A few-dollar attack can disconnect smartphones and security systems
Researchers from Michigan State University and three partner universities have demonstrated how it is possible to remove cellular devices from the network at a cost ranging from $2.50 to $4, exploiting vulnerabilities in the system for reporting lost or stolen phones. The team purchased a Samsung Galaxy Z Fold 7, copied the IMEI identification number from the sealed box, and reported the device as lost to the carrier, even though it was new and unused. The phone appeared blocked even though it was physically intact.
Quick Answer
The researchers identified six vulnerabilities in the cellular device blocking system, exploiting weaknesses in the devices themselves, carrier systems, and mechanisms for sharing block lists. The attack requires knowledge of the target device's IMEI number and can also be performed on connected home alarm systems.
Vulnerabilities in device blocking systems
Every device with a cellular radio has a unique 15-digit IMEI number, distinct from the phone number and SIM. When a phone is reported as stolen, the carrier adds it to the Equipment Identity Register, preventing it from accessing the network. However, researchers discovered that this mechanism can be exploited to block devices not owned by the attacker.
Insufficient identity checks
The three carriers tested accept reports only from users with active service, but none verified identity documents or social security numbers during the creation of prepaid accounts. Additionally, ownership checks are based on the device's presence in the network, not actual possession. One carrier accepted just one second of connection, while the others required one minute.
Vulnerable non-cellular devices
The team successfully reported non-cellular devices such as smartwatches and industrial development boards, demonstrating that checks do not distinguish between device types. Once reported, these devices could no longer connect to the network. The attack is possible due to vulnerable chipsets from two major suppliers, covering over 40% of the global market.
Attack on home alarm systems
Home security systems often use cellular connections as a backup. Attackers can force the switch to the cellular network, lure the device into a rogue base station to obtain its IMEI, and then report the device as lost. This disrupts communication between the alarm system and the monitoring center, leaving no trace detectable by the carrier.
Blocking smartphones not yet sold
The researchers purchased a database of IMEI numbers for devices not yet released, including the Samsung Galaxy Z Fold 7, before its release date. Using prepaid accounts, they blocked ten devices at a cost ranging from $250 to $400, demonstrating the economic feasibility of large-scale attacks.
Lack of synchronization between carriers
A device reported as lost by one carrier remained functional on the others, revealing that at least two of the three carriers do not correctly synchronize global block lists. Victims do not receive notification of the block and must prove possession of the device to restore service, a process that can take days.
Proposed solutions
The team suggested four improvements: device certification testing to prevent unauthorized IMEI disclosure, user identity verification through third-party services, stricter ownership checks, and more complete security information exchange between carriers. These changes aim to increase the cost of attacks without complicating the process for legitimate users.
The researchers have notified their results to carriers, chipset manufacturers, and device manufacturers involved. The GSMA has recognized the findings and forwarded them to its device security group.
Impact on cyber insurance and incident response
These vulnerabilities represent a significant risk for companies investing in cyber insurance and incident response. The ability to block devices without owning them could lead to financial losses and operational disruptions, making it essential to implement Managed Security Operations Center and Managed Detection and Response solutions to monitor and prevent such attacks.
Compliance with regulations
Companies must consider the impact of these vulnerabilities on NIS2 compliance and DORA compliance, which require robust measures of digital operational resilience. Adopting advanced Data Loss Prevention and SIEM can help identify and mitigate risks associated with these types of attacks.
Proactive protection
To prevent similar attacks, companies should consider regularly conducting penetration testing and vulnerability assessments to identify and correct vulnerabilities in their systems. Additionally, implementing zero trust architecture and identity access management can reduce the risk of unauthorized access to devices and sensitive data.
Frequently Asked Questions
What is the cost of an attack of this type?
The cost to block a device ranges from $2.50 to $4 per device, depending on the carrier. Blocking 100 devices would cost between $250 and $400.
How can companies protect themselves from these attacks?
Companies can protect themselves by implementing Managed Security Operations Center and Managed Detection and Response solutions, conducting regular penetration testing and vulnerability assessments, and adopting zero trust architecture and identity access management.
What are the regulatory implications of these vulnerabilities?
These vulnerabilities can affect NIS2 compliance and DORA compliance, making it essential to adopt measures of digital operational resilience and Data Loss Prevention.
Market and implications for telephony providers
The mobile telephony industry faces an unprecedented challenge: the three carriers tested did not implement sufficient identity checks to prevent such attacks. This calls into question the overall security of cellular networks and could lead to a review of industry regulations. The GSMA, the association representing mobile operators worldwide, has recognized the seriousness of the situation and forwarded the findings to its device security group. However, there are still no indications of when or how concrete solutions will be implemented.
Impact on end users and businesses
For end users, the impact of these vulnerabilities is significant. An illegally blocked device can cause service interruptions, data loss, and additional costs for restoration. Companies using cellular devices for critical operations, such as home and industrial alarm systems, must assess the potential impact on business assets. The ability to block devices not yet sold represents a particular risk for retailers and distributors, who could suffer significant financial losses.
Technical solutions and improvements
The researchers suggested four key improvements to mitigate these vulnerabilities. First, device certification testing should be implemented to prevent unauthorized IMEI disclosure. Second, carriers must verify user identity through reliable third-party services. Third, ownership checks must be stricter, requiring concrete proof of device possession. Finally, operators must improve security information exchange among themselves to ensure complete synchronization of block lists.
Future perspectives and forecasts
The identified vulnerabilities raise critical questions about the future of cellular device security. With the increasing adoption of IoT devices and growing dependence on cellular networks for critical applications, it is essential that the industry works to address these threats. Telephony providers and device manufacturers are expected to collaborate to develop advanced technical solutions, such as adopting more robust authentication protocols and implementing zero-trust architectures. Additionally, regulations may be updated to better reflect emerging challenges in cellular device security.
The researchers' findings serve as a wake-up call for the entire mobile telephony sector. The ability to block cellular devices without owning them, at an extremely low cost, underscores the urgency of improving existing security mechanisms. As providers and manufacturers work to address these vulnerabilities, users and businesses must remain vigilant and adopt proactive measures to protect their devices. Implementing advanced technical solutions and adopting robust security practices will be crucial to ensuring digital operational resilience in an ever-evolving threat landscape.
Editorial Note and Disclaimer
The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.
GoYou does not constitute a journalistic publication or an editorial product pursuant to Law No. 62/2001 and does not perform real-time information activities.
The GoYou project does not provide professional, technical, legal, or financial advice and disclaims all liability for the improper use of the information published.
In the Crypto sector, every investment involves risks: readers are invited to always inform themselves independently before making any decision.