IMEI (International Mobile Equipment Identity)

The International Mobile Equipment Identity is a 15-digit number that uniquely identifies a mobile device, independent of the SIM. It encodes the Type Allocation Code (manufacturer and model) and a serial number, and is checked against the EIR to block stolen, cloned, or non-type-approved equipment. Because the IMEI is transmitted to the network during attach, it has been used in tracking attacks and law-enforcement device identification; tamper-resistant IMEI storage and operator EIR hygiene are standard countermeasures.

Categories: Radio Access NetworkIdentity and SubscriberThreats and Attacks

IMEI in context

The radio access network is where mobile devices attach to the operator's infrastructure. Attacks in this layer include IMSI catching, rogue base stations and downgrade attacks; defenses rest on mutual authentication, integrity-protected signaling and Open RAN supply-chain hygiene.

Subscriber identifiers (IMSI, SUPI, MSISDN, IMEI) anchor authentication, charging and lawful interception. Any protocol that leaks a permanent identifier is treated as a privacy defect, which is why 5G introduced SUCI concealment on the air interface.

To place IMEI in the wider telecom-security picture, review Cell Phone (Mobile Phone), CPE, Firmware, IRSF, Malware and Paging Attacks — each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.