Low‑Cost Fake 5G Base Station Can Track Subscribers via Predictable Temporary IDs
What Happened – Researchers from i2CAT, the University of Murcia and NEC Labs built a cheap tool called 5G‑Shark that masquerades as a legitimate 5G base station. By exploiting unauthenticated cell‑reselection, the device lures a target phone onto a rogue cell, captures the temporary subscriber identifier (GUTI), and shows that many commercial networks rotate these IDs in a near‑sequential, predictable pattern. The result is the ability to link 84‑96 % of a subscriber’s successive registrations and effectively track the user without ever exposing the permanent IMSI.
Why It Matters for Trust & Control Assurance
- Continuous control‑assurance programs must verify that privacy‑related controls (e.g., randomization of temporary identifiers) are operating as intended, otherwise audit evidence will show a gap.
- Evidence of predictable GUTI rotation is a concrete control‑mapping finding that can be collected, monitored, and reported to demonstrate due diligence.
- Detecting rogue base‑station activity and documenting mitigation steps provides a defensible audit trail for privacy and telecom‑specific regulations.
Who Is Affected – Mobile network operators, telecom infrastructure providers, and all 5G subscribers who rely on the network’s privacy guarantees.
Recommended Actions
- Conduct a systematic audit of GUTI rotation randomness across all cells.
- Update network configuration to enforce cryptographically random temporary ID assignment per 3GPP specifications.
- Deploy monitoring for unauthenticated rogue base stations (e.g., SDR‑based detection).
- Record control evidence in a Trust Center or similar repository to support audit readiness. Source: https://www.helpnetsecurity.com/2026/09/22/5g-subscriber-tracking-research/
Technical Notes – The attack leverages the cell reselection procedure, which accepts broadcast messages without authentication. 5G‑Shark runs on open‑source software and inexpensive SDR hardware; no jamming or malformed packets are required. The captured identifier is the GUTI, which should be randomly reassigned but was observed moving only ~0.11 % of the identifier space in most tested networks. Source: https://www.helpnetsecurity.com/2026/09/22/5g-subscriber-tracking-research/