Can 4G and 5G Be Hacked? The Honest 2026 Answer
Can 4G and 5G be hacked? Honestly: yes — researchers have repeatedly shown that the world's mobile networks can be attacked, including the 2020 study this page originally covered, which found every tested 4G network could be knocked offline by a denial-of-service attack. But here is the answer that actually protects you: those headline attacks target carrier infrastructure, not your phone — and the mobile attack that genuinely empties ordinary people's bank accounts needs no radio wizardry at all. It is SIM swapping, and it works by sweet-talking your carrier's support line. This page ranks the real risks and gives you the twenty minutes of fixes that matter.
Jake had a customer walk in clutching a phone and a headline. She had read that 4G could be "easily breached," wanted her phone "checked for network hackers," and was seriously considering a $25 "radiation shield" sticker she had seen online. Jake checked the phone — fine, obviously — and then asked the two questions that mattered: Does your bank send login codes by text? Does your carrier account have a PIN? Yes and no, in that order. The thing she feared could not realistically touch her; the door that thieves actually walk through was standing open. Ten minutes later she left with an authenticator app, a carrier PIN, and her $25 still in her pocket.
Ethan: "The headlines are about counterfeiting the highway system — enormous, technical, aimed at the roads themselves. The crime that actually happens to people is someone walking up to the DMV counter, claiming to be you, and driving off with your license. Different crime, different lock. You bought alarm bells for the highway and left the counter unguarded."
What that scary research actually said
The 2020 study came from Positive Technologies, a security firm that audits real carrier networks. Its headline finding: 100% of the 4G networks they tested were susceptible to denial-of-service attacks through Diameter — the signaling protocol carriers use to talk to each other behind the scenes — and early 5G was not immune, because it ran on top of the same 4G core. The finding was real and worth reporting. What got lost in every headline, ours included, was the target: these are attacks on the plumbing between phone companies. They require access to the global carrier signaling network, and their victims are networks and, in targeted cases, tracked individuals — not the average person's WhatsApp history.
The deeper story is that mobile signaling was built on a handshake. The older SS7 protocol dates to an era when only a handful of national telecoms could connect, so the system simply trusted whoever showed up. Decades later, thousands of companies have access, and researchers have shown that trust can be abused to track phones or intercept texts. Diameter, 4G's replacement, inherited more of that trusting spirit than anyone wanted. This is the real lesson of the research: the weakness is in the eighties-era trust model between carriers, not in some flaw a stranger at a coffee shop can point at your phone.
| What the headline said | What it means for you |
|---|---|
| "100% of 4G networks can be breached" | Carriers can be attacked through inter-network plumbing; worst case for you is an outage |
| "5G is not immune" | Early 5G rode on the 4G core; finished standalone 5G fixes much of this |
| "Hackers can track any phone" | Signaling abuse enables targeted tracking — a real concern for specific individuals, not mass theft |
| What no headline said | The attack that empties ordinary accounts is SIM swapping — and you can block it this week |
DoS in plain English (keeping a promise from 2020)
The original version of this page promised to explain denial of service simply, so let's keep the tradition with a better analogy. A denial-of-service attack is a crowd of fake customers: one prankster (DoS) or a bused-in mob (DDoS — distributed denial of service) floods a shop with people who order nothing, until real customers cannot get through the door. Nothing is stolen; the harm is the closed door. Against a mobile network, that means an outage — calls failing, data dying — which matters enormously (emergency calls ride these networks) and is exactly why regulators and carriers took the research seriously. But note what a DoS is not: it is not surveillance, not theft, and not something aimed at you personally. If your data disappears for an afternoon, you were not "hacked" — you were standing in a crowded doorway.
Your actual mobile risk list, ranked honestly
| Threat | Who it really hits | Your defense |
|---|---|---|
| SIM swapping | Ordinary people with money or accounts — the #1 practical threat | Carrier PIN + move 2FA off SMS |
| SMS code interception (SS7/Diameter abuse) | High-value targets, but it has hit bank customers | Same fix: stop using SMS codes for anything important |
| Fake base stations / IMSI catchers ("stingrays") | Targeted surveillance — protests, espionage, specific individuals | Disable 2G; modern 5G hides your identifier |
| Network DoS (the 2020 headline) | Carriers — you experience it as an outage | Nothing to do; Wi-Fi calling is your workaround |
| "5G radiation" | Nobody — see below | Keep your $25; skip the sticker |
Notice the pattern in the defense column: the two threats that reach ordinary people are both defeated by the same two moves. That is why the fix section below is short.
SIM swapping: the attack that actually empties accounts
Here is the whole crime, no radio required. A thief gathers a little about you — name, number, a few facts from breaches or social media — calls your carrier pretending to be you, and claims a lost phone. If the support agent believes them, your number moves to the thief's SIM. Your phone goes dead; theirs starts receiving your calls and, crucially, your SMS login codes. Within the hour they are resetting your email and draining anything protected by "we'll text you a code." Losses from documented cases run from thousands to life-changing amounts, and the victims did nothing wrong except trust text messages as a lock.
If your phone ever drops to "No service" for no reason — especially with password-reset emails arriving — treat it as a fire alarm and move in this order:
- Call your carrier from any other phone and say the words "I think my SIM has been swapped" — they have a procedure, and minutes matter.
- Lock down your email from a computer: change the password, sign out all sessions. Email is the master key the thief wants next.
- Warn your bank and freeze anything the number can reset.
- Once the number is recovered, set the carrier PIN you were missing and move those accounts off SMS codes — the same attacker often tries twice.
Fake towers and stingrays: real, but not hunting you
IMSI catchers — fake cell towers, nicknamed stingrays — are genuine surveillance devices: your phone connects to the strongest tower it sees, and a fake one can log who is nearby or push phones down to ancient 2G, where encryption is weak enough to break. Two honest framings. First, this is targeted equipment — used around protests, investigations, and espionage — not something scanning your grocery run. Second, the defense finally exists for everyone: modern Android has a switch to refuse 2G connections entirely (Settings → Network & internet → SIMs → turn off Allow 2G — wording varies slightly by phone), and 5G's newer design encrypts the very identifier stingrays were built to harvest. Flip the toggle once and forget about it.
What 5G actually fixed (credit where due)
The 2020 research caught 5G at its weakest moment — "non-standalone" 5G, which was a 5G radio bolted onto the old 4G core, inheriting its problems. The finished, standalone version of 5G genuinely improved the foundations: your permanent subscriber identity is now encrypted before it ever crosses the air (the feature is called SUCI — concealing exactly what IMSI catchers harvested), inter-carrier signaling got a modern security-aware redesign, and the trust-everyone model is being retired plumbing piece by plumbing piece. None of this makes networks unhackable — carriers still run old equipment, and 2G/3G/4G will linger for years — but the direction of travel is real: each generation has made the network-side attacks harder, which is precisely why criminals moved to the support line instead.
About those dead birds (a correction we owe)
The 2020 version of this page mentioned, in passing, reports of birds dying from 5G radiation. That story — hundreds of starlings found dead in a park in The Hague — was a genuine viral sensation, and it was false: the deaths were never linked to any 5G test, no test was even running at the time, and the claim was debunked by every fact-checker who touched it. We repeated a myth, briefly, and it deserves a plain correction rather than a quiet deletion. For the underlying question: 5G uses non-ionizing radio waves, the same physical family as FM radio and Wi-Fi, at power levels regulated far below established safety limits — it does not have a mechanism for killing birds or cooking brains. The $25 sticker Jake's customer almost bought protects against exactly nothing, which is, in fairness, exactly what it does.
The 20-minute protection plan
- Call your carrier and set an account PIN / port-out lock (5 minutes). This single step defeats most SIM-swap attempts — the thief at the support line no longer has your password.
- Move your important accounts off SMS codes (10 minutes for the big three: email, bank, main social). Use an authenticator app or, better, passkeys where offered. Email first — it is the master key to everything else.
- Turn off 2G on Android: Settings → Network & internet → SIMs → Allow 2G off (1 minute). iPhones manage this differently; keeping iOS updated is the equivalent move.
- Know the SIM-swap alarm: your phone showing "No service" for no reason, especially alongside password-reset emails. React by calling the carrier from any other phone, immediately.
- Keep the phone updated — baseband and OS patches close the radio-layer bugs researchers keep finding, quietly, before they matter to you.
That is the honest whole of it. No sticker, no app subscription, no antenna tinfoil — two phone calls' worth of effort aimed at the door criminals actually use. (For the adjacent privacy layers — what your phone leaks through photos and browsers rather than radios — our WhatsApp photo metadata answer and the browser fingerprinting guide pick up where this page stops.)
FAQ — 4G/5G security, SIM swaps, and the rest
Can someone hack my phone through 4G or 5G?
Not in the way headlines imply. Network-level attacks need carrier-grade access and target infrastructure or specific individuals. The realistic path to your accounts is SIM swapping and SMS-code theft — both fixable by you.
What did the "100% of 4G networks" research actually find?
Positive Technologies tested real carrier networks in 2020 and found all of them could be hit with denial-of-service through the Diameter signaling protocol, with early 5G inheriting the risk. Target: carrier plumbing, not individual phones.
What is a DoS attack in simple terms?
A crowd of fake customers flooding a shop until real ones cannot get in. One attacker is DoS; a coordinated mob of machines is DDoS. The harm is the outage itself — nothing is stolen.
What is SIM swapping?
A thief convinces your carrier to move your number to their SIM, then receives your calls and SMS login codes. Your phone goes dead; your accounts fall. The defense is a carrier PIN and getting codes out of SMS.
How do I know if I've been SIM swapped?
Your phone suddenly shows no service where it normally works, often alongside password-reset emails you did not request. Call your carrier from another phone immediately — minutes matter.
Is SMS two-factor authentication safe?
Better than nothing, worse than everything else. SIM swaps and signaling attacks both intercept SMS codes; authenticator apps and passkeys are immune to both. Move email and banking first.
What is an IMSI catcher or stingray?
A fake cell tower that logs nearby phones' identifiers or downgrades them to weakly-encrypted 2G. Real, targeted surveillance gear — not mass consumer crime. Disabling 2G blunts its favorite trick.
How do I turn off 2G on my phone?
Android: Settings → Network & internet → SIMs → toggle Allow 2G off (wording varies by maker). iPhone has no user toggle; staying updated is the equivalent hygiene.
Is 5G more secure than 4G?
Standalone 5G genuinely is: it encrypts your subscriber identity over the air (SUCI), modernizes inter-carrier signaling, and retires much of the old blind-trust model. Networks still run legacy gear, so the gains arrive gradually.
What is SS7 and why does it keep coming up?
The 1980s signaling protocol that lets carriers route calls and texts to each other — designed when every participant was trusted. Abused, it can track phones and intercept SMS, which is a core reason SMS codes are the weak link.
Did 5G actually kill birds?
No. The viral Hague starling story was debunked — no 5G test was running when the birds died. Our 2020 write-up repeated the claim in passing; we were wrong to, and this page corrects it.
Is 5G radiation dangerous?
5G is non-ionizing radio, the same physical family as FM and Wi-Fi, operating far below regulated exposure limits. It has no mechanism for the harms attributed to it, and "shield" stickers protect against nothing.
Can attackers read my WhatsApp or Signal through the network?
End-to-end encrypted apps encrypt above the network layer, so even an attacker inside carrier plumbing sees ciphertext. Network position does not break the encryption — another reason the crime moved to account takeover instead.
Should I use Wi-Fi calling?
It is a convenience and outage workaround, not a security feature — fine to use, and handy the day a network DoS or tower failure hits your area.
Do VPNs protect against these attacks?
A VPN encrypts your internet traffic; it does nothing about SIM swaps, SMS interception, or fake towers, which live below or beside it. Useful tool, wrong lock for this door.
What single step matters most?
The carrier account PIN, with moving email off SMS codes a close second. Together they defuse the only mobile-network threats that realistically visit ordinary people.
Where to go next
- Browser fingerprinting: what it is and how to reduce it
The tracking that follows you with no SIM card involved at all. - Does WhatsApp share your photo metadata?
What actually leaks when you hit send — measured, not guessed. - Kernel-level Tor isolation with oniux on Kali
For readers who came here from the security-research side of the fence. - Verify any download's checksum from Windows
The everyday habit that blocks tampered files — no carrier required.
Revision note. Originally published March 27, 2020, reporting the Positive Technologies research the week it landed — and one line back then repeated the 5G-killed-birds story, which turned out to be a hoax; that correction is made openly above. Rewritten August 18, 2026: the research is now the doorway into what actually threatens your phone number and money — SIM swaps, SMS codes, fake towers — and the twenty minutes of fixes that close those doors. If mobile-security headlines have ever left you scared of exactly the wrong thing, that is what they are built to do; you have the ranked list now. Spotted something wrong or something missing? Tell me through the contact page and I will fix it. Stay safe out there.