The Ghost in the Airwaves: Why Legacy Pagers and Plaintext Radio Are a Ticking Time Bomb

The Ghost in the Airwaves: Unmasking the Critical Vulnerabilities of Legacy Paging Networks

In modern cybersecurity, we often fixate on the complexities of cloud-native infrastructure, supply chain attacks, and sophisticated ransomware campaigns. We build robust perimeters, implement Zero Trust, and obsess over encrypted endpoints. Yet, hiding in plain sight—operating on infrastructure dating back to the late 20th century—is a massive, unencrypted data leak that would be unthinkable if it were part of our digital web architecture.

I’m talking about the legacy paging networks still utilized by emergency services, hospitals, and critical infrastructure.

A recent 3.5-hour study conducted in the UK highlights the startling reality of this oversight. Using nothing more than a standard HackRF SDR (Software Defined Radio) and freely available open-source decoding software, a total of 187 individual messages were intercepted. This wasn’t a targeted attack against a high-value entity; it was a passive capture of ambient radio noise. The results serve as a sobering proof-of-concept for why relying on legacy technology for critical communication is a profound security failure.

A Window Into Private Lives

The intercepted data reveals that these networks are not merely carrying “system codes.” They are pipelines for highly sensitive, often PII (Personally Identifiable Information) and health-related data. Over the course of just a few hours, the capture included:

  • Clinical Privacy Violations: Messages contained patient-specific medical details, including critical organ donor fast-track alerts, primary angioplasty status updates (complete with direct phone numbers for coordination), and private nurse contact instructions.
  • Operational Exposure: Real-time location data for fire and rescue services was broadcast continuously, including precise map references for wildfires and incident locations for road traffic accidents.
  • Detailed Incident Intel: Responders received granular details on active emergencies—such as vehicle status (e.g., “person trapped,” “vehicle flipped on roof”) and victim descriptions—broadcast across the airwaves.
  • Data Leakage by Proxy: Even private residential details were exposed, including names, telephone numbers, and full addresses for pet owners involved in veterinary emergency calls.

In any modern digital system, this data would be subject to rigorous encryption, access control, and audit logs. On these legacy radio networks, it is effectively broadcast in the clear to anyone with a $300 SDR receiver and a basic antenna.

The Myth of “Security by Obscurity”

The continued reliance on these protocols—predominantly POCSAG—is often defended by the “it just works” argument. These systems are rugged, offer excellent building penetration, and are arguably more reliable than cellular networks during a total infrastructure failure.

However, defenders of this legacy stack are relying entirely on security by obscurity—the outdated assumption that because the frequencies are old and the protocols are obscure, nobody is listening.

That assumption has been rendered obsolete by the democratization of SDR technology. High-quality software-defined radios are now cheaper and more accessible than ever, and the technical barrier to entry for decoding these signals is effectively zero. A researcher or a malicious actor doesn’t need to bypass a firewall or crack an encrypted database; they simply need to be in range.

The Cost of Stagnation

The risk here is not just an individual data breach; it is a systemic vulnerability in critical infrastructure. When we fail to evolve our communication protocols as the threat landscape changes, we leave the door open for passive reconnaissance, operational disruption, and the widespread exposure of sensitive citizen information.

This is a failure of modernizing security postures. Keeping a legacy system online might save money in the short term, but it creates a massive, unmanaged liability in the long term.

As security researchers, we must view these findings as a clear signal. The continued use of unencrypted paging networks is a glaring hole in the national critical infrastructure. It is time to treat these radio-based communication systems with the same security rigor we apply to every other digital channel—because as long as the data is flying through the air unprotected, the “Ghost in the Airwaves” will continue to be a very real, very public threat.