There is no single “bug frequency”. Modern surveillance can use ordinary cellular, Wi-Fi, Bluetooth and short-range radio systems — or no radio transmitter at all. This guide explains the technologies a modern TSCM inspection has to consider.
Older listening devices were often simple analogue transmitters operating continuously on one frequency. They could often be found by scanning for an unexpected carrier. Modern devices can be digital, frequency agile, burst only when required, use a public communications network, or store information locally. A professional sweep therefore looks for behaviour and anomalies, not merely a list of known channels.
The frequency ranges below are a practical UK reference to technologies that may be encountered during technical surveillance counter-measures work. They are not “secret bug channels”: most are shared with large numbers of legitimate devices. Finding energy in one of these bands does not by itself indicate surveillance.


| Technology / device type | Typical UK spectrum or path | TSCM significance |
|---|---|---|
| Traditional VHF/UHF radio bug | Various VHF/UHF frequencies | A continuous carrier can be relatively conspicuous; intermittent or digitally modulated devices are harder to classify. |
| Low-power short-range device | Common UK SRD/ISM allocations, including around 433 MHz and 863–870 MHz | Busy bands containing alarms, sensors, controls and telemetry. Signal identification and localisation matter more than simple detection. |
| Cellular listening / tracking device | UK mobile allocations include spectrum around 700, 800, 900, 1800, 2100, 2300, 2600 and 3400–3800 MHz | Traffic may resemble an ordinary phone or IoT device. Presence alone is not evidence; correlation, location and device examination are important. |
| Wi-Fi camera / audio / IP device | 2.4 GHz, 5 GHz and increasingly 6 GHz Wi-Fi spectrum | Dense legitimate Wi-Fi environments make identification and network context essential. |
| Bluetooth / BLE device | 2.4 GHz | Low power and frequency hopping can make devices inconspicuous amongst legitimate peripherals and beacons. |
| DECT / cordless-derived device | Around 1.9 GHz in Europe/UK | Digital transmissions require protocol-aware interpretation rather than treating every signal as suspicious. |
| Frequency-hopping digital transmitter | Technology dependent | Energy moves between channels. Short dwell times can defeat simplistic “strongest carrier” approaches. |
| Burst / duty-cycled transmitter | Technology dependent | May remain RF-silent for long periods and transmit only briefly, so time and persistence matter. |
| GNSS vehicle tracker | Receives GNSS; typically returns location through cellular or another radio link | The GNSS receiver itself is not normally transmitting. Detection concentrates on the communications link, electronics and physical installation. |
| Local recorder / store-and-forward device | No RF required while recording | An RF-only sweep can miss it. Physical inspection and electronic-component detection become more important. |
| Hardwired microphone / camera | Cable, building wiring or other conducted path | May produce no useful over-the-air RF signature. Wiring and physical inspection are essential. |
| Optical / infrared surveillance | Optical rather than conventional RF path | Requires optical and physical countermeasures; a spectrum analyser alone is not sufficient. |
Cellular technology gives a surveillance device access to established wide-area infrastructure. In the UK, mobile services occupy multiple allocations from sub-1 GHz through the 3 GHz range, with newer high-frequency mobile allocations also developing. The practical TSCM problem is that legitimate phones, routers, alarms, vehicles and IoT equipment can occupy the same environment. A signal cannot be labelled a bug simply because it is cellular.
The 2.4 GHz band may contain access points, phones, laptops, headphones, keyboards, cameras, smart-home products and Bluetooth Low Energy devices. Modern TSCM therefore needs to distinguish expected equipment from unknown or misplaced devices and, where appropriate, correlate RF observations with a physical location.
Frequency-agile systems illustrate why a single sweep of a spectrum analyser is not enough. A transmitter may occupy any one channel only briefly, while a burst device may remain silent during much of an inspection. Appropriate observation time, spectrum history, localisation and knowledge of the RF environment all contribute to the assessment.

Some of the most important threats are not detectable by searching the radio spectrum at all. A local audio recorder, memory camera or hardwired microphone can collect information without transmitting. This is why professional TSCM combines RF examination with a systematic physical search and, where justified, techniques intended to locate concealed electronics.
No. Modern buildings contain hundreds of legitimate radio emitters. The professional task is to establish what a signal is, whether it belongs in the environment, where it originates and whether there is physical evidence supporting concern. False positives are one reason inexpensive wideband “bug detectors” can create more anxiety than useful information.
Radio allocations and network deployments evolve. This guide is intentionally technology-led rather than presenting a supposedly permanent list of exact bug frequencies. For authoritative current UK allocations, Ofcom's UK Frequency Allocation Table and mobile-frequency information should be treated as the reference.
Bug Detectors UK approaches surveillance detection as an RF and electronics investigation. The objective is not simply to make a detector beep; it is to understand the RF environment, identify anomalies, inspect plausible concealment locations and document findings and limitations.
If you have a specific concern, see our London bug-sweeping service, corporate TSCM, residential sweeps or vehicle and tracker searches.