fb-pixel Skip to main content
tech lab

Could exploding device attacks like those in Lebanon happen here?

The remains of exploded pagers in Lebanon on Sept. 18.AFP/Photographer: AFP/Getty Images

Could your phone or other personal electronics become a hand grenade detonated remotely?

It’s a serious question, now that hundreds of devices have exploded in the hands and hip pockets of people in Lebanon, allegedly by remote control from Israel. The attacks have killed at least 37 people, injured thousands more, and raised the specter of a terrifying new kind of warfare, featuring up-close-and-personal mayhem inflicted by personal electronic devices.

Many are now wondering if something similar could happen to personal electronics in the US. The consensus among security analysts is that such an event is conceivable, but quite unlikely.

“Something this tailored and this destructive of a particular target would be difficult to achieve,” said Brad Martin, a retired US Navy captain who’s now a senior policy researcher at the RAND Corporation, a national defense think tank.

But a less targeted attack would be possible. And Martin warned that US institutions and individuals are vulnerable to similar kinds of attacks that might not set off explosives, but could still cripple the nation’s critical systems.

According to multiple news reports, the initial attack on the Lebanese paramilitary group Hezbollah featured digital pagers packed with small amounts of plastic explosives and designed to go off upon receipt of a specific code. The leading theory says Hezbollah wound up with the deadly pagers because an Israeli shell company based in Hungary managed to infiltrate the supply chain. They made the pagers under contract to a Taiwanese firm which sold them to Hezbollah. The Taiwanese company has said it knows nothing about the operation.

Pagers are still used by doctors, nurses, and caregivers, though the global market size for pagers, estimated at $1.6 billion in 2023, is tiny compared to that for smartphones, according to Reuters.

It’s unclear so far how the walkie-talkies were booby-trapped. The Japanese company that manufactured them says it stopped making that particular model a decade ago.

Hannah Kain, president of ALOM, a supply-chain management company in Fremont, Calif., said that Hezbollah’s big mistake lay in its trusting attitude toward its suppliers. “Nobody had done a site visit,” said Kain. “Nobody had checked their references, no one had checked their business practices.”

Kain said she always tells clients to make sure they know their suppliers. “It’s very difficult to do it,” she said. “It takes an effort and that’s why many organizations skip over it.”

Hezbollah made another critical supply-chain mistake — single-sourcing. In an effort to stop Hezbollah operatives from using their easily monitored cellphones, the organization issued low-tech pagers to hundreds of them. But instead of buying these pagers from multiple suppliers, they relied on just one.

“That’s actually a case of being unduly reliant on a particular source,” said Martin.

A police officer inspected a car in which a hand-held pager exploded in Beirut, Lebanon, on Sept. 17.Hussein Malla/Associated Press

By contrast, he said, people in the Pentagon use secure government-issued phones on duty. Samsung, for instance, makes a line of Android smartphones specifically tailored for military and national security users. The same military and intelligence people often carry ordinary cellphones for everyday use. But with thousands of personnel buying different phones from different retailers, a Lebanon-style targeted supply-chain attack becomes impossible. The same goes for implanting explosives in civilian electronic devices.

Even if an enemy could intercept a shipment of iPhones and put bombs inside, said Martin, the attackers would have no way of knowing who would buy the phones. Setting them off would be a horrific act of terrorism, to be sure, but useless as a military strategy.

Josep Miquel Jornet, a professor of electrical and computer engineering at Northeastern University, added that pagers and walkie-talkies have plenty of unused space inside and offer easy access to the chips that control them. That makes it relatively simple to install control circuitry and an explosive. By contrast, he said, smartphones use advanced chips tightly clustered onto a wafer-thin motherboard. Making modifications without damaging the device would be exceedingly difficult, and there’d be hardly any room inside for a bit of plastic explosive.

“Is it possible?” said Jornet. “Yes, it is possible. Is it hard? It is much harder.”

Still, the US electronics supply chain is highly vulnerable — maybe not to explosives, but to exploits that could plant defective chips or malware inside critical systems.

Willy Shih, a professor at Harvard Business School who specializes in supply chains, said they’re very hard to manage and secure. Companies and governments buy directly from so-called Tier 1 contractors. But the Tier 1 companies buy their components from Tier 2 contractors, who in turn buy stuff from Tier 3 companies. You get the idea.

With so many possible permutations, “it quickly becomes very difficult to understand everyone in the supply chain,” said Shih. “As a matter of fact, most manufacturers don’t know who their suppliers are below Tier 2.”

According to a 2022 Defense Department report, the nation’s top defense contractors often don’t know who manufactures their sub-components. That’s a major opportunity for bad actors to smuggle defective hardware or software into US military systems.

The US may have used supply-chain attacks as well. According to a 2014 leak by National Security Agency contractor-turned-whistleblower Edward Snowden, US intelligence operatives intercepted internet routers made by telecom company Cisco for sale to overseas clients, and installed software that let the spy agency intercept vast amounts of confidential data.

And the US helped Israel develop Stuxnet, a malware program that damaged some of the centrifuges being used by Iran to enrich uranium for possible use in a nuclear weapon. The Stuxnet code was hidden on USB drives which were plugged into computers in the Iranian nuclear lab.

“That changed how the world viewed USB drives,” said Shih. “After that, a lot of people would not let USB drives attach to their systems any more.”

Shih said that the Lebanon attacks could have a similar impact on the electronics industry, as companies work to lock down their supply chains. “You’re going to have to have chain of custody and safety seals” on all sorts of electronics components, he said, just like the tamper-resistant seals on food and medicine packages.

But while our insecure supply chains really are dangerous, for now it seems they’re not likely to blow up in our faces.


Hiawatha Bray can be reached at hiawatha.bray@globe.com. Follow him @GlobeTechLab.