September 7, 2026

The Gap in Your Network Map: Cellular Device Detection

LTE and 5G devices can operate outside enterprise Ethernet and Wi-Fi infrastructure, creating a visibility gap beyond the scope of many conventional network security tools.

Enterprise security teams maintain detailed inventories of the devices connected to their networks. However, network visibility does not necessarily reveal every device operating inside a facility, particularly with LTE and 5G. 

A cellular device can use carrier infrastructure without relying on corporate Ethernet or Wi-Fi, creating the potential for a parallel communications path outside many conventional network security controls. Smartphones provide the most familiar example, but cellular connectivity extends far beyond phones. Routers, hotspots, gateways, industrial systems, IoT devices, security equipment, building controls, or any device with an embedded cellular module can use cellular connections. That means an organization’s network map can be completely accurate and still be incomplete.

The objective is not to treat every cellular device as a threat. Security teams need to distinguish authorized cellular activity from devices that violate policy, create connectivity outside approved architecture, or appear where cellular connectivity should not exist.

What Is Cellular Device Detection?

Cellular device detection identifies LTE and 5G devices operating within a monitored physical environment, including devices that may not connect to an organization’s wired or Wi-Fi networks. This capability addresses a visibility gap in conventional network-centric security. A firewall can inspect traffic that crosses the network infrastructure it protects. Network access control can identify devices requesting access to managed infrastructure. Mobile device management can enforce policies on enrolled devices. Wi-Fi wireless intrusion detection systems (WIDS) can identify Wi-Fi activity.

These technologies provide critical security capabilities, but they do not provide a complete inventory of cellular devices even if those devices operate inside a facility. A cellular device can use carrier infrastructure independently of the enterprise network, creating a potential communications path that conventional network security controls may not observe.

The Cellular Visibility Gap

A 2025 investigation into the financially motivated threat group UNC2891 provides a real-world example of this visibility gap. According to Group-IB, the attackers physically connected a Raspberry Pi to the same network switch as a bank ATM and equipped it with a 4G modem. The cellular connection gave the attackers remote access via mobile data, while the Raspberry Pi operated within the bank’s internal network.

The attackers used the Raspberry Pi and TINYSHELL backdoor to establish external command-and-control connectivity. Because the device used its cellular connection for remote access, Group-IB reported that the setup bypassed the bank’s perimeter firewalls and traditional network defenses. From that foothold, UNC2891 moved laterally within the environment, ultimately targeting the ATM switching infrastructure to facilitate fraudulent cash withdrawals. Investigators disrupted the attack before the group achieved that objective. 

The incident illustrates why network visibility alone can leave a gap. A small cellular-enabled device can sit inside trusted infrastructure while using an independent communications path outside conventional network controls. Firewalls, network access controls, and other network security technologies remain essential, but they address different parts of the security problem.

For security teams, the broader lesson extends beyond ATMs and banking. Cellular-enabled gateways, hotspots, embedded devices, and other equipment can introduce LTE or 5G connectivity into sensitive environments without relying on enterprise-managed internet access. Identifying unexpected cellular activity provides security teams with another layer of visibility into devices and communication capabilities that may not appear on the conventional network map.

Authorized, Unauthorized, and Unknown Cellular Devices

Security teams can divide cellular devices into three broad categories:

  • Authorized Devices:
    Organizations routinely authorize smartphones, routers, gateways, sensors, and other cellular equipment for legitimate business purposes. Security teams know these devices exist and can establish policies governing where and how personnel use them. Visibility still matters. An authorized device may appear in a location where policy prohibits cellular communications or operate at a time or place inconsistent with its approved use. The security question is not whether cellular technology itself presents a threat. The question is whether observed cellular activity aligns with organizational policy.
  • Unauthorized Devices:
    A second category includes recognizable devices that policy prohibits in a particular location or environment. An employee might carry a personal phone into a restricted area. A contractor could bring a cellular hotspot onto a site. A technician might introduce an LTE or 5G gateway to provide remote connectivity without following the organization’s security approval process. The device may have an innocent explanation, but its cellular capability can provide connectivity outside established network controls. For organizations that restrict external connectivity in sensitive environments, identifying these policy violations matters regardless of the user’s intent.
  • Unknown Devices:
    Unknown cellular devices present the most challenging visibility problem. These devices might include undocumented equipment, forgotten infrastructure, contractor-installed hardware, unauthorized hotspots, embedded cellular modules, or deliberately concealed systems. Whatever their origin, security teams cannot evaluate their authorization or risk until they discover them. The principle is straightforward: Organizations cannot apply policy to cellular devices they cannot see.

Cellular Creates a Parallel Communications Path

Enterprises depend on LTE and 5G for legitimate operations every day. Cellular connectivity itself does not make a device suspicious or malicious. Risk increases when cellular capability creates the potential for an unknown, unmanaged, or unauthorized communications path.

Organizations invest significant resources in controlling how information enters and leaves their environments. Firewalls, network segmentation, proxies, access controls, data loss prevention technologies, and security monitoring systems enforce policies across enterprise-managed infrastructure. Cellular connectivity can operate independently of that infrastructure.

For example, a cellular gateway attached to equipment in an operational technology environment could provide external connectivity without relying on the organization’s conventional network perimeter. A cellular-enabled device inside a sensitive facility could retain the capability to communicate externally even when administrators tightly restrict Ethernet and Wi-Fi access. A hotspot could provide another device with an alternative internet connection outside approved architecture.

In each case, the security problem starts with visibility. Security teams need to discover the cellular device before they can determine whether it is authorized, investigate its presence, locate it, or enforce organizational policy.

Why Can’t Traditional Security Tools Provide Complete Cellular Visibility?

Traditional enterprise security tools cannot provide complete cellular visibility because they monitor network traffic, managed devices, network access, or Wi-Fi activity rather than all LTE and 5G devices operating within the physical environment.

  • Firewalls monitor traffic that traverses the network infrastructure they protect. A cellular connection that independently reaches a carrier network may never cross that inspection point.
  • Network access control governs devices attempting to connect to managed network infrastructure. A cellular-only device may never request that access.
  • Mobile device management provides valuable security controls for smartphones, tablets, and other enrolled devices. It does not provide comprehensive discovery of unmanaged, contractor-owned, unauthorized, embedded, or unknown cellular devices operating inside a facility.
  • Wi-Fi WIDS monitors Wi-Fi activity. Cellular communications use different wireless technologies and frequencies, requiring different detection capabilities.

Cellular device detection complements these technologies by addressing a separate visibility requirement: identifying LTE and 5G devices that may never interact with enterprise-managed network infrastructure.

5G Security and Cellular Device Visibility Are Different Problems

The expansion of 5G makes this distinction increasingly important. In March 2026, the National Institute of Standards and Technology finalized its Applying 5G Cybersecurity and Privacy Capabilities white paper series. NIST notes that 5G standards focus security capabilities on interoperable interfaces, leaving organizations to address additional security requirements within the underlying IT infrastructure. 

NIST also published design principles for commercial and private 5G network operators, including approaches for isolating data-plane, control-plane, and operations and maintenance traffic. These recommendations address the security of 5G systems and supporting infrastructure. However, they do not eliminate a separate enterprise security question: Which cellular devices are actually operating inside the organization’s facilities? An organization can strengthen the architecture of a private 5G network while still lacking visibility into an unrelated LTE or 5G device operating independently within the same physical environment. 

Device visibility has also attracted attention within 5G security research. In May 2026, the IEEE 5G/6G Innovation Testbed added an Intrusion Detection System and Rogue UE Monitor designed to help researchers identify suspicious activity and unauthorized or compromised devices participating in a 5G environment.

Network-level rogue-device monitoring and RF-based cellular detection address different layers of the problem, but they reinforce the same security principle: device visibility must precede device policy.

Look Beyond Network Asset Discovery

Traditional asset discovery typically asks, “What devices connect to my network?” The growth of independent wireless connectivity raises another question: “Which devices can communicate from within my environment?” Those questions can produce very different answers.

A smartphone operating through LTE or 5G may never appear on the corporate network. Neither may a cellular gateway, hotspot, or embedded cellular module. Yet each can operate inside the same physical environment as protected systems, sensitive information, employees, and critical infrastructure.

This distinction becomes particularly important in data centers, manufacturing environments, critical infrastructure, defense installations, government facilities, research laboratories, and other locations where organizations closely control communications technologies. Extending security visibility into the wireless environment helps security teams identify devices that can operate independently of enterprise-managed infrastructure.

How Can Organizations Detect Cellular Devices Inside a Facility?

Organizations need visibility into the RF spectrum to detect cellular devices that do not connect to enterprise-managed network infrastructure. Bastille provides continuous, 100% passive monitoring of the RF spectrum. Bastille detects cellular devices operating over LTE and 5G without requiring those devices to connect to enterprise Wi-Fi, Ethernet, or other managed network infrastructure.

This visibility allows security teams to identify cellular devices, establish authorized-device policies, and detect unauthorized activity. Teams can investigate devices based on authorization, location, and organizational policy without waiting for them to interact with enterprise network infrastructure.

When security teams need to find a detected device, Bastille uses patented algorithms and analysis to localize it within the monitored environment. This capability changes the security question. Instead of asking: “Did an unauthorized device connect to my network?” security teams can ask: “Is an unauthorized cellular device operating anywhere in my protected environment?” The second question expands security visibility beyond enterprise-managed network infrastructure.

Your Network Map Can Be Accurate and Still Be Incomplete

Enterprise security teams have spent decades improving network visibility, and that investment remains essential. But connectivity no longer stops at the boundaries of enterprise-managed infrastructure. An organization’s network map can accurately represent its connected assets while still missing devices operating through LTE and 5G. As cellular connectivity spreads across smartphones, routers, gateways, IoT devices, industrial equipment, and embedded systems, security teams need visibility into both the devices that connect to their networks and the cellular devices operating independently within their facilities.

Cellular device detection extends security visibility beyond enterprise-managed network infrastructure and into the RF spectrum, giving security teams a more complete picture of the communications technologies operating inside protected environments. The device that creates the greatest visibility gap may be the one that never appears on the network map.

Close your cybersecurity gaps with AI-driven wireless visibility

See Bastille in action with a live demo from our experts in wireless threat detection.