When a phone is lost or stolen, reporting it to a cellular carrier is supposed to prevent unauthorized use. Michigan State University researchers have found that weaknesses in the reporting system itself could potentially be exploited to block legitimate devices from cellular networks.
The researchers identified six vulnerabilities spanning mobile devices, carrier reporting infrastructure and cross-carrier operations, and demonstrated their security impact through two experimental attacks on operational 4G and 5G networks.
“We found that the security mechanisms that are supposed to protect the lost and stolen phone reporting service are not sufficient,” said Guan-Hua Tu, associate professor in the Michigan State University College of Engineering and one of the study’s authors. “An attacker can potentially abuse these weaknesses to remotely block a device from cellular service, even though the device has not actually been lost, stolen or sold.”
Turning a theft-prevention system into a potential attack
When a phone is lost or stolen, its owner can report the device to a mobile carrier using its unique International Mobile Equipment Identity, or IMEI. The carrier adds the IMEI to an Equipment Identity Register, or EIR, effectively blacklisting the device so it cannot connect to cellular networks.
Researchers examined this lost and stolen device reporting ecosystem, including devices, carrier reporting systems and the cross-carrier infrastructure that shares blacklisted device information. The researchers found weaknesses in how carriers verify the identities of people submitting lost-device reports and whether those people own the devices. For example, some reporting systems allow users to report devices that were not covered by their own service subscriptions. The device-blocking information shared between systems lacks sufficient security information to help carriers identify potentially fraudulent reports.
The researchers found that these vulnerabilities reflect broader gaps in how lost and stolen device reports are verified and shared. Neither 3GPP nor GSMA — two major organizations that collaborate to manage global mobile communication standards — standardizes how carriers should verify the identity of someone reporting a device or establish device ownership. Carriers therefore rely on their own policies and usage-based approaches.
Together, the vulnerabilities could allow attackers to submit fraudulent lost-device reports that cause legitimate devices to be blacklisted.
Home security systems could be remotely frozen
One of the researchers’ proof-of-concept attacks, called Home Security System Freezing, demonstrates how the vulnerabilities could affect more than smartphones. It could prevent cellular-connected home security systems from communicating with homeowners and monitoring centers, potentially blocking critical alarm notifications during an emergency.
Many home security gateways use Wi-Fi as their primary connection and low-cost cellular IoT for backup connectivity. Wi-Fi can be disrupted relatively stealthily because it is more difficult for carriers to pinpoint a localized attacker, while continuous cellular jamming requires high-power transmissions that carriers can detect and localize using nearby base stations.
Unlike traditional cellular jamming, the approach does not require an attacker to continuously transmit a powerful signal near the victim. Instead, researchers demonstrated how an attacker could briefly disrupt a home security gateway’s Wi-Fi connection, exploit a vulnerability in its cellular IoT modem to obtain its IMEI, and later report the device as lost. Because the two steps could occur weeks or months apart, the attack could be difficult to trace and localize.
Researchers tested representative home security gateways and found that two major U.S. home security providers, together accounting for more than 41% of the U.S. market, use cellular IoT modem chipsets that are vulnerable to the demonstrated attack.
The potential implications extend beyond home security. Cellular IoT modems are used in devices including water and electricity meters, industrial sensors and medical monitoring systems. Losing cellular connectivity in these settings could disrupt critical services and, depending on the device and its role, potentially create safety risks.
A potential attack on new flagship phones
The second proof-of-concept attack, called Zero-Day Flagship Phone Ambush, could target the IMEIs of new flagship smartphones before or around their release and exploit weaknesses in the reporting system to have those devices classified as lost or stolen.
Because a single fraudulent report can potentially propagate through cross-carrier systems, an attacker could attempt to block large numbers of newly released devices from connecting to cellular networks.
Researchers demonstrated the feasibility of the attack using a Samsung Galaxy Z Fold7 as a representative flagship device. They found that its device identifier could be obtained before the phone’s public release, and they used the reporting-system vulnerabilities to demonstrate how a legitimate device could be blocked from cellular service.
Strengthening the system
The researchers proposed four categories of countermeasures while maintaining existing lost-device reporting services.
The recommendations include expanding the 3rd Generation Partnership Project, or 3GPP, conformance testing to more thoroughly evaluate how devices protect IMEIs; strengthening identity verification for people submitting lost-device reports; using multiple factors to verify the relationship between a reporter and a device; and improving security requirements for the Global System for Mobile Communications Association’s, or GSMA’s, cross-carrier Central Equipment Identity Register system.
The researchers emphasize that their goal is not to eliminate lost and stolen device reporting, which remains an important security service, but to make the system more resistant to abuse.
“We want to preserve the existing workflow for legitimate users while raising the cost for attackers,” Tu said. “The goal is to make the system more secure without making it difficult for people who genuinely lose their phones to report them.”
The researchers disclosed their findings to affected carriers, chipset vendors, device manufacturers and relevant standards organizations. The GSMA has acknowledged the findings and forwarded them to its device security group for further discussion and remediation. The hope is that these recommendations could strengthen the reporting system while preserving the existing process for people who legitimately lose their phones.
The research was led by MSU doctoral student Min-Yue Chen and Tu, in collaboration with researchers at the University of Maryland, Baltimore County; National Yang Ming Chiao Tung University in Taiwan; and Utah State University.
The study, “Insecurity of Lost/Stolen Phone Reporting Services: Vulnerabilities, Attacks and Countermeasures,” received the Best Paper Award at the 24th ACM International Conference on Mobile Systems, Applications and Services, or MobiSys 2026, marking the first time an MSU-led paper has received the honor.
MobiSys is the premier international venue for research on mobile computing and wireless systems.
MSU College of Engineering Media and Public Relations page