Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Low-Cost Fake 5G Base Station Can Track Subscribers via Predictable Temporary IDs

Researchers built 5G‑Shark, a cheap fake base station that lures phones onto a rogue cell and captures temporary GUTI identifiers. Tests of three operators showed predictable ID rotation, allowing linkage of 84‑96 % of re‑registrations. The finding highlights a privacy control gap that continuous control‑assurance programs must monitor.

LiveThreat™ Intelligence · 📅 September 22, 2026· 📰 helpnetsecurity.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
4 recommended
📰
Source
helpnetsecurity.com

Low‑Cost Fake 5G Base Station Can Track Subscribers via Predictable Temporary IDs

What Happened – Researchers from i2CAT, the University of Murcia and NEC Labs built a cheap tool called 5G‑Shark that masquerades as a legitimate 5G base station. By exploiting unauthenticated cell‑reselection, the device lures a target phone onto a rogue cell, captures the temporary subscriber identifier (GUTI), and shows that many commercial networks rotate these IDs in a near‑sequential, predictable pattern. The result is the ability to link 84‑96 % of a subscriber’s successive registrations and effectively track the user without ever exposing the permanent IMSI.

Why It Matters for Trust & Control Assurance

  • Continuous control‑assurance programs must verify that privacy‑related controls (e.g., randomization of temporary identifiers) are operating as intended, otherwise audit evidence will show a gap.
  • Evidence of predictable GUTI rotation is a concrete control‑mapping finding that can be collected, monitored, and reported to demonstrate due diligence.
  • Detecting rogue base‑station activity and documenting mitigation steps provides a defensible audit trail for privacy and telecom‑specific regulations.

Who Is Affected – Mobile network operators, telecom infrastructure providers, and all 5G subscribers who rely on the network’s privacy guarantees.

Recommended Actions

  • Conduct a systematic audit of GUTI rotation randomness across all cells.
  • Update network configuration to enforce cryptographically random temporary ID assignment per 3GPP specifications.
  • Deploy monitoring for unauthenticated rogue base stations (e.g., SDR‑based detection).
  • Record control evidence in a Trust Center or similar repository to support audit readiness. Source: https://www.helpnetsecurity.com/2026/09/22/5g-subscriber-tracking-research/

Technical Notes – The attack leverages the cell reselection procedure, which accepts broadcast messages without authentication. 5G‑Shark runs on open‑source software and inexpensive SDR hardware; no jamming or malformed packets are required. The captured identifier is the GUTI, which should be randomly reassigned but was observed moving only ~0.11 % of the identifier space in most tested networks. Source: https://www.helpnetsecurity.com/2026/09/22/5g-subscriber-tracking-research/

📰 Original Source
https://www.helpnetsecurity.com/2026/09/22/5g-subscriber-tracking-research/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →