How are bad actors getting access to SS7? Is SS7 being transported over public IP networks and subject to intercept? Are they bribing/hacking telecoms themselves?
I don't know how effectively that strategy still works today, but I think it speaks to the significant degree to which the phone system is completely insecure and untrustworthy by design.
1. Renting access by pretending to be legit telecom business
2. Internal access
3. Internet hacking into less protected telecom operators to then compromise the SS7 core network nodes and send traffic from there.
Other ways exist, but these represent the bulk.