Cheap Cell Phone Disconnect Attacks Threaten Cellular Networks

Researchers at Michigan State University and three partner schools discovered critical vulnerabilities in carrier systems used to block lost and stolen mobile devices, allowing attackers to remotely disable active hardware like smartphones and home alarm panels for a few dollars. According to Michigan State University College of Engineering associate professor Guan-Hua Tu, an attacker can exploit these systemic gaps to cut a device off remotely, “even though the device has not actually been lost, stolen or sold.”

How Cellular Carriers Track and Block Lost Devices

Every device containing a cellular radio relies on a 15-digit serial number known as an IMEI. Factories burn this number directly into the hardware, keeping it separate from SIM cards, phone numbers, and customer accounts. When someone reports a phone stolen, carriers drop that specific IMEI into a database called an Equipment Identity Register. Once logged, the cellular network refuses to register the hardware, regardless of who holds the device or which SIM card sits inside.

The research team set out to discover what stops malicious actors from submitting serial numbers they do not actually own. U.S. carriers currently accept lost-device reports only from individuals with active service, a policy intended to make reporters traceable. However, testing across three major U.S. carriers and their resellers revealed that none of the networks verified a Social Security number or government ID when establishing a prepaid account. Furthermore, prepaid customers possessed the same ability to file lost-device reports as anyone else, and these prepaid accounts could be funded using anonymous Visa gift cards purchased off retail racks.

Exploiting Flaws to Silence Home Alarm Panels

The research team identified six distinct weaknesses spanning the mobile devices themselves, the carrier systems that take the reports, and the machinery carriers use to share block lists. To test these vulnerabilities in practice, the researchers bought a Samsung Galaxy Z Fold 7, copied the identification number printed on the sealed box, and reported the phone as lost to its carrier before opening the package. The brand-new phone, sitting safely on a lab bench the entire time, failed to connect. Blocking a device they did not own took between 20 and 80 seconds and cost between $2.50 and $4.

Beyond standard smartphones, the researchers tested four low-power cellular data boards used in home security gateways alongside four standard phones. While the phones properly ignored corrupted identity requests, two of the cellular boards answered with their IMEIs. According to the research findings, those vulnerable chipsets come from two vendors whose combined global market share exceeds 40 percent. By knocking a home security gateway off Wi-Fi, luring it to a small rogue base station to capture its IMEI, and later filing a fraudulent lost-device report, an attacker can cut off cellular backup entirely. Alarms stop reaching homeowners and monitoring centers, and victims receive no notice that any of this has happened.

Mass Blocking Unsold Flagship Phones

Attackers can scale these exploits to target inventory before it ever reaches consumers. Because IMEIs are assigned before devices ship, companies that verify devices for the supply chain sell access to these numbers. The research team acquired a full database from one such company for $600, plus $30 monthly for updates, and located the Z Fold 7’s serial number prior to its July 25, 2025 release date.

Cell Phone Signal Blocking Set – Review

A single prepaid account successfully reported ten devices without tripping anything. Scaling this operation to 100 devices requires ten prepaid accounts, costs between $250 and $400, and takes roughly 33 minutes to a little over two hours against $200,000 worth of hardware. Restoring service requires proving ownership to the carrier via a receipt showing the IMEI and identity verification. If the fraudulent report originated on a competing network, the dispute can escalate to the GSMA, the industry body that runs the global block list, introducing additional delays. Meanwhile, tests revealed that a phone reported lost on one carrier continued working normally on two other networks a week later, indicating that at least two of the three carriers are not syncing with the global list they tell customers about.

Proposed Fixes and Systemic Overhauls

To address these systemic security gaps, the researchers developed four proposed fixes and built a working prototype. First, device certification tests must verify that phones and modules refuse to disclose their IMEIs when receiving unauthenticated requests. Second, carrier reporting portals should require government-ID verification using established third-party services utilized by federal agencies. Third, ownership verification should combine multiple data points—such as matching the device to the reporter’s plan—and require in-store verification for doubtful cases. Finally, records shared between carriers must include security metadata indicating whether the reporter underwent identity checks.

Did You Know? The GSMA acknowledged the researchers’ findings and forwarded the data to its device security group to review potential industry-wide mitigations.

Frequently Asked Questions

How do attackers obtain the IMEI of a target device?

Attackers can acquire serial numbers by purchasing supply chain databases prior to a phone’s official release date, or by tricking low-power cellular modules—such as those inside home alarm panels—into disclosing their IMEIs via rogue base stations.

Do carriers verify identity when a lost phone is reported?

According to the research team, major U.S. carriers require active service to file a report, but prepaid accounts can be opened anonymously without verifying a Social Security number or government ID.

Can a phone blocked on one carrier still work on another?

Yes. Testing showed that a smartphone reported lost on one carrier continued operating normally on two rival networks a week later, highlighting synchronization failures across carrier block lists.

How cellular network outages show the vulnerability in our critical systems

What devices are vulnerable to remote blocking besides phones?

Cellular-enabled home security gateways, water and electricity meters, industrial sensors, and cardiac monitors utilizing vulnerable low-power cellular chipsets can potentially be targeted.

Join the Conversation

What steps do you think mobile carriers and standards bodies should take to balance user convenience with robust device security? Share your thoughts in the comments below, or subscribe to our newsletter for ongoing updates on cybersecurity and network infrastructure.

Leave a Comment