Mobile networks expose IMEI and other phone data to attackers – report
Over 1,000 network operators have been warned.

Image by Foto500 | Shutterstock
- An incoming call can expose a phone’s IMEI, model, and operating system before the recipient answers.
- BR confirmed the flaw with 70 test calls across major German mobile networks.
- GSMA warned over 1,000 operators to check networks and block unnecessary data transmissions.
- German operators say they fixed the leak, but networks in other countries may still be vulnerable.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Attackers can simply call a victim and obtain technical information, including the smartphone’s IMEI and OS version, even before the call is accepted. An investigation by BR (Bayerischer Rundfunk), one of Germany’s public-service broadcasters, uncovered a critical vulnerability in mobile networks, prompting GSMA to issue an alert to over 1,000 mobile network operators.
A simple incoming call exposes the recipient’s 15-digit IMEI number, as well as information about the smartphone model and operating system version. This data can be used to identify and track the owner and identify devices running vulnerable software.
According to research by BR, the leaks occur when a call is initiated between clients of 2 different mobile networks.
German journalists confirmed the bug after making 70 test calls across the networks of Telekom, Vodafone, and Telefonica (O2).
One of the calls was made to Roderich Kiesewetter, a former Bundeswehr general staff officer and Bundestag member. The politician confirmed that the leaked IMEI was correct and said the vulnerability opens a “gateway to foreign intelligence services.”
The vulnerability was also confirmed by Germany's Federal Office for the Protection of the Constitution, which believes that intelligence services are likely to abuse the leaked information.
The leak prompted the Global System for Mobile Communications Association (GSMA), which unites over 1,000 mobile operators, to issue an emergency warning to its member companies, urging them to check their networks and filter out unnecessary transmissions.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
BR cites the 9-page briefing saying that attackers could use the data to create device profiles, use phishing and social engineering in a more targeted manner, and track down known security vulnerabilities in devices and software.
“The research outlined by BR indicates that in certain instances; some VoLTE service configurations could inadvertently reveal device identifiers, but not individual user identities. While some device information is essential to provide VoLTE service to customers, we recommend certain data is removed as it could potentially be used to create linkages to specific device types used by individual users,” a GSMA spokesperson told Cybernews.
GSMA further explains that this issue relates to how operators configure their systems and comply with market regulations.
The GSMA has held industry briefing sessions making network operators, technology vendors, and other relevant stakeholders aware of this matter.
“We’ve also shared various communications, including a detailed briefing paper, providing further guidance,” the spokesperson said.
In response to the report, mobile network operators in Germany have already implemented technical changes that have plugged the leak. The BR’s research does not cover other countries, and mobile networks elsewhere may still remain vulnerable to similar flaws.
Heise.de reports that mobile operators in Germany failed to correctly implement GSMA’s industry standards.
Several technical standards (RFCs), published by the Internet Engineering Task Force (IETF), warn that the IMEI can be used to uniquely identify and track devices.
Check if your data has been leaked
In RFC 7254, GSMA members are warned that IMEI identifies the mobile device, and it “potentially could be used to identify and track users for the purposes of surveillance and call data mining if sent in the clear.”
RFC 7255 specifies that mobile providers and smartphone manufacturers must not include the IMEI in messages to prevent violations of users’ privacy.
Updated on August 27th [11:25 a.m. GMT] with comments from GSMA.