Researchers Expose Flaws Allowing Remote Disabling of Unactivated Cell Phones
Security researchers have uncovered multiple vulnerabilities in cellular network systems that allow attackers to remotely disable new, unactivated phones and other devices for mere dollars.

Researchers from Michigan State University and partner institutions have demonstrated a concerning security flaw within the systems used by cellular carriers to manage lost and stolen devices. Their findings reveal that attackers can remotely disable a brand-new phone, even before it has been activated or opened, by exploiting weaknesses in the reporting and blocking mechanisms.
The attack involves obtaining a device's unique International Mobile Equipment Identity (IMEI) number, often found on the product's packaging. With this number, an attacker can then report the device as lost or stolen to the cellular carrier. This action causes the carrier to add the IMEI to a blacklist, preventing the device from connecting to the cellular network, regardless of who possesses it or which SIM card is inserted.
The research team identified six distinct weaknesses across the device, carrier reporting systems, and cross-carrier data sharing infrastructure. These vulnerabilities were tested against three major U.S. carriers and their resellers. The cost to exploit these flaws was remarkably low, ranging from $2.50 to $4 per device, with the process taking as little as 20 to 80 seconds.
A critical aspect of the vulnerability lies in the inadequate identity verification processes employed by carriers. The researchers found that carriers often accept lost-device reports from individuals with active service, even if those individuals are not the actual owners of the device. Furthermore, setting up a traceable prepaid account often requires minimal verification, such as a government ID or Social Security number, and can even be paid for anonymously with gift cards.
Beyond phones, the researchers confirmed that the vulnerabilities extend to other cellular-enabled devices. They successfully reported smartwatches, cellular development boards, and even devices physically incapable of operating on the carrier's network as lost. This indicates a broader systemic issue that could impact various connected devices.
One particularly alarming demonstration involved a home security gateway. By first luring the device onto a rogue base station to capture its IMEI and then disrupting its Wi-Fi connection, attackers could trigger the gateway to fall back to its cellular backup. Once on cellular, the device would be blocked, rendering the alarm system inoperable and leaving homeowners unaware of potential security breaches.
The attack also targets new flagship phones before they are even sold. By purchasing IMEI databases, attackers can obtain the unique identifiers of upcoming devices. They can then use these IMEIs to block large batches of unactivated phones, potentially causing significant financial loss to manufacturers and retailers, with minimal cost and effort.
The implications of these findings are substantial, highlighting a systemic failure in securing the lost and stolen device reporting ecosystem. The lack of robust verification and the ease with which devices can be blocked without the owner's knowledge or recourse pose a significant threat to consumers and businesses alike. Victims are left with non-functional devices and no immediate notification or clear path to resolution.