ctipilot.ch
← Back to the live brief
HIGHNATOB2research

German mobile carriers leaked callees' IMEI, device model and OS version to callers during call setup — GSMA confirmed the flaw and warned its 1,000+ member operators worldwide

first published 2026-08-29 04:09 UTCrun 2026-08-29T0409Z-intel2 sourcesmulti-source

Bayerischer Rundfunk (BR) published an investigation, corroborated the same window by heise, that found Germany's three mobile network operators — Deutsche Telekom, Vodafone and Telefónica/O2 — forwarded device-identifying data to the calling party during call setup, before the callee ever answered (BR24, 2026-08-27). Across more than 70 test calls, Telekom's and O2's networks in several cases forwarded the callee's full 15-digit IMEI — confirmed by Wireshark packet captures of the call-setup traffic — and Telekom's and Vodafone's networks separately exposed the callee's smartphone model and operating-system version, specific enough to reveal whether a target device was missing a given security update (BR24, 2026-08-27; heise Security, 2026-08-27). The leak occurred only in certain unspecified network/device constellations rather than on every call, and BR could not establish since when the gap existed; BR notified the three operators in late June 2026, after which Vodafone said it had "further narrowed" transmitted call data, Telekom said in mid-August it would adjust its network, and Telefónica said it had implemented technical measures — all three state they otherwise meet international industry standards (BR24, 2026-08-27).

The GSMA confirmed the flaw on inquiry and, per a nine-page briefing BR obtained, warned its 1,000+ member operators worldwide to review their networks and filter unnecessarily transmitted call-setup information — an implicit acknowledgment that the same signaling gap plausibly extends beyond Germany's three carriers to any GSMA member network (BR24, 2026-08-27). Germany's domestic security service (BfV) assessed the flaw as security-relevant, stating that given cyberattacks against mobile devices by state-affiliated actors already on record, it is "near-certain" that foreign intelligence services use such information for their own purposes (BR24, 2026-08-27). A scenario in the Bundeswehr's own magazine "Y" illustrates the mechanism: correlating a soldier's IMEI between a domestic posting and a later deployment abroad — its example is a training ground in Lithuania — could put that individual "in a spy's focus"; the Federal Ministry of Defense separately told BR that intelligence services can use such device identifiers to build movement profiles and identify individuals (BR24, 2026-08-27). HPI mobile-security researcher Jiska Classen called it a serious flaw enabling mass profile-building and said it shows how poorly such carrier systems are tested (BR24, 2026-08-27). SRLabs founder Karsten Nohl, asked by heise to elaborate, added that device-model exposure also enables more targeted attacks and IMEI cloning, while stating he sees no dramatic security impact in the finding on its own (heise Security, 2026-08-27). BR notes the finding parallels an April-2026 discovery of a similar flaw in Norwegian networks by Mnemonic researcher Harrison Sand, who shared his methodology with BR — suggesting the underlying signaling gap is not specific to any one carrier or country (BR24, 2026-08-27).

Neither BR nor heise names the precise signaling layer — an SS7 interconnect field, a Diameter/IMS parameter, or a VoLTE SIP header — carrying the leaked data; this is recorded as an unresolved open question, not an invented mechanism. Detection concept for a telco SOC or network-security team: audit outbound call-setup signaling at the interconnect boundary for device-identifying parameters (IMEI, UE capability/OS-version fields) reaching the calling party or a foreign network, consistent with GSMA and IETF guidance (RFC 7254, RFC 7255) that such fields be anonymized or stripped before leaving the home network (heise Security, 2026-08-27). Hardening lever: filter or strip unnecessary device-identifying call-setup parameters at the network edge, per the GSMA's own briefing recommendation.

In the networks of Telekom and Telefónica (O2), IMEI numbers reached the caller in several cases.

The Federal Office for the Protection of the Constitution (BfV) assesses the security vulnerability discovered by BR research, on inquiry, as "security-relevant".

After BR approached the association with questions, it warned its more than 1,000 member companies, which also include the German network operators.

Bayerischer Rundfunk (BR24) 2026-08-27

ATT&CK mapping

1 technique mapped from the cited reporting · MITRE ATT&CK v19.2

Reconnaissance TA0043
T1592.004Gather Victim Host Information: Client Configurations

Adversaries may gather information about the victim's client configurations that can be used during targeting. Information about client configurations may include a variety of details and settings, including operating system/version, virtualization, architecture (ex: 32 or 64 bit), language, and/or time zone.

overlap matrix · ATT&CK page ↗

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.