A $4 Lost-Phone Report Could Silence Your Home Alarm
The phone was still sealed in its box. Yet after researchers reported its identifier as lost, it could not connect to the mobile network. That demonstration exposes a larger problem: the anti-theft system intended to protect devices can become a cheap way to disconnect someone else’s phone or a home alarm’s cellular backup.
Michigan State University and collaborators described six weaknesses spanning devices, mobile operators and the cross-carrier system that shares lost-device records. Their MobiSys 2026 paper won a Best Paper Award. The university published its account on 9 September 2026; its page supplies no publication time. The paper itself dates from June, so this is new reporting and explanation of published research, not a newly discovered zero-day.
A lost-phone report does more than lock an account
Every cellular device has an IMEI, an identifier separate from its phone number and SIM. When an owner reports a device lost or stolen, an operator can place that IMEI on a block list so the device cannot register on the network. The defense makes a stolen handset less useful. But it also creates an availability decision with consequences beyond the reporting customer.
The researchers tested the reporting practices of three major US carriers and associated resellers. They found weaknesses in how a reporter’s identity and ownership were checked, what kinds of devices could be reported, and what trust information followed a block-list entry to other operators. A brief prior network attachment could be treated as evidence that a device belonged to a reporting account. That is not the same as proving ownership.
In the team’s experiments, filing a fraudulent report cost $2.50 to $4 per device and took tens of seconds. Those figures describe the tested services and conditions, not a universal price or a guarantee that every carrier can be abused in the same way. The attacker also needs the target IMEI. The researchers showed two routes to obtaining it, each with its own prerequisites.
Why a home alarm’s backup link matters
Many alarm gateways primarily use Wi-Fi and fall back to cellular when the home connection fails. In one laboratory attack, researchers briefly disrupted Wi-Fi, used a nearby rogue cellular station and a susceptible modem to obtain the gateway’s IMEI, then later submitted a false lost-device report. At a later interruption of Wi-Fi, the blocked gateway could no longer use its cellular backup to send alarm notifications.
This is not an internet-only attack against any alarm. It requires local radio access, a vulnerable modem, knowledge of the identifier and abuse of the reporting workflow. Still, the two stages can be separated in time. The researchers tested a representative gateway and service, and said two major US home-security providers use affected chipset families. That is a serious trust-boundary failure: a theft-prevention process can silently suppress an unrelated safety system’s fallback channel.
The team also demonstrated a second scenario using a Samsung Galaxy Z Fold7. An identifier available through supply-chain data before the phone’s public release was reported lost while the handset remained sealed. On setup, it could not connect. This does not establish a real-world criminal campaign, but it shows how a false report could affect legitimate new devices before their owners ever use them.
The fix belongs to carriers and device makers
For an individual whose service unexpectedly stops, the immediate step is to ask the carrier to check whether the IMEI was incorrectly blacklisted and to gather purchase documentation. Reversing a false report may require proving ownership and, if the record crossed operators, escalation through industry processes. Switching SIMs will not solve a device-level IMEI block.
For operators, the researchers recommend stronger identity and multi-factor ownership checks, better security metadata when sharing reports, and a review path for doubtful requests. Device certification should also test whether a modem reveals its IMEI to an unauthenticated radio request. Operators supporting alarms and other cellular IoT should test how a false blacklist entry affects backup availability, alerts and restoration. These are proposed countermeasures, not a vendor patch that has already reached every affected system.
The researchers disclosed the findings to affected parties, and Michigan State says the GSMA passed them to its device-security group. The broader lesson is that an anti-theft control cannot be judged only by whether it blocks stolen phones. It must also prove that one customer cannot turn it against another person’s device or emergency connection.
Sources: Michigan State University, 9 September 2026; MobiSys 2026 paper and public review, June 2026; Help Net Security, 11 September 2026.


