Overview
- An investigation by Bayerischer Rundfunk that ran more than 70 test calls found that some German mobile networks transmitted IMEI numbers and, in some cases, device model and OS version to callers before calls were answered.
- Telekom, Vodafone and Telefónica confirmed the findings to reporters and have said they have narrowed or stopped the data transmissions after being notified by BR and receiving technical guidance.
- The global industry body GSMA told its members to check and filter unnecessary call‑setup data and Germany’s Bundesnetzagentur and the domestic intelligence service BfV have classified the gap as security‑relevant.
- Security experts warn that exposed IMEIs and device details can be used to track handsets across networks, target devices with model‑specific malware or enable IMEI‑cloning attacks, though no public evidence yet shows widespread exploitation.
- The leak appears limited to certain VoLTE or service configurations and is likely an implementation or configuration error in standards handling, so regulators are pressing operators and vendors for technical clarification and audits.