network.
A handset continuously interacts with the operator's base stations and selects an available network according to parameters defined by the protocol. The user does not normally control that process manually.
Under certain conditions, specialised equipment may attempt to pass itself off as an element of the mobile network. Technologies of this kind are often referred to as fake base stations or IMSI catchers.
Their capabilities depend on the network generation, the operator's configuration, the specific handset, and other technical conditions.
For a lawyer, the underlying principle is what matters: one should not assume that because a phone shows an available mobile network, the user is automatically in a position to verify the entire infrastructure through which their communication travels.
That is exactly why the most confidential matters should not be discussed over an ordinary mobile channel merely because it feels familiar and straightforward.

SMS as a separate weak point

The risks of mobile networks concern more than phone conversations.
SMS is still used by a large number of services to confirm logins, reset passwords, or provide additional user verification.
In that situation, compromising SMS can have consequences that reach far beyond mobile communication itself.
For example, if an outsider has already obtained the password to a given service but needs an SMS code to complete the login, the mobile number becomes the last line of defence.
The situation is even more serious where a service allows account access to be restored primarily through a phone number.
As a result, a mobile-communication security problem can turn into a security problem for email, a messenger, a social network, or another account.
For business-critical services, therefore, it is worth avoiding any situation in which SMS is the only mechanism protecting an account.

The operator sees more than the content of a conversation

Using a mobile network generates a significant volume of technical information.
To provide the service, the operator needs to know that a particular subscriber is present on the network, which part of the network is serving them, and how to route a call or a data transfer.
Ukrainian legislation expressly treats as data processed by providers of electronic communications services, among other things, information about the fact that a service was received, data transmission routes, and information about the location of terminal equipment.
This does not mean that the operator continuously determines the precise GPS coordinates of every subscriber.
A mobile network does, however, technically need to know which part of the infrastructure a device is interacting with. In the course of that operation, records may be generated about connections, the network elements used, and other technical parameters.
Data of that kind is often referred to as metadata.

Metadata can also be confidential

Even without access to the content of a particular conversation, metadata can reveal a great deal about a person.
If it is known who someone communicates with regularly, at what times their calls take place, and in which areas they use the mobile network, then a large number of such events can be assembled into a pattern of behaviour.
It becomes possible, for instance, to establish how regular the activity is, what the typical routes are, or which contacts are consistent.
For a lawyer, this aspect is especially significant.
It is not only the conversation with the client that may be confidential. In certain situations, what matters is the very fact that a particular person is in regular contact with a particular lawyer, or that their devices are present in particular locations.
Protecting attorney-client privilege should therefore not be reduced to a single question: “Can the content of a phone conversation be overheard?”
There is also information about the fact of the communication itself and about its technical characteristics.

Leaks of operator data

The data held by an operator must also be regarded as an information asset.
Operators are required to protect end-user data. Yet any large information system can potentially become the target of a cyberattack, insider abuse, or other unauthorised access.
Various sets of personal and technical data obtained through leaks or unlawful access to information systems may end up circulating illegally.
It is therefore important for a lawyer to recognise that part of the information generated while using a mobile network lies outside their direct control.
This is the fundamental difference between ordinary mobile communication and a system whose infrastructure the user or the organisation controls itself.

An ordinary call or a messenger

An ordinary mobile call and a secure communication channel for a lawyer
A secure messenger changes the trust model for the content of a conversation, but it does not make the device invisible to the network
During an ordinary phone call, a lawyer relies on the mobile operator's telecommunications infrastructure.
With a modern secure messenger, the model can be different.
If the messenger implements end-to-end encryption properly, the mobile operator provides internet access but should not obtain the plaintext content of the conversation held through the messenger.
That does not make a messenger absolutely safe. The service's servers, the endpoint devices, the accounts, and other risks remain, and each has to be assessed separately.
The trust model, however, changes fundamentally.
In an earlier article we already looked at the use of secure messengers and, for systems with heightened confidentiality requirements, at running your own communications infrastructure. The broader approach to protecting lawyer-client confidentiality also covers devices, premises, and digital traces.
Under such a model, the mobile network is used mainly as a channel for internet access, while the confidential communication itself takes place inside a separate protected system.

You cannot disappear from the operator's network entirely

At the same time, even using a messenger does not mean that the mobile operator drops out of the technical chain completely.
If a smartphone is connected to mobile internet, it still registers on the operator's network and uses its base stations.
The operator therefore continues to handle the very fact that the device is connected to the network.
A secure messenger primarily changes the protection of the content of the communication, but it does not make a mobile device invisible to the telecommunications network.
In the same way, changing a device's technical identifiers should not be treated as a universal means of achieving anonymity. Beyond the technical limitations, manipulating such identifiers may carry legal consequences of its own.
Practical recommendations for a lawyer should therefore aim not at trying to “hide” from the way the mobile network works, but at choosing the right channel for particular information.

First contact and subsequent confidential communication

In practice, giving up ordinary phone calls altogether is difficult.
A new client may find a lawyer's number on a website, through a referral, or in another open source, and simply call in the usual way. Requiring every person to install a specific secure application before any first contact is often unrealistic.
Ordinary mobile communication may therefore remain the channel for initial contact.
It is important, however, to separate that first contact from the subsequent discussion of confidential information.
During the first call, you can establish who is making the enquiry, determine the general nature of the matter, and agree on the channel to be used from then on.
If the further conversation will involve information covered by attorney-client privilege, it makes sense to move to a secure communication channel agreed in advance.
In this way, the ordinary phone number remains available to the client, but it is not necessarily used for a detailed discussion of the most sensitive circumstances of the case.
The condition of the device itself also deserves separate assessment: our article on how to tell if your phone is being tapped helps clarify which risks relate specifically to the endpoint equipment rather than to the operator's network.

Conclusion

The development of 4G and 5G has significantly raised the technological level of mobile networks, but new standards do not automatically eliminate the risks associated with older telecommunications infrastructure.
2G and the legacy mechanisms tied to it still have practical significance, and global interoperability between operators relies on complex inter-network infrastructure, including SS7.
For a lawyer, the risk is not limited to the possible interception of voice. It is also necessary to take into account the security of the operator's infrastructure, the possibility of unauthorised insider access, fake base stations, the risks of SMS-based authentication, and the existence of metadata about the fact of the communication.
A mobile operator, meanwhile, technically processes the information required for the network to function, including data relating to servicing a device and to its location within the network infrastructure. So even without access to the content of a conversation, certain information about communication activity exists.
The practical approach is not to abandon mobile communication altogether. An ordinary call can be used for initial contact with a client, but the most confidential matters are better moved to secure channels agreed in advance.
The more sensitive the information, the more important it is for a lawyer to understand which infrastructure carries it, who controls that infrastructure, and what technical traces the communication itself leaves behind.
Making an informed choice of communication channel is one of the elements of protecting attorney-client privilege today.

Mobile networks and attorney-client privilege

Need to assess the risks of mobile communication with a client?

The ProDefence team can help define the threat model for calls, SMS, and metadata, and propose a practical format for a secure channel — without unsupported guarantees of “absolute security”.

Request a consultation

Confidential. No requests for seed phrases or private keys.