Researchers Develop Low-Cost Tool to Track 5G Subscribers
A new tool called 5G-Shark can track 5G subscribers by luring their phones to a fake base station, despite 5G's privacy enhancements.

Researchers have developed a surprisingly affordable tool, dubbed 5G-Shark, capable of tracking 5G mobile subscribers. The system works by creating a fake base station designed to lure target phones into connecting with it. Once connected, the tool can then probe the device, effectively tracking its user.
The research, conducted by teams from the i2CAT Foundation, the University of Murcia, and NEC Laboratories Europe, aimed to audit the privacy protections of commercial 5G networks. While 5G networks, particularly standalone (SA) 5G deployments, were designed with enhanced privacy features to obscure permanent device identifiers, the study revealed a persistent vulnerability.
In their tests on commercial standalone 5G networks, the researchers found that while permanent identities were successfully concealed in almost all instances, the networks continued to issue temporary identifiers. These temporary IDs, crucial for network operation, were found to be handed out in a predictable pattern. This predictability allows an observer, such as the 5G-Shark tool, to potentially track subscribers over time and across different locations.
The implications of this research are significant for mobile privacy. Although 5G offers improvements over previous generations, the continued reliance on predictable temporary identifiers means that sophisticated adversaries or even determined researchers could still potentially track individuals. This could have ramifications for user privacy, location tracking, and the overall security posture of mobile communications.
The development of 5G-Shark highlights the ongoing cat-and-mouse game between network security designers and those seeking to exploit vulnerabilities. The tool's low cost makes such tracking techniques more accessible, potentially lowering the barrier to entry for malicious actors or surveillance operations.
While the research focused on specific commercial networks, it raises broader questions about the implementation and robustness of 5G privacy standards globally. Further investigation and potential updates to network protocols or device firmware may be necessary to fully address the identified tracking vectors.
The findings underscore the importance of continuous security auditing and research in evolving mobile technologies. As networks become more complex, understanding and mitigating potential privacy leaks remains a critical challenge for the cybersecurity community.