← Back to results
Federal

Understanding Cybersecurity of Mobile Networks Act

Source: Congress.gov  ·  1,649 words in original text
This bill directs the Assistant Secretary of Commerce for Communications and Information to write a report about cybersecurity weaknesses in mobile phone service networks. The report will examine how vulnerable these networks are to cyberattacks and surveillance by hostile actors. The Assistant Secretary must submit this report to Congress within one year of the bill becoming law.
Mobile service providers (including small and rural providers), mobile phone manufacturers, makers of mobile operating systems and apps, academic researchers, the Federal Communications Commission, the Department of Homeland Security, the Department of State, the intelligence community (a term defined in the National Security Act of 1947), and Congress.
- The Assistant Secretary must examine how mobile service providers have addressed cybersecurity weaknesses found by researchers and federal agencies. (Sec. 2(b)(1)) - The report must discuss whether customers consider cybersecurity when buying mobile service and whether tools exist to help customers understand cybersecurity risks. (Sec. 2(b)(2)) - The report must estimate how widely encryption (scrambling information so others cannot read it) and authentication techniques (methods to verify identity) are used in mobile phones, services and software. (Sec. 2(b)(4)) - The report must discuss obstacles preventing providers from using stronger encryption and authentication methods and removing outdated ones with known weaknesses. (Sec. 2(b)(5)) - The report must estimate how widely cell site simulators (devices that trick phones into connecting to fake networks) and similar surveillance technologies are available and used by hostile actors in the United States. (Sec. 2(b)(7)) - The Assistant Secretary must exclude 5G technology from the report and only examine weaknesses that have been exploited in real situations or realistically could be exploited. (Sec. 2(d)(2), (3))
If this bill becomes law, Congress will receive a detailed report examining how secure mobile phone networks are against cyberattacks and surveillance. The report will include classified (secret) information provided separately to Congress and will have sensitive technical details removed from the public version.
- "Adversary" means any unauthorized hacker entering a mobile network, or any foreign government or foreign person conducting serious, long-term actions against United States national security or the safety of Americans. (Sec. 2(f)(1)) - "Mobile service" means commercial mobile service (regular cell phone service) or commercial mobile data service provided to United States customers. (Sec. 2(f)(6)) - "Mobile communications equipment or service" means any equipment or service needed to provide mobile service. (Sec. 2(f)(5)) - "United States person" means a U.S. citizen, a permanent resident alien, an organization created under U.S. law, or any person physically located in the United States. (Sec. 2(f)(8))
Not specified in bill text. The report is due one year after the date the bill becomes law.
Important: This plain English summary was generated by AI and is provided for informational purposes only. It is not legal advice. Always consult the official bill text on Congress.gov or a qualified attorney for legal matters.