Fake Base Stations (IMSI Catcher) Threat
IMSI catchers work as fake base stations and force your phone to connect to them. This way, they can listen to your calls and messages and determine your location.
These devices can downgrade your phone to 2G/3G networks and weaken encryption. Disabling 2G connection on modern smartphones provides important protection.
Security-focused operating systems offer additional layers of protection against fake base stations. Also, using messaging apps with secure encryption (E2EE) increases your data security.
IMSI catchers work by intercepting the IMSI number, your phone's identity card. When your device connects to the fake station, your IMSI number is recorded and tracking becomes possible. This method can be applied silently, especially in crowded areas (airports, protests, shopping malls).
SS7 (Signaling System 7) vulnerabilities are weaknesses in the protocol that telephone providers use to communicate with each other. Through these vulnerabilities, attackers can read your SMS, redirect your calls, and learn your location — even from the other side of the world. Unlike IMSI catchers, SS7 attacks do not require physical proximity.
Signal Intelligence (SIGINT) is a broad surveillance method used by states and large organizations. These systems collect base station data and can build movement profiles of specific individuals. Therefore, the privacy of your location data depends not only on your phone settings but also on the infrastructure level.
One of the most effective defense methods is to completely disable the 2G network. 2G networks do not support modern encryption standards and are the most vulnerable layer against IMSI catcher attacks. On Android 12 and above, this setting is available under 'Settings > Network & Internet > SIMs > Turn off 2G'.
QMOBILE, with its privacy-focused approach headquartered in BASEL, restricts 2G connectivity by default on its Pixel-based devices. This way, users are protected against IMSI catcher attacks at both hardware and software levels. QMOBILE devices remain resistant to SS7 and similar vulnerabilities by receiving timely security updates.
As additional protection, conduct sensitive conversations through apps that offer secure encryption (E2EE). Signal and similar apps encrypt voice calls end-to-end, so IMSI catchers or SS7 attacks cannot listen to your calls. Prefer app-based (TOTP) methods over SMS-based two-factor authentication.