By Cyber Defense Technologies February 17, 2026 4 min read
For government officials, military personnel, defense contractors and anyone in a sensitive role, the phone is a remarkably rich target. It holds email, messages, contacts, calendars, photos, authentication apps and a continuous record of location. It travels everywhere, connects to many networks, and is often used for both official and personal purposes.
Adversaries have noticed. Mobile devices are targeted by criminals seeking credentials and money, and by state-sponsored actors seeking intelligence.
How mobile devices are attacked
Phishing by text and messaging apps
"Smishing" and messaging app lures deliver malicious links that lead to credential theft or malware. Small screens make suspicious details harder to spot.
Malicious and over-permissioned apps
Apps from unofficial sources, or even official stores, can request excessive permissions to access messages, contacts, location or microphone.
Advanced spyware
Commercial spyware and state-developed tools have been used against journalists, activists, officials and others. Some have exploited previously unknown vulnerabilities to compromise devices with minimal or no user interaction, known as zero-click attacks.
Network-level interception
SMS messages and traditional voice calls are not end-to-end encrypted. Fake base stations and compromises of telecommunications networks can expose them. In late 2024 and 2025, U.S. and allied agencies described state-sponsored compromise of telecommunications providers, and reporting indicated that communications of some government and political figures were targeted.
SIM swapping
Attackers convince a carrier to move a victim's number to a SIM they control, intercepting calls and text-message authentication codes.
Physical access
Lost, stolen or briefly unattended devices can be accessed or tampered with, especially at borders or while traveling.
Government guidance
In December 2024, CISA published mobile communications best practice guidance for highly targeted individuals, such as senior government officials and politicians. Its recommendations include using end-to-end encrypted messaging, moving away from SMS for multifactor authentication in favor of phishing-resistant methods, using password managers, setting a carrier PIN to protect against SIM swapping, keeping software updated, and using platform-specific protections.
Mobile protections for high-risk users
- Keep operating systems and apps fully updated
- Use end-to-end encrypted communication apps
- Avoid SMS for multifactor authentication; use phishing-resistant methods
- Enable the platform’s high-security or lockdown mode where available
- Restart devices regularly
- Install apps only from official stores, and review permissions
- Use a carrier PIN or account lock to prevent SIM swapping
- Keep official and personal use separate
Protecting high-risk users
Keep devices updated
Updates fix vulnerabilities, including those used by advanced spyware. Replace devices that no longer receive updates.
Use end-to-end encrypted communications
For sensitive conversations, use approved end-to-end encrypted apps rather than SMS or traditional calls, within the rules your organization sets for official communications.
Strengthen authentication
Avoid SMS for multifactor authentication. Use phishing-resistant methods such as security keys or passkeys.
Enable high-security modes
Some mobile platforms offer high-security modes that reduce the attack surface available to sophisticated spyware at some cost in convenience. For users at elevated risk, the trade-off is often worthwhile.
Restart regularly
Some mobile exploits do not survive a reboot. Regular restarts can disrupt certain attacks.
Control apps
Install only from official stores, review permissions, and remove apps that are no longer needed. Organizations can enforce this through mobile device management.
Separate official and personal use
Use managed government or corporate devices for official work, with appropriate management and protections, rather than mixing sensitive work into personal devices.
Travel carefully
For sensitive travel, consider loaner devices, minimal data and heightened vigilance, following your organization's travel security guidance.
For organizations
- Manage devices used for official business with mobile device management and compliance policies.
- Include mobile in threat modeling for high-risk users.
- Monitor for compromise indicators where tools allow, and have a response plan for suspected mobile compromise.
- Train users on smishing, app risks and reporting.
- Protect accounts tied to phone numbers from SIM-swap attacks.
Frequently asked questions
Can a phone be compromised without the user doing anything? Advanced spyware has used zero-click exploits in some cases. Keeping devices updated and using high-security modes reduces this risk.
Is SMS-based MFA better than nothing? Yes, but it is vulnerable to SIM swapping and interception. Phishing-resistant methods are much stronger.
How would someone know their phone is compromised? Advanced compromises are designed to be invisible. If compromise is suspected, contact your security team rather than trying to investigate alone.
What to do this week
- Confirm all managed devices run a supported, fully updated operating system.
- Move high-risk users from SMS-based MFA to phishing-resistant methods.
- Ask carriers to add account PINs or port-out protection for high-risk users' numbers.
- Review mobile app permissions policies in your device management platform.
- Brief senior staff on the CISA mobile guidance and your organization's rules for official communications.
How CDT can help
CDT helps organizations protect high-risk users through penetration testing that includes mobile applications and APIs, social engineering assessments, and hands-on training, including mobile exploitation training on our field-deployable CRIB cyber range.