Researchers have developed 5G-Shark to lure phones onto rogue base stations, collect subscriber IDs, force network downgrades and trigger service disruptions.
Security researchers have developed a method that can pull nearby 5G phones onto a rogue base station without jamming the legitimate network or broadcasting malformed radio messages.
The method, named 5G-Shark, manipulates the standard cell-reselection process used by phones to choose between available mobile cells. Researchers used it to collect subscriber identifiers, track devices through temporary identifiers, force connections onto older network generations and trigger denial-of-service (DoS) attacks.
The research was published on 21 September 2026 by Oscar Lasierra, Gines Garcia-Aviles, Antonio Skarmeta and Xavier Costa-Pérez. The authors are affiliated with the i2CAT Foundation, University of Murcia, NEC Laboratories Europe and ICREA.
How 5G-Shark Attracts Nearby Phones
5G-Shark observes network information broadcast by the real operator and configures its rogue cell with matching operator identifiers, frequencies and reselection priorities.
A phone in an idle or inactive radio state automatically checks nearby cells. If the rogue cell advertises a higher priority and provides sufficient signal quality, the phone can select it as the preferred cell under normal 3GPP mobility rules.
The researchers found that their test devices spent almost 70% of the observed time in an eligible idle state. A one-minute broadcast window, averaging 58 seconds, was sufficient to attract the team’s test phones, complete the registration exchange and release them back to the commercial network.
According to the research paper, no action was required from the phone owner, and the devices displayed no security warning. The attack could still cause a short interruption in connectivity.
Extracting Identifiers and Forcing Downgrades
Once connected, the phone sends a registration request containing its temporary network identifier, known as a GUTI. The rogue base station claims that it cannot recognize that identifier and sends an identity request before mutual authentication has taken place.
What the rogue base station receives depends on whether the phone is connected through a Standalone or Non-Standalone 5G network. On Standalone networks, the permanent subscriber identity is normally transmitted as a concealed SUCI. Even when that protection worked, 5G-Shark could collect the phone’s temporary identifier and request its IMEI/IMEISV.
Non-Standalone 5G uses 5G radio access while retaining a 4G control plane. This provides weaker subscriber identity protection. In the researchers’ tests, devices connected through Non-Standalone configurations exposed their permanent IMSI in clear text across all three studied operators.
The rogue station can then send an unauthenticated registration-rejection message. Different rejection codes caused phones to fall back to LTE or UMTS, repeatedly attempt registration, lose data connectivity or enter other unwanted states.
Commercial Networks and Consumer Devices Tested
The study included the Galaxy Z Flip3, OnePlus 8, Oppo Find X5 Lite, iPhone 13 Pro, Google Pixel 8, Galaxy S23 and a Quectel RM520N-GL modem. The OnePlus 8 could not connect to the researchers’ laboratory 5G Standalone network and was excluded from later tests.
The researchers tested networks operated by three unnamed Tier-1 mobile carriers, identified in the paper only as Operator A, Operator B and Operator C. All three provided Non-Standalone coverage in the testing area, but only two had usable Standalone service.
In most Standalone tests, the phones concealed their permanent subscriber identities as expected. The exception was a Galaxy S23 using a SIM card issued in 2010 by Operator A, which sent its IMSI in clear text.

Temporary IDs Could Still Support Tracking
The team collected 3,742 temporary-identifier observations across Standalone and Non-Standalone networks. Operator C generated values with a comparatively random distribution, while Operator A and the Non-Standalone network of Operator B assigned identifiers in small, near-sequential steps.
According to the paper, these clustered values could allow consecutive registrations to be linked to the same device even when the subscriber’s permanent identity remains encrypted. Operator B’s Standalone network showed partial re-randomisation, but roughly half of consecutive re-registrations remained linkable.
Testing on a Galaxy S23 also uncovered implementation-specific failures. Two rejection codes sent the modem into a continuous registration loop that could drain the battery. Another caused the modem to become unresponsive until the researchers toggled airplane mode to restart its network connection.
Researchers Recommend Changes to Phones and Standards
The researchers propose that phones compare newly advertised cell priorities with previously observed network information and flag unexplained high-priority cells. They also recommend quarantining unauthenticated rejection messages that demand a downgrade and displaying a warning when a network requests an identity in clear text.
The work remains a preprint, and the operators were deliberately anonymised. All commercial-network experiments targeted devices and SIM cards owned by the research team. The paper does not document the interception of unrelated subscribers or state whether the operators and device manufacturers were notified before publication.
5G-Shark does not give an attacker access to calls, messages or files. The risk comes from what can happen before a phone authenticates the network. Attackers can collect identifiers, track devices and downgrade or interrupt mobile service without any action from the user.

