Latest
When a Client Thinks the Ghostwriter Used AIThe Clients Who Pay and VanishWhat an AI Detector Score on Your Manuscript Is WorthWhen Your Memoir Should Be a NovelWhat Belongs on a Copyright PageThe One-Hour Call Before I Quote Your BookThe Work You Would Never Have StartedWhen Your Own Memoir Sounds Like BraggingMonthly or Milestone: How Ghostwriting Gets BilledWhat It Costs to Fix an AI-Written ManuscriptThe Quotation Marks That Get Authors SuedThe Hugging Face AI Agent Attack: An Operations ReadingBehind the Book: The Mysterious Island, Neb’s SideHow to Organize Decades of Memories Into a MemoirWhy Rotten Tomatoes Sucks: The Score Does Not Mean What You ThinkWhy Amazon KDP Sucks: They Terminated My Account OvernightIngramSpark: How I Publish Now and WhyWhy Fiverr Sucks for Ghostwriting: The Buyer’s SideWhy eBay Sucks Now: A Seller’s Numbers and a Buyer’s WarningThe Ghost Story TraditionThe Gothic TraditionThe Christmas Ghost Story TraditionBooks to Give a WriterResurrection as a Narrative StructureThe Beach Read ArgumentWhy It’s a Wonderful Life Failed on ReleaseWhat to Read in SpringWhat to Read in SummerWhat to Read in OctoberHow Warner Bros. Dismantled a $17 Billion Cartoon EmpireThe Imaginary Scarcity TrapThe Graph That Goes Vertical Is Usually Somebody Else’sSubstack Is Not Collapsing. The Promise Was.The Disasters That Happen to Ordinary PeopleToba: The Winter That Almost Ended UsJay Stifflemire: Nothing Ever Gets Written DownGeorgie-Ann Getton: I Forgot I Had Free WillAI Detection Cannot Be Evidence, and Publishing Is Using It That WayAI Consciousness Left Philosophy and Entered the LaboratoryThe Office Block Where the Bedrooms AreThe Web Got Fenced: What AI Search Costs Small SitesBlack Tuesday: The Web Ring War Nobody Outside It NoticedWhat the AI Visibility Industry Sells, and What the Evidence SaysBlack Tuesday: The Original ring-master.net Page, 2000Behind the Book: Peacekeeper, The Dissolution WarsBehind the Book: Real World SurvivalBehind the Book: Publish Your BookBehind the Book: ReincarnationBehind the Book: Sell Your BooksBehind the Book: Selling on eBay
The Writing King Your Ethical Ghostwriter. Your Story, Done Right.

Going Low-Tech Didn’t Save Them: The Pager Attack as a Supply Chain Lesson

This entry is part 6 of 13 in the series Nothing Is Isolated
TL;DR: Hezbollah went low-tech on purpose, trading trackable smartphones for simple pagers, and it did not save them, because the pagers themselves were the attack. The lesson reaches far past one militant group. Every organization buys hardware and software through layers of resellers and suppliers it will never meet, and trusts that what arrives is what it ordered. The pager attack is the most violent proof that this trust is a vulnerability. This is the sixth article in a series on attacks that beat isolation, and it takes the supply-chain lesson apart for anyone who buys anything.
Series Navigation  (13 parts)

There is a certain kind of security advice that sounds wise and is dangerous. Simplify. Go back to basics. The old technology was safer because it was dumber. I’ve heard versions of it my whole career, usually after a breach, usually from someone who wants a clean answer to a messy problem.

Hezbollah followed that advice to the letter. It gave up the powerful, connected, trackable smartphone for the simple, dumb, untrackable pager, and the simplification is exactly what killed its people. The previous article covered what happened. This one is about why the low-tech move failed, because the reason it failed is a warning for everyone who buys anything. That is all of us.

Why didn’t going low-tech protect Hezbollah?

Because low-tech solved the wrong problem.

The threat Hezbollah was defending against was surveillance. Smartphones leak location and can be turned into listening devices, so the group reasoned that a device with no GPS, no microphone, and no internet connection would close that hole. On that specific threat, the reasoning was sound. A pager genuinely cannot be tracked the way a phone can.

But the attack that came was not surveillance. It was sabotage, built into the device before Hezbollah ever touched it. And against that threat, simple versus sophisticated made no difference at all. A dumb device can hide a bomb just as well as a smart one, maybe better, because nobody is scanning a pager’s traffic or worrying about its firmware. Hezbollah moved from a threat it could see to a threat it could not, and felt safer the whole way.

This is the trap in the “go back to basics” advice. Simplifying a system reduces some risks and does nothing for others, and it can hide the ones it leaves behind a feeling of having done something. The centrifuge operators at Natanz felt safe behind their air gap. Hezbollah felt safe behind its pagers. Both had addressed the threat on their minds and left the flank open, and in both cases the attacker walked in through the flank.

What is a supply chain attack?

A supply chain attack is one where the attacker doesn’t come at you directly. They compromise something you buy or depend on, and let your own trust carry the attack the last mile.

You don’t build your own computers, write your own operating system, or manufacture your own network hardware. Nobody does. You buy them, from companies you mostly don’t know, who buy parts from other companies you’ve never heard of, assembled in places you’ll never see. Every product that arrives at your door is the end of a chain of hands, and you trust the whole chain because you have no practical choice. Checking it yourself, all the way down, is impossible.

The attacker’s insight is simple. Why fight through your defenses when you’ll happily install their code or plug in their device yourself, as long as it arrives wearing the label of someone you trust? The pager attack is that insight taken to its most extreme conclusion. Israel didn’t break into Hezbollah’s supply chain. It became Hezbollah’s supply chain, building a real company that sold a real product, so the weapon arrived through the front door as a normal purchase.

The genius and the horror of becoming the supplier

I want to be precise about what made this work, because this is what translates to every other field.

Israel reportedly didn’t intercept a shipment and tamper with it. Interception is the older, cruder method, and it leaves seams: a delayed package, a resealed box, a serial number that doesn’t match. Israel built a legitimate business instead. A company in Budapest with real staff, real clients, and a genuinely good product, established over time until it was simply a known vendor in the market. Then it steered the compromised devices to the target through ordinary sales.

Sit with the defensive nightmare in that. There was no seam to find. The company was real. The product worked. The paperwork was clean. Hezbollah could have run every check available to a careful buyer, inspected the devices, tested them, verified the vendor, and found nothing, because there was nothing to find until the moment the devices were told to detonate. A supplier who is patient enough to be genuine for years is a supplier no inspection can catch.

Strip the explosives away and this is the exact thing that keeps security professionals awake. A trusted vendor, built up over years, delivering a compromised product through legitimate channels. Swap the bomb for a hidden hardware implant, a backdoor in the firmware, or a poisoned piece of software, and the pager attack is just the bloodiest version of a risk that runs under every organization on earth.

Does this reach ordinary organizations, or just militant groups?

It reaches everyone, and the rest of this series is the proof.

Nobody is going to build a bomb into your laptop. But the structure of the pager attack, the compromised thing delivered through a trusted channel, is the single most common way large organizations get breached, and the articles ahead walk through case after case.

A software company’s routine update, signed and shipped to thousands of customers, carries an attacker’s code because the company itself was compromised first. A retailer loses millions of credit cards because attackers got in through the account of a heating and cooling contractor nobody thought of as a security risk. A core piece of software that runs on much of the internet is quietly backdoored by a volunteer who spent two years earning the right to touch it.

None of those needed a bomb. Each one used the same move Israel used against Hezbollah: get inside the chain of trust, and let the target install the attack themselves. The pager attack is the extreme, physical version that makes the pattern impossible to look away from. The software versions kill no one and happen constantly, and most of them never make the news.

What can an organization do about supply chain risk?

Less than we’d like, and more than nothing, and both halves matter.

The hard limit first. You cannot fully verify a supply chain. You cannot take apart every device, audit every line of code in every update, or trace every component to its origin. A determined, well-resourced attacker who becomes your supplier can beat any check a normal organization can run. That was the whole point of the pager attack, and pretending otherwise sells a false comfort I won’t sell.

What you can do is stop treating trusted as a permanent state. A vendor being familiar is not evidence they’re safe today.

The practices that help all come from that shift. Buy from as few hands as possible, so the chain is short enough to reason about. Prefer suppliers who can show you how they secure their own process. Design your systems so one compromised component can’t reach everything.

That last one matters most. Hezbollah’s failure wasn’t only that the pagers were rigged. It was that thousands of people carried the same compromised device, so one betrayal reached them all at once. A system where any single trusted thing can take down the whole is a system waiting for its supplier to turn.

And treat the contractors, vendors, and dependencies at the edge of your operation as part of it, because the attacker already does. The heating contractor, the small software library, the reseller two steps removed, none of them feels like your security perimeter, and every one of them is. The diagram on the wall shows the systems you own. The attack comes through the ones you merely trust.

The next articles leave the physical world and follow this exact pattern through the biggest software supply chain attacks on record, starting with a company that sold spying dressed as security for half a century. For the wider view, the cybersecurity hub collects the rest of my work on this.

Frequently Asked Questions

Why didn’t switching to pagers protect Hezbollah?
Because the low-tech switch solved the wrong problem. Pagers do close the surveillance hole that smartphones open, since they have no GPS, microphone, or internet connection. But the attack was sabotage built into the device during manufacture, and against that a simple device offers no protection at all. Hezbollah defended against a threat it could see and left itself open to one it could not.
What is a supply chain attack?
A supply chain attack is one where the attacker compromises something you buy or depend on instead of attacking you directly, and relies on your own trust to carry the attack the rest of the way.

Because no organization builds its own hardware and software from scratch, everyone trusts a long chain of suppliers they cannot fully verify, and the attacker exploits exactly that trust.

How was the pager attack a supply chain attack?
Israel reportedly did not intercept and tamper with a shipment. It built a legitimate-looking business with real staff, real clients, and a genuinely good product, established it as a known vendor, and then steered the rigged devices to Hezbollah through ordinary sales. It became the supply chain instead of breaking into it, so the weapon arrived as a normal, trusted purchase.
Could inspection have caught the rigged pagers?
Almost certainly not. The vendor was a real company, the product worked as a pager, and the paperwork was clean. There was nothing wrong with the devices as devices until the moment they were told to detonate. A supplier patient enough to be genuine for years is one that ordinary inspection and vendor checks cannot catch.
Does supply chain risk affect normal businesses or only militant groups?
It affects everyone. Nobody is going to build a bomb into a business laptop, but the structure of the attack, a compromised product delivered through a trusted channel, is one of the most common ways organizations get breached. Poisoned software updates, vendor account compromises, and backdoored open-source components all follow the same pattern without any explosives.
Can you fully protect against a supply chain attack?
No. You cannot take apart every device, audit every line of every update, or trace every component to its source, and a well-resourced attacker who becomes your supplier can beat any check a normal organization runs. What helps is shortening the chain, choosing suppliers who can show how they secure their own process, and designing systems so one compromised component cannot reach everything.
What is the main lesson of the pager attack for security?
That trusted is not a permanent state, and the edges of your operation, the contractors, vendors, and dependencies you rely on but do not control, are part of your attack surface whether or not they appear on your security diagram. The attack comes through the things you trust, not the things you defend, so the trust itself has to be examined.

Continue the Series

1. The Morris Worm |
2. Stuxnet: The History |
3. Stuxnet: Crossing the Air Gap |
4. Stuxnet: The Aftermath |
5. The Pager Attack |
6. The Pager Supply Chain |
7. Crypto AG |
8. Agent.btz |
9. NotPetya |
10. SolarWinds |
11. The Target Breach |
12. The XZ Backdoor |
13. The Line to AI

📝 Disclaimer

The views and opinions expressed in this blog post are solely those of Richard Lowe and are based on personal experience and research. This content is for informational purposes only and should not be construed as professional legal, financial, accounting, or business advice. Always consult with qualified professionals before making important business or legal decisions. Richard Lowe is not a lawyer, accountant, or licensed professional advisor, and this content does not establish any professional relationship.

0 comments

No comments yet. Yours can be the first.

Was this useful?

Leave a comment