When a phone is lost or stolen, reporting it to a cellular carrier is supposed to prevent unauthorized use. Michigan State University researchers have found that weaknesses in the reporting system itself could potentially be exploited to block legitimate devices from cellular networks. September 9, 2026 A stolen-phone safeguard could disrupt home alarms and block new flagship phones by Emilie Lorditch, Michigan State University edited by Robert Egan Robert Egan Senior Editor Meet our editorial team Behind our editorial process Editors' notes This article has been reviewed according to Science X's editorial process and policies.
Editors have highlighted the following attributes while ensuring the content's credibility: fact-checked trusted source proofread The GIST Add as preferred source Michigan State University researchers have found that weaknesses in the reporting system itself could potentially be exploited to block legitimate devices from cellular networks. The researchers identified six vulnerabilities spanning mobile devices, carrier reporting infrastructure and cross-carrier operations and demonstrated their security impact through two experimental attacks on operational 4G and 5G networks. "We found that the security mechanisms that are supposed to protect the lost and stolen phone reporting service are not sufficient," said Guan-Hua Tu, associate professor in the Michigan State University College of Engineering and one of the study's authors.
"An attacker can potentially abuse these weaknesses to remotely block a device from cellular service, even though the device has not actually been lost, stolen or sold." Turning a theft-prevention system into a potential attack When a phone is lost or stolen, its owner can report the device to a mobile carrier using its unique International Mobile Equipment Identity, or IMEI. The carrier adds the IMEI to an Equipment Identity Register, or EIR, effectively blacklisting the device so it cannot connect to cellular networks. Researchers examined this lost and stolen device reporting ecosystem, including devices, carrier reporting systems and the cross-carrier infrastructure that shares blacklisted device information.
The researchers found weaknesses in how carriers verify the identities of people submitting lost-device reports and whether those people own the devices. For example, some reporting systems lets users report devices that were not covered by their own service subscriptions. The device-blocking information shared between systems lacks sufficient security information to help carriers identify potentially fraudulent reports.
The researchers found that these vulnerabilities reflect broader gaps in how lost and stolen device reports are verified and shared. Neither 3GPP nor GSMAโtwo major organizations that collaborate to manage global mobile communication standardsโstandardizes how carriers should verify the identity of someone reporting a device or establish device ownership.
Carriers therefore rely on their own policies and usage-based approaches. Together, the vulnerabilities could allow attackers to submit fraudulent lost-device reports that cause legitimate devices to be blacklisted.
Home security systems could be remotely frozen One of the researchers' proof-of-concept attacks, called Home Security System Freezing, demonstrates how the vulnerabilities could affect more than smartphones. It could prevent cellular-connected home security systems from communicating with homeowners and monitoring centers, potentially blocking critical alarm notifications during an emergency.
Many home security gateways use Wi-Fi as their primary connection and low-cost cellular IoT for backup connectivity. Wi-Fi can be disrupted relatively stealthily because it is more difficult for carriers to pinpoint a localized attacker, while continuous cellular jamming requires high-power transmissions that carriers can detect and localize using nearby base stations.
Unlike traditional cellular jamming, the approach does not require an attacker to continuously transmit a powerful signal near the victim. Instead, researchers demonstrated how an attacker could briefly disrupt a home security gateway's Wi-Fi connection, exploit a vulnerability in its cellular IoT modem to obtain its IMEI and later report the device as lost.
Because the two steps could occur weeks or months apart, the attack could be difficult to trace and localize. Researchers tested representative home security gateways and found that two major U.S.
Home security providers, together accounting for more than 41% of the U.S. Market, use cellular IoT modem chipsets that are vulnerable to the demonstrated attack.
The potential implications extend beyond home security. Cellular IoT modems are used in devices including water and electricity meters, industrial sensors and medical monitoring systems.
Losing cellular connectivity in these settings could disrupt critical services and, depending on the device and its role, potentially create safety risks. A potential attack on new flagship phones The second proof-of-concept attack, called Zero-Day Flagship Phone Ambush, could target the IMEIs of new flagship smartphones before or around their release and exploit weaknesses in the reporting system to have those devices classified as lost or stolen.
Because a single fraudulent report can potentially propagate through cross-carrier systems, an attacker could attempt to block large numbers of newly released devices from connecting to cellular networks. Researchers demonstrated the feasibility of the attack using a Samsung Galaxy Z Fold7 as a representative flagship device.
Discover more from ChuckysCarnage
Subscribe to get the latest posts sent to your email.
