IMEIAPI.orgTAC Base
Security

IMEI cloning, and why it fails more often than it works

Copying an identity onto another handset, or overwriting a handset's own. Both are criminal, both are detectable, and neither is as common as the warnings suggest.

Two different things called cloning: copying a valid IMEI onto another phone, and overwriting a phone's own IMEI

"Cloned IMEI" gets used for two different operations with different purposes and different tells. Separating them is the first step to knowing whether the phone in front of you has been interfered with.

Copying versus overwriting

Copying takes a valid IMEI belonging to a real, unblocked handset and writes it onto a second one. Two devices now claim one identity. The purpose is to give a blocked or unregistered device a clean-looking number.

Overwriting simply replaces a handset's own IMEI with something else, often invented. The purpose is usually to escape a block on the original number rather than to impersonate a specific device.

Both are criminal offences in most jurisdictions — the United Kingdom, most of the EU, the United States and many others legislate specifically against altering a device identifier. This is worth stating plainly because a certain amount of online material presents it as a grey area or a repair technique. It is neither.

Why it works badly

The appeal is obvious and the execution is poor, for reasons that are structural rather than technical.

A copied identity has to coexist with the original. Two handsets registering the same identity, sometimes in two places at once, is a pattern operators can see — and it draws attention to the legitimate device as well, which is how these cases often surface.

An overwritten identity has to survive contact with the physical device. The number now reported does not match the number printed inside the case, on the box, or in the manufacturer's records, and none of those can be edited from software.

What gives it away

Four signals of a tampered identifier, none requiring specialist equipment
Four checks, all available to whoever is holding the phone.

The label disagreeing with the dialled number is the cheapest test and catches most overwriting. It takes five seconds and is skipped constantly.

The record contradicting the hardware catches the rest. If the number resolves to a different model, a different manufacturer, or a device type that is not a phone, then whatever was written onto this handset came from somewhere else.

A failed checksum catches invented numbers, which frequently do not survive the check digit. And a well-formed number whose Type Allocation Code was never allocated to anyone is a strong signal on its own — the format is right, the number is fiction.

What this means for intake

The practical conclusion is not to fear tampering, which is comparatively rare, but to make the checks that detect it routine rather than exceptional.

  • Read the identifier from the device, never from a sticker or a photograph.
  • Resolve it and compare the answer with the hardware you can see.
  • Treat a disagreement between label and dialled number as a stop, not as a data-entry problem to be corrected.
  • Keep the number you were given alongside the one you resolved, so a later dispute can be traced rather than argued.

A system that does these four things by default catches tampering as a side effect of catching typos, which is the only way a check that fires rarely stays reliable.

Turn an IMEI into a device record.

Brand, model, code name, device type and radio bands, in one call. Tell us what you're building and we'll set you up with a key.