Header illustration for "IMSI catchers in Australia: what is actually known, and how to check your airspace lawfully"

"IMSI catchers in Australia: what is actually known, and how to check your airspace lawfully"

IMSI catchers in Australia: what is actually known, and how to check your airspace lawfully

An IMSI catcher — often called a stingray or cell-site simulator — is a radio device that impersonates a legitimate mobile base station, forcing nearby phones to reveal their identity and, on older networks, downgrade their encryption. Hackers Arise's article on scanning for cell towers in your vicinity covers how to map the towers around you with software-defined radio. That same skill set is the foundation for detecting fake towers — which is the part that matters for Australians who want to know what is happening in their own airspace.

What the Australian record actually shows

Official Australian disclosure has been thin. Federal Police responses to Freedom of Information requests about IMSI catcher use and holdings show the devices are in the hands of Australian agencies, with the detail withheld. In Victoria, successive parliamentary oversight work — including submissions to the Integrity and Oversight Committee's inquiry into IBAC's legislative framework — has examined how surveillance-device laws stretch across this class of equipment, and civil-society submissions have repeatedly pressed for judicial authorisation and public reporting on cell-site simulator use. Internationally, the picture is better documented: ECU reports and academic surveys catalogue routine government use in many countries.

The legal backdrop matters: the Telecommunications (Interception and Access) Act 1979 makes it an offence to intercept communications passing over Australia's telecommunications system without lawful authority. Possessing or operating an IMSI catcher yourself is not a lawful citizen activity in Australia — full stop. What lawful citizens can do is passive observation: receiving publicly broadcast signals is a different matter, and that distinction shapes everything below.

Detection is now a $30 problem

The Electronic Frontier Foundation's Rayhunter project turned an inexpensive portable hotspot into a cellular-spying detector, flagging anomalies such as forced downgrades from 4G to 2G and unusual authentication behaviour — the fingerprints an IMSI catcher leaves behind. The open-source code is on GitHub and is intended exactly for citizen auditing by activists, journalists and researchers.

For pure RF observation, an RTL-SDR dongle lets you see the real towers broadcasting around you. Our own RTL-SDR V4 receiver kit (A$55) and the bare R820T2 dongle (A$39) both receive the broadcast control channels that tower-mapping tools decode — and seeing your tower environment is step one of noticing something new in it. (We sell these; disclosed as our own stock.) Our SDR beginner's guide walks through the first-week setup.

Individual protective steps that need no hardware

The honest limits

Passive consumer tooling detects anomalies, not certainty. False positives happen, and a quiet adversary is invisible by design. The policy gap — Australian agencies confirmed to hold these devices, with little public reporting — is a matter for the oversight committees, not something citizens can fix with a dongle. What you can do is reduce what a fake tower learns from you, and add independent eyes to the spectrum.

This article is general information and not legal advice. Operating transmitting equipment in Australia is regulated by the ACMA under class-licensing rules; receive-only SDR monitoring of public signals is the scope discussed here.

Sources: Hackers Arise — Scanning for Cell Towers in Your Vicinity · EFF — Meet Rayhunter · TOLA Act 1979 · Right to Know — AFP FOI on IMSI catchers · Parliament of Victoria — IOC IBAC framework inquiry

Header image: Wikimedia Commons, "Mobile phone tower in Sherwood, Queensland, Australia, 2023" by Kgbo, CC BY-SA 4.0.

← All posts