Researchers showed that attackers can abuse mobile carriers’ “lost/stolen phone” reporting process to get devices blocked from the cellular network, even when the devices were never lost. With only a prepaid account and a target device’s IMEI number, blocking can cost just a few dollars and take under two minutes, and victims often get no warning until service stops.
How the attack worked
Researchers demonstrated that a carrier's lost/stolen device reporting process, meant to help legitimate customers protect themselves after theft, can be abused to disable devices the reporter never owned. All that was needed was a device's IMEI number and a prepaid account. In one test, researchers bought a Samsung Galaxy Z Fold 7, copied the identification number printed on the sealed box, and reported the still-unopened phone as lost. The block, which adds the IMEI to the network's equipment identity register, cost between $2.50 and $4 and took about 20 to 80 seconds to take effect.
A second scenario extended the technique to IoT: an attacker could knock a home alarm gateway off Wi-Fi to force it onto cellular backup, use a rogue base station to capture its IMEI, then later file a lost-device report to block it. This can be split into two phases months apart, and alarms simply stop reaching the homeowner and monitoring center with no explanation. A third scenario involved sourcing IMEIs for flagship phones before they even ship, using supply-chain verification databases, and scripting bulk reports against carrier web forms.
Why it succeeded
The reporting process relied on weak signals of ownership rather than actual proof. None of the examined carriers verified a Social Security number or government ID for prepaid account setup, and prepaid customers could file reports just like anyone else. Ownership checks in some cases only confirmed that a device had briefly connected to the network, as little as one second in one instance, which establishes prior activity but not who actually owns the device. Reports could also be funded anonymously, for example with a gift card.
What to watch for
- Reporting accounts that show minimal identity verification, particularly prepaid accounts
- Devices with very short historical network attachment being treated as sufficient ownership proof
- A single account filing multiple lost-device reports without triggering review
- Automated or scripted submissions hitting carrier web forms
- Cross-carrier blocklist inconsistencies, where a device blocked on one carrier still works elsewhere
How to build resistance
Organizations handling lost-device workflows should treat the reporting process itself as fraud-prone. Practical steps include routing reporters through government-ID verification services already used by federal agencies, combining multiple signals for ownership checks instead of relying on brief network activity alone, escalating doubtful cases to in-store verification, and notifying the actual account holder or device owner whenever a block is applied so fraudulent reports can be caught quickly. IoT and safety-related device makers should also review whether their hardware leaks IMEIs to unauthenticated queries and how resilient their products are to sudden cellular deactivation.
Key findings
- Researchers blocked a brand-new, unopened phone by copying the IMEI from the sealed box and filing a fraudulent lost-device report.
- Blocking a device they did not own cost between $2.50 and $4 and took about 20–80 seconds.
- Prepaid accounts could file lost-device reports without Social Security number or government ID verification, and could be funded with an anonymous gift card.
- Carriers’ “ownership” checks relied on whether a device had been active on the account briefly (as little as one second on one carrier).
- Attackers can target non-phones (e.g., home alarm panels) if they can obtain the device IMEI; victims typically receive no notice when blocked.
- In a demonstrated IoT scenario, an attacker could extract an alarm gateway’s IMEI via a rogue base station after knocking it off Wi‑Fi, then later block it so alarms stop reaching homeowners/monitoring centers.
- Cross-carrier global blocklist syncing appeared inconsistent: a phone reported lost on one carrier still worked on other carriers a week later.
Who’s being targeted
- Commonly targeted roles: Telecom Customer Support, Telecom Fraud / Risk Operations, Carrier Digital/eCommerce Teams, IoT Product/Security Teams, Home Security Operations.
- Affected industries: Telecommunications (mobile carriers and resellers), Consumer electronics (smartphones), Home security and alarm monitoring, Industrial IoT (sensors, development boards), Utilities (meters) (mentioned as potentially affected), Healthcare devices (cardiac monitors) (mentioned as potentially affected).
- Attack channels: website, physical.
- Impersonated: Legitimate subscriber/customer reporting their own lost phone, Legitimate subscriber/customer reporting their own device as lost, Legitimate customer reporting devices as lost.
Red flags to watch for
- Reporter uses a prepaid account with minimal identity proofing
- Ownership verification is based only on brief prior network attachment time
- Multiple devices reported in bulk without additional review
- IMEI can be collected via a short, hard-to-detect local rogue base station event
- Attack can be split into two phases “months apart,” making investigation harder
- No victim notification when the device is blocked
- High-volume reporting from a small number of prepaid accounts
- Automation against web forms (“script to drive the carriers’ web forms”)
- IMEIs sourced from third-party databases rather than customer-provided proof
Frequently asked questions
How can someone block a phone they don't own?
Researchers showed that filing a fraudulent lost/stolen device report with a carrier, using only the target device's IMEI, can get it blocked from the network. This worked even on a brand-new, unopened phone whose IMEI was copied from the sealed box.
How much does it cost to fraudulently block a device?
Blocking a device the researchers did not own cost between $2.50 and $4 and took roughly 20 to 80 seconds.
Do carriers verify identity before accepting a lost-device report?
In the cases examined, none of the carriers verified a Social Security number or government ID when setting up a prepaid account, and prepaid customers could file lost-device reports the same as anyone else.
Can this attack affect devices other than phones?
Yes. In a demonstrated scenario, an attacker extracted a home alarm gateway's IMEI via a rogue base station and later blocked it, stopping alarm signals from reaching the homeowner and monitoring center.
Read the video transcript
Imagine your phone just drops off the network, no signal, no warning, and it’s not a outage. Someone paid three bucks to brick it. Researchers bought a brand‑new Samsung, just copied the IMEI off the sealed box, used a prepaid account funded with a gift card, and filed a fake ‘lost device’ report online. For about $2.50, in under a minute, the carrier blocked that phone from the cellular network. Carriers often treat any device that briefly touched an account, even for one second, as ‘owned’ and don’t verify a Social Security number or ID for prepaid. Victims get zero notice; service just stops. This isn’t just phones, home alarm panels and IoT gateways can be silently disabled the same way. Here’s the move: treat every ‘lost or stolen device’ report as high‑fraud. If it’s on a prepaid account or the device was barely on the network, pause the block and escalate for stronger ID checks before you kill that IMEI.