Anyone Can Block Legitimate Phones via Carrier Lost‑Device Reporting
What Happened — Researchers from Michigan State University bought a new Samsung Galaxy Z Fold 7, used the IMEI from the sealed box, and filed a “lost device” report with three major U.S. carriers. All three carriers accepted the report from prepaid accounts with no government‑ID verification and blocked the phone within 20‑80 seconds, costing only $2.50‑$4 per block. The study identified six weaknesses across device, carrier, and cross‑carrier block‑list sharing processes.
Why It Matters for Trust & Control Assurance —
- Highlights a gap in third‑party identity verification that defeats continuous control‑monitoring objectives.
- Shows the need for auditable evidence of carrier‑provided device‑ownership checks to satisfy vendor‑risk programs.
- Demonstrates how a low‑cost, rapid attack can disrupt critical IoT or communications services, stressing the importance of documented oversight of telecom providers.
Who Is Affected — Telecom carriers, enterprises that depend on cellular connectivity for phones, alarm panels, and other IoT devices.
Recommended Actions —
- Review your carrier’s lost‑device reporting workflow for strong identity‑verification controls.
- Capture and retain logs of block‑list submissions as part of your audit‑readiness evidence.
- Incorporate carrier‑level checks into your continuous third‑party risk monitoring program. Source: https://www.helpnetsecurity.com/2026/09/11/cellular-network-lost-phone-reporting/
Technical Notes — The attack exploits weak verification of prepaid account sign‑up (no SSN or government ID) and minimal device‑activity thresholds (as low as one second) before accepting a block request. No software vulnerability (CVE) is involved; the weakness is procedural. Source: https://www.helpnetsecurity.com/2026/09/11/cellular-network-lost-phone-reporting/