A new NIST report found that attackers can use inexpensive, off-the-shelf hardware and software to impersonate legitimate cellular infrastructure and exploit vulnerabilities in 5G communications.
False or rogue base stations mimic legitimate carrier equipment and attempt to trick nearby devices into connecting to them. NIST tested six simulated attack scenarios and found that while 5G security improvements have reduced risks including privacy breaches and location tracking, devices remain susceptible to denial-of-service attacks that can degrade or disrupt cellular service.
NIST said the attacks can exploit vulnerabilities that occur before a device has authenticated with the network. The agency identified areas where standards and device-configurable protections could be improved and is accepting public comments on the findings through October 30.
ㅤJacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:
“Denial-of-service is the attack where a locked door is still a failure. An attacker does not need to get inside. They only need to stand in the doorway and stop everyone else from getting through. That is why these attacks are so hard to prevent, normal security and recovery rules can become the thing that keeps legitimate users out.
“That is what NIST found in its new 5G report. The false base station acted like a fake cell tower with a stronger signal, so phones chose it over the legitimate network. 5G authentication worked like the lock, the rogue tower could not complete a fake registration or access protected information. It could still reject or ignore the phone’s connection attempts, leaving the handset stuck retrying the wrong tower. In one test, that cycle lasted about 12 minutes.
“Monitoring is how operators see someone blocking the doorway. Repeated connection failures, one cell suddenly overpowering its neighbors, and many devices repeating the same failed process can distinguish an active attack from an ordinary outage. The lesson applies well beyond cellular networks. Encryption protects data after a connection exists. Monitoring tells defenders when the connection itself is being deliberately prevented.”
ㅤ
John Strand, Owner, Black Hills Information Security, Inc.:
“Cell phone infrastructure attacks have long fascinated me and a number of people at Black Hills Information Security. This isn’t mainstream security research. It’s not like EDR or Apache, where tons of organizations have access to the software and can test it. Setting up femtocells and intercepting cellular communications usually takes very specialized equipment, sometimes available only to government or law enforcement agencies.
“None of this is new. We’ve seen versions of these techniques in Mr. Robot and Silicon Valley, and a lot of them are actually viable. But testing can run into FCC restrictions, which means many security testing firms don’t touch this area. That leaves a real question. How thoroughly are these vulnerabilities being validated, and do we get a chance to address the full attack surface?
“These are the kinds of forbidden technologies I find fascinating from a security perspective. I relish any chance we get to test them.”
ㅤTesting technologies such as 5G are great as it really focuses attention on them. Addressing any vulnerabilities found in these technologies is a different matter entirely.
Related
This entry was posted on October 2, 2026 at 8:44 am and is filed under Commentary with tags NIST. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
NIST finds 5G devices remain vulnerable to fake base station attacks
A new NIST report found that attackers can use inexpensive, off-the-shelf hardware and software to impersonate legitimate cellular infrastructure and exploit vulnerabilities in 5G communications.
False or rogue base stations mimic legitimate carrier equipment and attempt to trick nearby devices into connecting to them. NIST tested six simulated attack scenarios and found that while 5G security improvements have reduced risks including privacy breaches and location tracking, devices remain susceptible to denial-of-service attacks that can degrade or disrupt cellular service.
NIST said the attacks can exploit vulnerabilities that occur before a device has authenticated with the network. The agency identified areas where standards and device-configurable protections could be improved and is accepting public comments on the findings through October 30.
ㅤJacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:
“Denial-of-service is the attack where a locked door is still a failure. An attacker does not need to get inside. They only need to stand in the doorway and stop everyone else from getting through. That is why these attacks are so hard to prevent, normal security and recovery rules can become the thing that keeps legitimate users out.
“That is what NIST found in its new 5G report. The false base station acted like a fake cell tower with a stronger signal, so phones chose it over the legitimate network. 5G authentication worked like the lock, the rogue tower could not complete a fake registration or access protected information. It could still reject or ignore the phone’s connection attempts, leaving the handset stuck retrying the wrong tower. In one test, that cycle lasted about 12 minutes.
“Monitoring is how operators see someone blocking the doorway. Repeated connection failures, one cell suddenly overpowering its neighbors, and many devices repeating the same failed process can distinguish an active attack from an ordinary outage. The lesson applies well beyond cellular networks. Encryption protects data after a connection exists. Monitoring tells defenders when the connection itself is being deliberately prevented.”
ㅤ
John Strand, Owner, Black Hills Information Security, Inc.:
“Cell phone infrastructure attacks have long fascinated me and a number of people at Black Hills Information Security. This isn’t mainstream security research. It’s not like EDR or Apache, where tons of organizations have access to the software and can test it. Setting up femtocells and intercepting cellular communications usually takes very specialized equipment, sometimes available only to government or law enforcement agencies.
“None of this is new. We’ve seen versions of these techniques in Mr. Robot and Silicon Valley, and a lot of them are actually viable. But testing can run into FCC restrictions, which means many security testing firms don’t touch this area. That leaves a real question. How thoroughly are these vulnerabilities being validated, and do we get a chance to address the full attack surface?
“These are the kinds of forbidden technologies I find fascinating from a security perspective. I relish any chance we get to test them.”
ㅤTesting technologies such as 5G are great as it really focuses attention on them. Addressing any vulnerabilities found in these technologies is a different matter entirely.
Share this:
Like this:
Related
This entry was posted on October 2, 2026 at 8:44 am and is filed under Commentary with tags NIST. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.