Researchers from the i2CAT Foundation, the University of Murcia, and NEC Laboratories Europe created 5G-Shark to lure phones onto a fake base station and test how commercial 5G networks handle identity privacy. Their tests found that while permanent IDs were mostly hidden, predictable temporary IDs still enabled subscriber tracking on some networks, and crafted reject messages could force phones into service loss, retry loops, or modem freezes. #5G-Shark #i2CATFoundation #UniversityofMurcia #NECLaboratoriesEurope #SamsungGalaxyS23
Keypoints
- 5G-Shark uses a fake base station to pull idle phones onto a controlled cell.
- The tool works with open-source software and low-cost software-defined radio hardware.
- Most tested networks concealed permanent subscriber IDs, but some still leaked trackable temporary IDs.
- Predictable GUTI rotation allowed linking most consecutive re-registrations on some operators.
- Crafted Registration Reject messages caused denial-of-service-like effects on a Samsung Galaxy S23 and other devices.
Read More: https://www.helpnetsecurity.com/2026/09/22/5g-subscriber-tracking-research/