HomeIntelligenceBrief
BREACH BRIEF 🟠 High ThreatIntel

Low-Cost Fake 5G Base Station Can Track Subscribers via Predictable Temporary IDs

Researchers built 5G‑Shark, a cheap fake base station that lures phones onto a rogue cell and captures temporary GUTI identifiers. Tests of three operators showed predictable ID rotation, allowing linkage of 84‑96 % of re‑registrations. The finding highlights a privacy control gap that continuous control‑assurance programs must monitor.

Verisq™ Intelligence · 📅 September 22, 2026 · 📰 helpnetsecurity.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
helpnetsecurity.com

Low‑Cost Fake 5G Base Station Can Track Subscribers via Predictable Temporary IDs

What Happened – Researchers from i2CAT, the University of Murcia and NEC Labs built a cheap tool called 5G‑Shark that masquerades as a legitimate 5G base station. By exploiting unauthenticated cell‑reselection, the device lures a target phone onto a rogue cell, captures the temporary subscriber identifier (GUTI), and shows that many commercial networks rotate these IDs in a near‑sequential, predictable pattern. The result is the ability to link 84‑96 % of a subscriber’s successive registrations and effectively track the user without ever exposing the permanent IMSI.

Why It Matters for Trust & Control Assurance

  • Continuous control‑assurance programs must verify that privacy‑related controls (e.g., randomization of temporary identifiers) are operating as intended, otherwise audit evidence will show a gap.
  • Evidence of predictable GUTI rotation is a concrete control‑mapping finding that can be collected, monitored, and reported to demonstrate due diligence.
  • Detecting rogue base‑station activity and documenting mitigation steps provides a defensible audit trail for privacy and telecom‑specific regulations.

Who Is Affected – Mobile network operators, telecom infrastructure providers, and all 5G subscribers who rely on the network’s privacy guarantees.

Recommended Actions

  • Conduct a systematic audit of GUTI rotation randomness across all cells.
  • Update network configuration to enforce cryptographically random temporary ID assignment per 3GPP specifications.
  • Deploy monitoring for unauthenticated rogue base stations (e.g., SDR‑based detection).
  • Record control evidence in a Trust Center or similar repository to support audit readiness. Source: https://www.helpnetsecurity.com/2026/09/22/5g-subscriber-tracking-research/

Technical Notes – The attack leverages the cell reselection procedure, which accepts broadcast messages without authentication. 5G‑Shark runs on open‑source software and inexpensive SDR hardware; no jamming or malformed packets are required. The captured identifier is the GUTI, which should be randomly reassigned but was observed moving only ~0.11 % of the identifier space in most tested networks. Source: https://www.helpnetsecurity.com/2026/09/22/5g-subscriber-tracking-research/

📰 Original Source
https://www.helpnetsecurity.com/2026/09/22/5g-subscriber-tracking-research/

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →