August 28, 2026, 9:34 am | Read time: 3 minutes
When you call someone on a cellphone, you usually don’t notice the technical processes happening in the background during the connection setup. It was precisely during this phase that a security issue apparently arose in German mobile networks. In certain cases, sensitive data from the called smartphone could become visible to the caller.
This is according to research by Bayerischer Rundfunk (BR). The reporters conducted more than 70 test calls. The information visible depended on the respective mobile network. In the networks of Telekom and Telefónica, the company behind O2, the 15-digit IMEI of a smartphone could be read multiple times. This is the unique identification number of a cellphone.
Different data were visible depending on the network
In addition to the IMEI, calls over Telekom and Vodafone could sometimes reveal further information. This included the smartphone model and the installed version of the operating system. However, the issue did not occur with every call. Apparently, certain technical conditions had to be met.
How long the security gap has existed is not yet known. According to the research, the information could become visible under certain conditions during the connection setup.
5G Frequencies Must Be Reauctioned: Impact on Users
Which Cell Phone Area Code Belongs to Which Provider
Authorities consider the vulnerability to be security-relevant
The affected data is considered sensitive. From the smartphone model and the software version used, it can be determined, for example, whether important security updates are missing. The Federal Office for the Protection of the Constitution therefore classifies the vulnerability as “security-relevant.”
Also of interest: Telekom invests in Polish fiber-optic network
As the research shows, during a test call, the reporters were able to read the IMEI of the smartphone of CDU Bundestag member Roderich Kiesewetter. Using this identifier, they then determined the exact device model. Kiesewetter later described the vulnerability as a possible “gateway for foreign intelligence services” and expressed concern about potential consequences for his environment.
Providers and mobile network association responded to the findings
After BR informed the mobile network providers of the results at the end of June, they initiated measures. Telefónica stated that it had already implemented countermeasures. Vodafone restricted the amount of information transmitted during connection setup. Telekom also announced adjustments to its network.
The research also triggered international reactions. The mobile network association GSMA informed more than 1,000 member companies about the incident and recommended a review of their networks.
The Federal Network Agency also attaches great importance to the affected information. In their assessment, the IMEI is among the particularly sensitive customer data. This identification number is not needed for establishing a connection on the receiving side. Therefore, according to the agency, it should not leave the mobile network.