Michigan State Researchers Find Critical Flaws in U.S. Cellular Blocking Systems
Security gaps allow attackers to remotely disconnect phones and IoT devices by filing fraudulent theft reports.
Researchers from Michigan State University have uncovered critical vulnerabilities in the systems U.S. cellular carriers use to block lost or stolen devices. These flaws allow an attacker to remotely disconnect a stranger's phone or IoT device from the network by filing fraudulent reports.
According to the study, the vulnerability stems from minimal identity checks during the reporting process. In some cases, hardware leaks its unique 15-digit International Mobile Equipment Identity (IMEI) number to unauthorized requests, providing attackers with the necessary identifier to trigger a block. Guan-Hua Tu, an associate professor at Michigan State University specializing in wireless networking and security, noted that an attacker can use these weaknesses to cut a device off remotely, “even though the device has not actually been lost, stolen or sold.”
How Cellular Blocking Works
Cellular devices rely on the IMEI number as a unique hardware identifier. When a user reports a device as stolen, carriers add that specific number to an Equipment Identity Register (EIR). Once a device is listed in the EIR, the network refuses registration for that hardware, regardless of which SIM card is inserted into the device. The researchers tested this ecosystem across three major U.S. carriers and their associated resellers to identify where the verification process fails.
Risks to Infrastructure and Safety
This vulnerability enables targeted denial-of-service attacks against both individuals and critical infrastructure. The risk extends beyond smartphones to include IoT devices such as home security gateways, water and electricity meters, and cardiac monitors. If these devices are silenced, critical alarms or health monitoring data may fail to reach homeowners or emergency centers, often without the victim being notified that their connection has been severed.
The Path Forward
While the core vulnerability has been demonstrated, the industry must now address the lack of rigorous identity verification for reporting stolen hardware. Future security updates may need to focus on how IMEI numbers are exposed to unauthorized requests and how carriers validate the ownership of a device before adding it to the Equipment Identity Register. It remains to be seen how quickly major carriers will implement stricter authentication to prevent these fraudulent disconnections. The ability to weaponize a legitimate security feature—the theft block—highlights a systemic failure in how hardware identity is managed across the telecommunications landscape.