Skip to content
Answer Stack
Open menu

Is PSTN secure, and can PSTN calls be encrypted?

✓ Verified Last reviewed by AnswerStack Next review due Oct 18, 2026

Every claim is sourced below

The public switched telephone network offers almost no built-in security, and an ordinary landline call travels across it with no encryption, so it can be overheard by anyone who taps the copper line, gains access inside a telephone exchange, or reaches the signaling that controls the call.[1][9][12] The standard that defines how the PSTN digitizes voice, ITU-T G.711, encodes speech as pulse code modulation and includes no encryption of its own, and lawful interception is a designed-in feature of carrier switches rather than an add-on.[2][1][6] The control network behind call setup, Signaling System No. 7, was built on the assumption that connected operators could be trusted, and researchers and a US cybersecurity official have documented its use to track people and intercept calls and texts.[3][4][5] A PSTN call can be encrypted, but only by adding matching cryptographic equipment at both ends, such as the NSA's STU-III and its successor STE, or by moving the conversation off the circuit-switched network onto an IP path protected by protocols like SRTP.[7][8][11] The network itself never supplies the encryption, so any confidentiality has to come from the endpoints.[9]

Why is the PSTN considered insecure?

The PSTN carries a phone call as an open, unencrypted signal, which is the root reason it is considered insecure, because nothing in the network scrambles the audio and anyone who can reach the call can listen to it.[1][12] When the network digitizes voice for its core it uses pulse code modulation as defined in ITU-T Recommendation G.711, and that standard describes only how to sample and encode speech, not how to protect it, so a digital PSTN call is a stream of numbers that anyone with access can play back as sound.[2] Security was never a design goal for the telephone network. It grew up as a system run by trusted carriers whose staff needed to reach lines to maintain and connect them, and lawful interception was later built directly into the switches rather than added on afterward.[1][6]

Three consequences follow. The confidentiality of a normal call depends entirely on physical and operational trust in the carrier, because the signal gives nothing away for free. The places where a call can be reached, the subscriber line, the exchange, and the signaling network, sit outside a caller's control, so an ordinary user cannot inspect or harden them. Adding real confidentiality means changing the endpoints, since the network in the middle forwards whatever it is handed without adding or expecting encryption.[9]

This is different from how internet traffic has come to work, where encryption increasingly travels with the data by default. On the PSTN the data and the protection are separate concerns, and the network supplies only the transport. That design made the telephone system open and easy to interconnect across operators and countries, and those same properties are why a call is straightforward to intercept for anyone positioned on its path.[1]

A call on the PSTN can be reached at several distinct points, and each one calls for a different kind of access. The table summarizes the main exposure points, and the sections after it explain how each works and what it means in practice.

Exposure point What an attacker needs What it exposes
The subscriber line (local loop) Physical access to the copper pair at the building, a junction box, or a street cabinet The full audio of every call on that line [1]
The telephone exchange Access to the switch that serves the line An invisible copy of the call, with no sign the line is tapped [1]
Built-in lawful interception Legal authorization plus carrier action at the switch Any subscriber's calls, activated remotely by design [1][6]
The SS7 signaling network Connectivity into the inter-operator signaling network Call and text redirection and location tracking [4][5]

Tapping the subscriber line

The oldest and most direct attack is a physical tap on the line that runs to a phone, because that copper pair carries the conversation as an open signal all the way to the exchange.[1] The word wiretap comes from exactly this method, an electrical connection onto an analog telephone line that carried the audio off to a recorder.[1] The vulnerable stretch is the local loop, the wiring from a building back to the telephone exchange, and it can be reached at the premises, at a junction box, or out at a street cabinet. Because the signal is not encrypted, no code has to be broken once the wires are reached, and the tap simply listens.[1] For most of the network's history this was the practical limit on eavesdropping, since it required someone to be physically present on the line, which is also why it left behind the effort and evidence that later switch-based methods removed.

Interception inside the telephone exchange

Once telephone exchanges became computerized, tapping a line stopped requiring any physical presence on the wire, because the switch itself can copy a call.[1] At a digital exchange the switching computer duplicates the digitized bits that represent a conversation and sends the copy to a second line, and there is no way for the subscriber to tell that it is happening.[1] Interception can be set up remotely by the carrier rather than by a technician standing at a distribution frame, which makes it faster, cleaner, and undetectable from the subscriber's side.[1] This is the point where the network's lack of encryption matters most, because the call is being handled as plain, readable data at the exact moment the switch is best positioned to copy it. Whatever protection the call has now rests on the carrier's controls over who can activate that copy and under what authority.

Interception built into carrier networks by law

In the United States and many other countries, the ability to intercept a call is a required feature of the network rather than a weakness someone has to find. The Communications Assistance for Law Enforcement Act, signed into law in 1994, requires telecommunications carriers to design their equipment and facilities so that law enforcement can carry out authorized wiretaps.[6] A carrier served with a lawful order has to be able to isolate a target's communications and hand them to the agency named in the order, and in 2005 the same obligation was extended to broadband internet access and interconnected VoIP services.[6] The practical meaning for confidentiality is that every compliant switch already contains a working interception function that can be turned on for a given line.[6] Whether that capability is used only under proper authorization depends on legal and operational controls rather than on anything technical in the call, since the call offers no encryption to stand in the way.[1]

SS7 and signaling-layer attacks

Signaling System No. 7 is the control network that sets up, routes, and tears down calls between operators, and it carries little authentication of its own because it was built on the assumption that every network connected to it could be trusted.[3] That trust is the vulnerability. A party who gains access to the SS7 network, whether a small carrier, a leased connection, or an intruder, can send signaling messages that redirect calls and texts or ask the network where a subscriber's phone is.[4] Security researchers demonstrated location tracking through SS7 as early as 2008, and by 2014 the same techniques could follow a phone almost anywhere with a high success rate, while a 2017 case saw attackers reroute two-factor authentication texts to drain bank accounts.[4] These weaknesses are not just theoretical for US networks. A senior official at the Cybersecurity and Infrastructure Security Agency told the Federal Communications Commission in 2024 that attackers had exploited SS7 and the related Diameter protocol to track people in the United States and to intercept their calls and messages.[5] Because SS7 sits underneath the call, these attacks work without any access to the subscriber's line or handset.

Can PSTN calls be encrypted?

Yes, but the encryption has to be added at the two endpoints, because the PSTN itself will not encrypt a call and does not expect one to be encrypted.[9][12] The network's job is to carry whatever audio it is handed from one end to the other, so any confidentiality has to be created before the signal enters the network and undone only after it leaves.[9] In practice that means both parties need matching equipment that turns speech into an encrypted signal the line can carry, then converts it back at the far end.[9] A single secured phone is of no use on its own, since a normal handset on the other end has no way to decrypt anything, which is why secure telephones fall back to ordinary, unprotected calls whenever the far side cannot go secure.[7] The methods that achieve this range from dedicated government terminals and commercial scrambling devices to carrying the call over an encrypted internet path instead of the circuit-switched network.

Each approach puts the encryption in a different place and suits a different user. The table compares them, and the sections after it describe how each one works and where it fits.

Approach Where the encryption lives Typical use
Secure telephones (STU-III, STE) Dedicated hardware at both ends, using government-grade keys Classified government and military voice [7][8]
Analog voice scramblers A device that alters the audio on the line Low-cost privacy, with limited protection [10]
Encrypted IP replacing the call path Software or devices using SRTP for media and TLS for setup Modern business and personal secure calling [11][12]

Secure telephones such as STU-III and STE

The most established way to hold a protected conversation over ordinary phone lines is a matched pair of secure telephones, and the reference example is the STU-III family the NSA introduced in 1987 for the US government, its contractors, and its allies.[7] An STU-III works like a normal phone for regular calls, but when both ends have a compatible unit the users press a button and, after a short setup delay, the call switches into an encrypted mode able to protect conversations up to Top Secret.[7] The encryption depends on a removable crypto ignition key, so a unit without its key cannot send or receive classified audio.[7] The STU-III has since been retired in favor of Secure Terminal Equipment, a digital successor that runs over ISDN lines and takes a removable crypto card such as the Fortezza Plus or KSV-21, with newer sets interoperating through the Secure Communications Interoperability Protocol.[8] The common thread is that the protection is a property of the terminals at each end, not of the line between them, which is exactly why the same handsets keep working as ordinary phones when a secure link is not available.[7]

Analog voice scramblers and their limits

Analog scramblers alter the sound of a voice on the line so a casual listener hears noise instead of speech, and they were the earliest attempt at telephone privacy, but the simple ones provide very little real protection.[10] The most basic method, frequency inversion with a fixed setting, offers no meaningful security at all, because software is readily available that reverses it and restores the original voice.[10] Scramblers were used for voice traffic during the Second World War and were often intercepted and decoded, a track record that reflects the weakness of rearranging an analog signal rather than encrypting it.[9] What is sold today under the same name is usually different in kind, a device that digitizes the voice and applies real encryption, often with public-key methods, which is far stronger than the analog inverters it replaced.[10] For anyone weighing a scrambler, the distinction that matters is whether the box performs genuine digital encryption or merely shuffles the audio, since only the former resists a determined listener.

Moving the call onto an encrypted IP path

The modern answer to securing a call is to stop sending it as open audio over the circuit-switched network and instead carry it as encrypted data over an IP connection.[11][12] On an IP path the media can be protected by the Secure Real-time Transport Protocol, SRTP, which adds confidentiality, message authentication, and replay protection to the voice stream, while the call setup is protected separately by Transport Layer Security.[11] A call that never leaves an encrypted IP service can be private from end to end, whereas the moment it crosses a gateway onto the traditional PSTN it becomes ordinary unencrypted voice again.[12] The practical implication is that a mixed call is only as protected as its weakest leg: an app-to-app or Teams-to-Teams call may be encrypted throughout, but as soon as one party is on a normal phone number reached over the PSTN, that portion of the path is in the clear.[12] As carriers retire the circuit-switched network and move voice onto IP, encryption becomes possible on segments that never had it, though it still has to be switched on and supported at both ends rather than assumed.[11]

Trade-offs and what to watch

The PSTN's openness is inseparable from the qualities that made it useful, and naming the trade-offs explains why it stayed in service and how to think about protecting calls on it.

Interoperability came at the cost of confidentiality

The telephone network connects equipment from countless operators and countries precisely because it makes no assumptions about encryption, so any two phones can complete a call.[1] That universality is also why a call is readable at so many points, and there is no setting a subscriber can change to close the gap from their end alone.[9]

Endpoint encryption adds friction

Because protection has to live in matched endpoints, both parties need compatible equipment, which historically limited strong secure voice to organizations that could issue the same terminals to everyone who needed them.[7][9] A secured device offers nothing when the other end cannot match it, and it quietly reverts to an ordinary call in that case.[7]

Migration to IP changes the picture but not automatically

Carrying voice over IP makes encryption technically available, yet it is not on by default across every path, and a call that touches a PSTN number for even one leg is unprotected on that leg.[12] The safe working assumption is that a call is unencrypted unless you know that both ends and every segment support it and have it enabled.[11]

What PSTN security is not

A few common assumptions about telephone privacy do not hold, and separating them prevents a false sense of security.

A private line is not an encrypted line

A dedicated or leased line keeps a call off shared switching, but it does not encrypt the audio, so anyone who reaches the physical circuit can still listen.[1] Privacy of routing is not the same as confidentiality of content.

The digital core does not mean the call is protected

Most of the PSTN core has been digital for decades, and people sometimes read digital as secure, but the digitization defined in G.711 is only an encoding of the sound, with no encryption attached.[2] A digital call is a stream of numbers that reconstructs the voice for anyone who captures it.

Caller ID is not authentication

The number shown on an incoming call is signaling information, not proof of who is calling, and the same signaling layer that carries it has been abused to spoof numbers and redirect calls.[4] Trusting a call because of the number it displays is a separate risk from eavesdropping.

Retiring the PSTN does not by itself add encryption

Moving to IP makes encryption possible, but it does not guarantee it, and a modern IP call still travels unprotected whenever it crosses onto a traditional phone number or a segment where encryption was never enabled.[12]

This entry separates two questions that often get merged, whether the PSTN is secure and whether its calls can be encrypted, and sources each part against primary standards and independent reporting. The claim that the network carries voice without encryption is grounded in ITU-T G.711, the standard that defines how the PSTN digitizes speech and contains no security mechanism.[2] The interception points are drawn from documented descriptions of line and exchange tapping, from the text of the Communications Assistance for Law Enforcement Act, and from a 2024 filing in which a US cybersecurity official described SS7 exploitation against American networks.[1][6][5] The encryption methods are described from the specifications and reference documentation for secure terminals and for the Secure Real-time Transport Protocol.[7][8][11] Telecommunications security work moves quickly, so the date on each source shows when a claim was verified. Engineers, security researchers, and carrier staff who work with these systems are welcome to suggest corrections, which are checked against primary sources before any update.

This answer was written and reviewed by the AnswerStack Editorial Team, which has no commercial stake in the products, companies, or methods discussed. Every claim is cited inline and verified on the dates shown.

Sources

Telephone tapping

Wikipedia

Independent Verified Jul 18, 2026 Supports: A PSTN call is carried as an unencrypted signal and can be tapped physically on the analog line or, at a digital exchange, by copying the digitized bits to a second line undetectably; modern digital exchanges allow interception to be ordered remotely

“Now that many exchanges have been converted to digital technology, tapping is far simpler and can be ordered remotely by computer.”

ITU-T G.711: Pulse code modulation (PCM) of voice frequencies

International Telecommunication Union (ITU-T)

Primary source Verified Jul 18, 2026 Supports: G.711 defines pulse code modulation encoding of voice frequencies, the baseline digital voice channel of the PSTN, and describes only sampling and encoding, not encryption; status in force

“Pulse code modulation (PCM) of voice frequencies. Status: In force.”

ITU-T Q.700: Introduction to CCITT Signalling System No. 7

International Telecommunication Union (ITU-T)

Primary source Verified Jul 18, 2026 Supports: Signalling System No. 7 (SS7) is the out-of-band control network that sets up, routes, and releases calls between operators; standardized in the Q.700 series; status in force

“Introduction to CCITT Signalling System No. 7”

Signalling System No. 7

Wikipedia

Independent Verified Jul 18, 2026 Supports: SS7 lacks authentication between networks and trusts connected operators, allowing call and SMS interception, redirection, location tracking, and two-factor bypass; Tobias Engel 2008 location tracking, ~70% tracking success by 2014, and a 2017 O2 Telefonica attack that rerouted 2FA texts to raid ban

“anyone can track the movements of mobile phone users from virtually anywhere in the world with a success rate of approximately 70%”

EFF to FCC: SS7 is Vulnerable, and Telecoms Must Acknowledge That

Electronic Frontier Foundation

Independent Verified Jul 18, 2026 Supports: In a 2024 FCC filing, CISA official Kevin Briggs reported that attackers exploited SS7 and Diameter to track people in the United States and intercept calls and text messages, with documented 2022 incidents on US networks

“Nefarious actors can also use SS7 attacks to track a target's precise location anywhere in the world.”

Communications Assistance for Law Enforcement Act

Wikipedia

Independent Verified Jul 18, 2026 Supports: CALEA (1994) requires telecommunications carriers to design equipment and facilities so law enforcement can conduct authorized wiretaps and isolate and deliver a target's communications; extended in 2005 to broadband internet access and interconnected VoIP

“To amend title 18, United States Code, to make clear a telecommunications carrier's duty to cooperate in the interception of communications for Law Enforcement purposes.”

STU-III

Wikipedia

Independent Verified Jul 18, 2026 Supports: STU-III is a family of secure telephones introduced in 1987 by the NSA that works over ordinary phone lines, encrypts up to Top Secret, requires a compatible unit at both ends and a crypto ignition key, and falls back to normal unencrypted calls; secure mode engages after a short delay

“They then press a button on their telephones and, after a 15-second delay, their call is encrypted to prevent eavesdropping.”

Secure Terminal Equipment

Wikipedia

Independent Verified Jul 18, 2026 Supports: STE is the US government's current secure telephone system for landline communications, replacing STU-III, using digital ISDN lines and a removable crypto card (Fortezza Plus KOV-14 or KSV-21), with newer sets supporting SCIP

“Secure Terminal Equipment (STE) is the U.S. government's current encrypted telephone communications system for wired or 'landline' communications.”

Secure telephone

Wikipedia

Independent Verified Jul 18, 2026 Supports: Securing a call requires matching equipment at both ends using the same protocol; early scramblers were often intercepted and decoded because of scrambling's inherent insecurity; known secure systems include STU-III, STE, SCIP, and ZRTP-based phones

“Scramblers were used to secure voice traffic during World War II (1939-1945), but were often intercepted and decoded due to scrambling's inherent insecurity.”

Scrambler

Wikipedia

Independent Verified Jul 18, 2026 Supports: Simple analog scrambling such as fixed frequency inversion offers no real security because software can restore the original voice; modern devices that digitize and encrypt the voice, using public-key systems, are far more secure than analog inverters

“Voice inversion with a fixed frequency offers no security at all and software is available to restore the original voice.”

RFC 3711: The Secure Real-time Transport Protocol (SRTP)

Internet Engineering Task Force (IETF)

Primary source Verified Jul 18, 2026 Supports: SRTP is a profile of RTP that provides confidentiality, message authentication, and replay protection for RTP media and control traffic, using AES in counter mode and HMAC-SHA1; the basis for encrypting voice carried over IP

“SRTP...can provide confidentiality, message authentication, and replay protection to the RTP traffic and to the control traffic for RTP”

GCC High Teams Calling vs. Traditional VoIP: Which is More Secure for Government Contractors?

Atlantech Online

Supporting Verified Jul 18, 2026 Supports: Corroborates that PSTN calls are not encrypted and that end-to-end encryption applies only to app-to-app (Teams-to-Teams) legs, so a call that reaches a PSTN number is unprotected on that leg; paired with [11] and [1] for the core claim

“Encrypted voice traffic at rest & in transit for Teams-to-Teams calls only (PSTN calls are not encrypted).”

Revision history

2 revisions since publication
v1.1 Reviewed and re-verified.
v1.0 Published after editorial review.