Researchers from Ruhr-Universität Bochum in Germany recently discovered a new flaw in 4G/LTE mobile devices that could be exploited by hackers to impersonate the phone's owner. The team is expected to present the results of their research at the Network Distributed System Security Symposium in San Diego.
Specifically, hackers have the ability to compromise and manipulate user accounts, illegally upload documents with users’ identities, and even intercept encrypted internet traffic, due to a bug that exists in all devices using LTE service. However, it is extremely unlikely that an average user will fall victim to this particular “hacking” attack. This is due to the fact that it is a fairly complex hack and therefore difficult for anyone to implement.

According to security engineer Maya Levine, the hacker who will carry out the attack must have the necessary expertise and be in close proximity to the victim. She also points out that there is not much chance of an average user falling victim to this “hacking” attack, unlike a famous and prominent person, who may have a large amount of sensitive information. Even then, the chances of a hacker managing to extract useful information are minimal, given that most digital activities are encrypted.
Hackers can exploit this flaw in the following way: When an LTE mobile phone user moves, the nearest cell tower sends a signal to their device. The hacker would have to be in the same area as the potential victim to “fool” the cell tower and have the know-how to impersonate the original user and therefore send and receive LTE signals.
According to Mark Nunnikhoven, vice president of cloud research for cybersecurity firm Trend Micro, the hacker could also manipulate and direct a user's account by making international calls or using premium services offered by the victims' provider, such as subscribing to a TV package.
Hackers can also collect unencrypted information sent to the victim, which is however not a common occurrence except in activities like Facebook and email, while normal activities are almost unlikely to be affected by this.
However, the bug could create a problem for network providers and legal services, as they may face difficulty in checking whether a particular user did the activities suggested by their device.
According to Darren Shou, chief technology officer at NortonLifeLock, the carrier could say, “I received a request for this service and charged you,” and the user could respond, “It wasn’t me, it was an evil twin. What denial would there be?”
While the discovery of this particular bug shouldn't cause any LTE user to panic, it does remind consumers, providers, and technologists of the need to continually improve their security practices.
The LTE bug is not something the user can control, but there are other things they can control. For example, making sure passwords are changed, knowing what links people click, and freezing bank accounts when there is suspicious activity are all best practices for deterring hackers.
Finally, for technologists, the LTE hack revelation is yet another testament to how important encryption is, as hackers continue to find new ways to steal valuable and sensitive data.
