The U.S. Secret Service said on September 23, 2025, that agents dismantled a network of electronic devices spread across the New York tri-state area that was used to conduct telecommunications-related threats against senior U.S. officials.
The devices were concentrated within 35 miles of the United Nations General Assembly in Manhattan, where global leaders are gathered this week.
The agency said the discovery came through a protective intelligence investigation and that forensic work is continuing. Details were released in a public statement and confirmed in national reporting by the Associated Press and the Washington Post.
What investigators found
According to the Secret Service, the probe uncovered more than 300 co-located SIM servers and over 100,000 SIM cards across multiple sites in the region.
Officials said the equipment had been used to send anonymous telephonic threats and could enable a wide range of telecom attacks, including disabling cell towers, enabling denial-of-service operations, and facilitating encrypted communication between potential threat actors and criminal groups.
The agency’s description of the equipment aligns with additional details reported by CBS News, which said investigators assessed the system could send as many as 30 million text messages per minute.
Devices were found in clusters, including in vacant properties, and configured to operate together, officials said. The architecture appeared designed to scale traffic quickly while masking users, a setup that investigators say can both amplify harassment campaigns and complicate attribution.
The Secret Service statement described the network as capable of supporting multiple attack vectors against public and commercial cellular infrastructure.
Why the timing and location mattered

The United Nations General Assembly is underway in New York City this week. The Secret Service said the concentration of devices within 35 miles of the venue, combined with their capabilities, presented an unacceptable risk to the city’s telecommunications. The agency said it “moved quickly to disrupt this network” because of the potential for significant disruption, a point echoed in national coverage by the Associated Press.
Officials said the inquiry began after multiple threats were directed at senior U.S. government officials. Early analysis indicated cellular communications between nation-state actors and individuals known to federal law enforcement, according to the Secret Service release.
The Department of Homeland Security’s Homeland Security Investigations, the Department of Justice, the Office of the Director of National Intelligence, the New York Police Department, and other partners are assisting.
How officials characterized the risk
Secret Service Director Sean Curran said “the potential for disruption to our country’s telecommunications posed by this network of devices cannot be overstated,” describing the operation as part of the agency’s mission to prevent attacks before they materialize.
“Imminent threats to our protectees will be immediately investigated, tracked down and dismantled,” he said in the agency’s statement, which was cited by outlets including the Washington Post.
Investigators said the device network enabled anonymous and encrypted communications and could be used for denial-of-service attacks against cellular infrastructure. Reporting by CBS News and ABC News added that the equipment was distributed across more than five locations and that agents seized SIM farms capable of large-scale message blasts.
What remains under investigation
Authorities did not immediately announce arrests. Forensic examinations of the devices are ongoing, and officials have not disclosed who assembled or operated the network.
The Secret Service said preliminary analysis points to contacts with foreign actors and individuals already known to U.S. law enforcement, but it did not identify specific countries or groups in public statements. The Associated Press reported that investigators are assessing whether the network was intended to disrupt communications around the UN session or served broader criminal and harassment purposes.
The investigation’s next steps will focus on mapping command-and-control pathways, confirming whether the equipment was used in previous incidents, and determining the legal exposure of any suspects. Agencies involved have cautioned that similar installations could exist elsewhere, a point raised in national reporting while noting there is no specific public warning of a current, active attack against New York networks.
The broader security backdrop
The operation occurred as New York implements enhanced security measures around the General Assembly. President Donald Trump is scheduled to address the gathering on September 23, 2025, and the city has issued extensive traffic and public safety advisories.
Local coverage has outlined road closures and coordination among federal and city agencies for the week’s events, including the Secret Service protective footprint, as noted by FOX 5 New York.
Telecom-enabled threats have posed recurring challenges for law enforcement, which relies on public networks for emergency services and real-time communications. The Secret Service said the dismantled equipment could have interfered with those services, an outcome officials sought to prevent as high-level events brought additional strain to local infrastructure.
The agency emphasized that the investigation continues and that it will release further details as appropriate through official channels.
The Secret Service statement, supported by national reporting, frames the discovery as a preemptive action to remove a network capable of mass messaging, service degradation, and anonymized coordination. Federal and local partners remain on the case while the city proceeds with UN-related programming under heightened security and monitoring of telecommunications systems.
