HomeIntelligenceBrief
BREACH BRIEF 🟠 High ThreatIntel

Anyone Can Block Legitimate Phones via Carrier Lost‑Device Reporting, Researchers Find

Researchers from Michigan State University exposed six weaknesses in U.S. carrier lost‑device reporting that let an attacker block a phone or IoT device they don’t own, costing only a few dollars. The flaw highlights gaps in third‑party identity verification and continuous control monitoring for telecom services.

Verisq™ Intelligence · 📅 September 11, 2026 · 📰 helpnetsecurity.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
2 recommended
📰
Source
helpnetsecurity.com

Anyone Can Block Legitimate Phones via Carrier Lost‑Device Reporting

What Happened — Researchers from Michigan State University bought a new Samsung Galaxy Z Fold 7, used the IMEI from the sealed box, and filed a “lost device” report with three major U.S. carriers. All three carriers accepted the report from prepaid accounts with no government‑ID verification and blocked the phone within 20‑80 seconds, costing only $2.50‑$4 per block. The study identified six weaknesses across device, carrier, and cross‑carrier block‑list sharing processes.

Why It Matters for Trust & Control Assurance

  • Highlights a gap in third‑party identity verification that defeats continuous control‑monitoring objectives.
  • Shows the need for auditable evidence of carrier‑provided device‑ownership checks to satisfy vendor‑risk programs.
  • Demonstrates how a low‑cost, rapid attack can disrupt critical IoT or communications services, stressing the importance of documented oversight of telecom providers.

Who Is Affected — Telecom carriers, enterprises that depend on cellular connectivity for phones, alarm panels, and other IoT devices.

Recommended Actions

  • Review your carrier’s lost‑device reporting workflow for strong identity‑verification controls.
  • Capture and retain logs of block‑list submissions as part of your audit‑readiness evidence.
  • Incorporate carrier‑level checks into your continuous third‑party risk monitoring program. Source: https://www.helpnetsecurity.com/2026/09/11/cellular-network-lost-phone-reporting/

Technical Notes — The attack exploits weak verification of prepaid account sign‑up (no SSN or government ID) and minimal device‑activity thresholds (as low as one second) before accepting a block request. No software vulnerability (CVE) is involved; the weakness is procedural. Source: https://www.helpnetsecurity.com/2026/09/11/cellular-network-lost-phone-reporting/

📰 Original Source
https://www.helpnetsecurity.com/2026/09/11/cellular-network-lost-phone-reporting/

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →