Skip to main content

Meet the $250 Verizon device that lets hackers take over your phone

If you’ve never heard of a femtocell, now would be a good time to learn.

At the Black Hat hacker conference in Las Vegas, NV, on Wednesday, a pair of security researchers detailed their ability to use a Verizon signal-boosting device, a $250 consumer unit called a femtocell, to secretly intercept voice calls, data, and SMS text messages of any handset that connects to the device.

Recommended Videos

A femtocell is, basically, a miniature cell phone tower that anyone can use to boost their wireless signal in their home. Most of the major U.S. wireless carriers sell femtocells, as do other retailers, and they can typically be purchased for $150 to $250.

For a cell phone or tablet to connect to a femtocell, it must be within 15 feet of the device, and remain within 40 feet to maintain a connection, explains Doug DePerry of security firm iSEC Partners and one of the researchers who discovered the vulnerability. But when your device does connect to the femtocell, you will not know it.

femtocell-talk
Image used with permission by copyright holder

“Your phone will associate to a femtocell without your knowledge,” says DePerry. “This is not like joining a Wi-Fi network. You don’t have a choice.”

The iSEC Partners team, led by DePerry and fellow researchers Tom Ritter and Andrew Rahimi, successfully tapped into the root of two femtocells sold by Verizon and manufactured by Samsung, which allowed them to intercept SMS messages in real-time, and even record voice calls.

During a demonstration of their exploit, Ritter and DePerry showed how they could begin recording audio from a cell phone even before the call began. And the recording included both sides of the conversation. The duo also demonstrated how it could trick Apple’s iMessage – which encrypts texts sent over its network using SSL, rendering them unreadable to snoopers, including the NSA – into defaulting to SMS, allowing the femtocell to intercept the messages.

“If you block the SSL connection back home to Apple, iMessages fails over to SMS, which is plain text,” explains Ritter. “And that we can see just fine.”

In their final demonstration, DePerry and Ritter showed off their ability to “clone” a cell phone that runs on a CDMA network (like Verizon’s) by remotely collecting its device ID number through the femtocell, in spite of added security measures to prevent against cloning of CDMA phones. Once a phone is cloned to another handset – meaning the network thinks both phones are the same device, assigned to a single account – a hacker can make expensive phone calls (i.e. 1-900 numbers), or use excessive amounts of data, and the charges are all attributed to the cloning victim.

Because both the cloned phone and its evil twin device must be connected to a femtocell to work – “any femtocell,” says DePerry, not just one that’s been hacked – the cloning dangers are limited. However, when it comes to intercepting calls and text messages, the eavesdropping potential is significant – especially if someone with a hacked femtocell sets up camp in a heavily trafficked area, like Times Square, to listen in on passersby.

Fortunately for Verizon customers, the company has since issued a patch to all affected femtocells. Sprint currently offers a femtocell that is similar to the vulnerable models from Verizon, but the company has said it plans to discontinue the device. And while AT&T also offers femtocells, it requires an extra level of authentication that makes much of the iSEC Partner’s findings irrelevant. Still, says Ritter, the femtocell vulnerability is a major problem.

“It’d be easy to think this is all about Verizon,” says Ritter. “But this really about everybody. Remember, there are 30 carriers worldwide who have femtocells, and three of the four U.S. carriers.”

Ritter suggests that all carriers that offer femtocells require owners to provide a list of approved devices that are allowed to connect to their femtocell. And also prevent customers’ cell phones from connecting to any unauthorized femtocell.

Andrew Couts
Former Digital Trends Contributor
Features Editor for Digital Trends, Andrew Couts covers a wide swath of consumer technology topics, with particular focus on…
Android phones get new security feature that iPhone owners already have
The Google Pixel 9a on a table showing the screen.

Google is taking a page out of Apple's playbook by launching a new security feature that makes Android phones automatically restart after a few days of inactivity.

The new auto-restart feature (or auto-reboot, if you want to call it that) was patched into the latest Google Play services update, which was released on Monday. The release notes say that the update forces your Google Pixel 9, Samsung Galaxy S25, or other Android phone to restart itself "if locked for [three] consecutive days," which means you need to enter your PIN code if you want to unlock it after not using it for that period of time. It resembles the Inactivity Reboot feature on iOS 18.1, only iPhones would restart themselves after four days.

Read more
The $999 iPad Pro M4 is discounted by $100 at select stores today
Writing in Arabic script using the ESR Geo Digital Pencil on the M4 iPad Pro.

If you want one of the best tablets, it is only natural to gravitate towards the iPad Pro line. It is the top of the iPad line, and we compare the iPad Pro M4 and Microsoft Surface Pro side by side. These are intense products. And right now you can get the 11-inch version of the iPad Pro M4 for just $899. That's $100 off its usual $999 price. Tap the appropriate button below to jump to this deal at the retailer of your choice or keep reading to see why we like it so much.

Why you should buy the iPad Pro M4
The basic stat line of the iPad Pro M4 is quite impressive. Its 11-inch OLED screen has a 2420 x 1668 pixel resolution that refreshes at 120Hz, and in our iPad Pro M4 review we noted that it has a noticeable "boost in saturation, contrast, and viewing angle" compared to previous iPads. The speakers are fantastic too, producing "enough thump that you can clearly feel the sonic vibrations if you're holding the slate in your hands." The M4 iPad Pro has 8GB of RAM and (this version) has 256GB of memory storage.

Read more
This Samsung Galaxy S25 Ultra deal from Mint Mobile saves you $380
The screen on the Samsung Galaxy S25 Ultra.

If you've been waiting for phone deals on the Samsung Galaxy S25 Ultra, here's your chance at a $200 discount. You can get its 256GB model for only $1,100 instead of $1,300, but there's a catch -- you have to sign up to a Mint Mobile subscription. That's not a negative though, as you can get the service's Unlimited plan for only $180 for 12 months instead of $360. All in all, it's the 256GB Samsung Galaxy Ultra with a 12-month Unlimited plan from Mint Mobile for $1,280 instead of $1,660, for total savings of $380. This is a limited-time offer though, so you have to act fast if you want to take advantage of it.

Why you should buy the Samsung Galaxy S25 Ultra

Read more