Low-Cost Phone Deactivation: Removing a Stranger’s Device from Cellular Network
Getting a stranger s phone kicked off the cellular network costs a few dollars
Study Overview
Researchers at Michigan State University and three collaborating institutions conducted experiments revealing critical flaws in cellular network security protocols.
Methodology
The study involved purchasing a Samsung Galaxy Z Fold 7, replicating its factory-embedded 15-digit IMEI, and submitting a lost-device report to a carrier. After opening the unactivated device, the researchers found it disconnected from the network despite being new and unused. This demonstrated vulnerabilities across multiple layers of the device tracking system.
Key Findings
The team identified six systemic weaknesses in carrier mechanisms for disabling lost or stolen devices. These included flaws in device authentication, carrier reporting processes, and cross-carrier blocklist sharing. Testing on three major U.S. carriers and their resellers revealed that unauthorized device deactivation could be executed for $2.50 to $4, with completion times ranging from 20 to 80 seconds. The attack vector was not limited to smartphones; it extended to devices like home security alarm panels, industrial sensors, and cellular development boards.
Systemic Weaknesses
The core issue stemmed from insufficient verification processes. Carriers accepted reports only from users with active service plans, but this did not prevent anonymous accounts created with prepaid SIMs and anonymous payment methods. Prepaid customers could file reports without providing government-issued identification or Social Security numbers. The researchers exploited this by setting up accounts using anonymous Visa gift cards, bypassing basic traceability measures. Ownership verification relied on device activity history rather than direct proof of ownership. A device needed only minimal network interaction—such as one second of connectivity on one carrier or a minute on others—to pass verification. Once a device was reported, it was blocked from rejoining the network regardless of its actual status. The study demonstrated that even devices not designed for cellular use, such as smartwatches or industrial equipment, could be targeted.
Blocklist Synchronization Issues
A critical finding revealed that carriers did not synchronize their blocklists effectively. A device reported lost on one carrier remained functional on the other two, indicating at least two carriers were not updating global databases as claimed.
Attack Scenarios
Two primary attack scenarios were tested. The first involved compromising home security gateways. These devices, which use low-power cellular chips for backup connectivity, were found vulnerable due to chipset manufacturers accounting for over 40% of the market. Researchers simulated an attack by disrupting Wi-Fi connections, forcing the gateway to switch to cellular, and then extracting its IMEI via a rogue base station. This allowed the device to be blocked without triggering alerts. The attack required 17 seconds in the lab and left no trace for carriers to detect. The second attack targeted new smartphones before they were officially released. IMEIs are assigned during manufacturing, and the researchers obtained a database of these numbers for $600 plus monthly fees. By reporting ten devices using a single prepaid account, they demonstrated that blocking 100 units would cost $250 to $400, far below the value of the devices themselves. Victims received no notification of the block, and restoring service required proving ownership through receipts and identity verification.
Home Security Gateways
The first involved compromising home security gateways. These devices, which use low-power cellular chips for backup connectivity, were found vulnerable due to chipset manufacturers accounting for over 40% of the market. Researchers simulated an attack by disrupting Wi-Fi connections, forcing the gateway to switch to cellular, and then extracting its IMEI via a rogue base
