A system designed to kick stolen phones off cellular networks can be turned against phones that were never stolen in the first place.
Researchers at Michigan State University recently reported six flaws in lost-and-stolen device reporting systems that could allow legitimate devices to be remotely blacklisted from cellular service.
The attack takes advantage of a basic assumption in the reporting ecosystem: once a device is reported stolen, cellular networks are supposed to reject it. But the researchers found that carriers' checks on who can report a device and whether that person actually owns it can be insufficient, turning a theft-prevention mechanism into a potential way to cut legitimate equipment off from cellular service.
How phones can be stolen without actually being stolen
Imagine buying a brand-new device, opening the box, turning it on, and finding out your carrier thinks you stole it. Researchers proved this is possible with what they call the Zero-Day Flagship Phone Ambush, an attack that abuses weaknesses in how carriers verify the identity of anyone reporting a phone as stolen.
The trick feels similar to an Instagram incident in June in which attackers manipulated Meta’s AI support flow into treating an attacker-controlled email as the account owner's. While different, the similarity stems from how a malicious individual could fool a safety system into believing they are authorized to report a sensitive situation.
The phone attack gets even stranger because the researchers could target devices before they get an owner. To prove that, the researchers obtained the International Mobile Equipment Identity (IMEI) of a Samsung Galaxy Z Fold7 before the phone went on sale, reported that identifier as lost, and then opened a sealed unit later to find the legitimate phone blocked from the cellular network.
That effectively turns a flaw in a carrier support workflow into a potential denial-of-service tool for new phones, and potentially the phone that is already in your hands.
The same weakness can affect cellular security backups
The researchers found another way to turn the same reporting weakness against home security systems, this time by going after the cellular connection that is supposed to keep them online when Wi-Fi fails. They termed the exploit Home Security System Freezing.
The researchers found that another flaw, this time in the cellular modems of home security systems, could let an attacker obtain the system’s IMEI, giving them the identifier needed for the next part of the attack.
According to Digital Trends, this flaw affected two major home security providers, which together account for 41% of the U.S. home security market.
From there, the attack follows the same basic pattern as the phone exploit: the carrier blacklists its IMEI, and cellular networks then treat the legitimate security device as if it were stolen.
The attack does not compromise the alarm software itself. Instead, it targets the cellular connection designed to keep the system connected when Wi-Fi is unavailable. If that backup connection is blocked, the system could lose an important secondary communications path.
What does this mean for users?
For users, the bigger concern is what gets cut off when that system is abused. A phone could suddenly lose cellular service despite never being stolen, a scenario that can become more confusing when the phone is new.
The effect also extends beyond confusion. Imagine running out of Wi-Fi coverage or trying to make an urgent call, only to realize your device is blacklisted.
A home security system, on the other hand, could lose the cellular backup it relies on when Wi-Fi fails, potentially leaving a homeowner unaware that the backup connection has been disabled. That moment of blank can be exploited for theft and other malicious purposes.
That makes this more than a strange carrier bug: the system users trust to protect themselves and their assets can, under the conditions demonstrated by the researchers, be turned against legitimate users.
The researchers presented their reports to the affected bodies, including the GSM Association (GSMA), and proposed measures to keep the service useful for legitimate users while also raising the bar for malicious actors.
The recommendations include:
- Expand the 3rd Generation Partnership Project conformance testing to protect IMEIs.
- Strengthen identity checks for people submitting lost-device reports.
- Use multiple factors to verify a reporter's relationship to the device.
- Tighten security requirements for GSMA’s Central Equipment Identity Register (CEIR), which handles cross-carrier sharing of blocked-device information.
For users, there is no simple setting that fixes a weakness in carrier blacklisting infrastructure. An unexplained loss of cellular service may therefore require checking with the carrier to determine whether the device's IMEI has been incorrectly flagged as lost or stolen.
The larger fix sits with carriers, device makers, and industry bodies. The researchers' work shows that a system built to protect stolen devices is only as trustworthy as the process used to decide which devices belong on the blacklist in the first place.
In other cybersecurity news, attackers reportedly hijacked HBO Max’s verified Reddit account and used it to run 108 malicious ads that directed Windows and macOS users to ClickFix attacks designed to install information-stealing malware.





