// blog

The Drone Is Also a Subscriber

Neutralising a cellular-guided aircraft by working with the mobile network it flies on — and the exact point at which that stops working.

BG
Baruch Glick
Founder, GOTEAM · August 19, 2026 · 14 min read
Night thermal-style view over a valley: several cellular masts below, an aircraft locked in a tracking box above the skyline, and a line drawn from one mast to the aircraft
Drone communicating over cellular (illustration)
01 · CONNECT The aircraft joins as an ordinary subscriber 02 · WHAT THE NETWORK ALREADY COLLECTS — no new hardware Radio layer Altitude and distance outside the range a handset occupies Strong signal from many towers that street level cannot see at once Sector changes tracing a flight path Traffic layer Sustained upload against a thin downlink — a handset does the reverse Constant-rate session held while aloft Metadata only. Content stays encrypted and unread Absence Never places or receives a call Talks to one destination, not to a dozen application back-ends Freshly activated SIM, no roaming, no history behind it 03 · BEHAVIOURAL MODEL Not a signature — a model of normal The carrier owns the baseline: millions of device-hours of ordinary behaviour. Output is a ranked shortlist carrying its evidence, NOT an alarm. 04 · AGENTS — the response has to complete inside the window, so no step waits for a person Assemble Package the behaviours, the confidence and the time window Resolve identity Which subscriber, and which physical hardware module Check authority Is this action permitted, on this instrument, by whose warrant 05 · A PERSON AUTHORISES The one step that is not automated They approve a decision already assembled — not an investigation to begin. 06 · EFFECT — nothing is transmitted, nothing else on the band is touched Force the device off the network immediate, like dropping a call Suspend the subscriber identity a reconnection cannot authenticate Block the destination it reaches for link nominally alive, and useless Blacklist the hardware module a fresh SIM in the same unit still fails Redirect into a monitored dead end preserves attribution — and the aircraft keeps flying 07 · WHERE THIS STOPS WORKING Already on inertial or visual guidance? Then it no longer needs the network. Disconnecting removes the operator's ability to change its mind, and nothing else. It keeps flying. It still arrives. The terminal phase needs a kinetic layer. Nothing above touches it. cruise — minutes seconds terminal — no time left
From a drone joining the network to an effect on its link — and the phase where the network has no leverage left

Most of the counter-drone conversation assumes the defender and the aircraft are alone in the field: a sensor, a threat, and whatever the defender can emit or fire between them. But a growing share of long-range unmanned aircraft do not fly alone. They fly on somebody's mobile network — a small cellular module aboard the airframe, carrying commands out and video back over the same towers that serve the traffic on the road below.

That third party is not neutral. The mobile operator whose network the aircraft is using is a company with an operations centre, a legal department, and an interest in not having its towers used to guide a weapon. It is also, in the moment that matters, the only participant that can see the aircraft's connection from the inside.

What follows is an argument about that: what a cooperating operator can actually do, what a thermal detection system has to hand it for any of it to work in seconds rather than hours, and — the part that decides whether the whole idea is worth building — where it stops helping.

The network already knows something is flying

Start with what the operator can see without buying a single piece of counter-drone equipment.

A device connected to a mobile network produces a continuous stream of measurements simply by being connected. Some of those measurements look wrong for a phone. The distance and altitude figures a network derives for a device sit outside the range a handset on the ground normally occupies. A device in the air has an unobstructed view of many towers at once, so it reports strong simultaneous signal from a set of towers that would be mutually exclusive for anything at street level — buildings and terrain would have shadowed most of them. And it changes tower sectors in a pattern that traces a flight path rather than a road: straight lines across the sector map, turns no vehicle would make, speeds that do not fit traffic.

None of that requires a drone-specific product. It is behavioural detection over data the network already collects for its own purposes. An operator who chooses to look can build a standing filter for airborne-behaving devices.

The problem is what that filter returns. Across a metropolitan network it returns a lot — legitimate aircraft, devices on tall structures, measurement artefacts, and whatever the filter's tuning happens to catch that day. A list of candidates is not an identification, and an operations centre cannot act on a list.

The hinge: a bearing and a timestamp collapse the list

This is the part of the argument that is actually new, and it is worth being precise about why.

"A mobile operator can disconnect a device" is not a novel claim. Operators disconnect devices every day. The reason network-side response has not featured in counter-drone architecture is that the operator has never had a way to know which device, quickly enough for the answer to matter. Behavioural detection alone produces a population, and reducing a population to a suspect is slow, arguable work.

A passive thermal sensor produces exactly the missing quantity. It sees the aircraft by its own heat, so it does not care whether the aircraft is transmitting, and what it outputs is not a suspicion — it is a track: a bearing from a surveyed position, an elevation, a direction of travel, and a timestamp good to the frame.

Hand that to the operator in real time and the geometry does the work. The operator takes the sector map around the sensor's position, intersects it with the bearing and the direction of travel, filters to the seconds either side of the timestamp, and asks which of its airborne-behaving candidates was moving along that line at that moment. The population collapses. The realistic outcome is one or two candidates rather than thousands, and it arrives in the time a query takes rather than the time an investigation takes.

That inversion is the whole proposition. It changes what a detection system is in this architecture. It is not producing an alert for a human to react to, and it is not cueing a shooter. It is supplying the discriminating parameter that turns a network operator's broad statistical filter into a specific identification — a targeting cue for a response that happens entirely inside somebody else's infrastructure.

It also cuts the other way, and the point deserves stating in the operator's favour rather than ours: without the network side, a thermal track is a track. It tells you something is there. It does not, by itself, do anything to the aircraft. The two halves are worth more together than either is alone, which is the ordinary condition of every layer in a layered defence.

Cutting the link, with nothing emitted

Once the connection is identified, the operator has a set of actions that need no new equipment and no cooperation from the aircraft.

It can force the device off the network immediately. It can suspend the subscriber identity on the card so that even a reconnection attempt fails to authenticate. It can block the specific server or address the device is trying to reach, leaving the connection nominally alive but useless. Or — the option worth the most to an investigator — it can redirect the device's traffic into a monitored dead end, where the aircraft continues to believe it has a link while everything it sends is captured and traced.

Set that against the alternative. The established way to sever a drone's control link is to jam it: flood the relevant band with enough noise to drown the signal. Jamming works, and it has three costs that never go away. It is indiscriminate — it takes down whatever else is using that band within its footprint, including the phones of the people you are protecting. It is heavily regulated, and around controlled airspace and civil infrastructure the regulation typically amounts to a prohibition for anyone who is not a specifically authorised state user. And it emits, which in any contested environment means it announces both that you are there and where.

A network-side disconnection has none of those properties. Nothing is transmitted. Nothing outside the identified connection is affected. The action happens on infrastructure that is already lawfully entitled to disconnect a device on it, at the operator's own console. Our inference: this is the reason a carrier's operations lead would engage at all. The counter-drone argument on its own is somebody else's problem; the argument that they can contribute a decisive effect using a mechanism they already own, without radiating anything or degrading service to a single other subscriber, is not.

The hardware keeps its own name

Suspending the subscriber identity handles the account. It does not handle the airframe, because the obvious countermeasure is a second card.

The physical cellular module carries a hardware identifier separate from the subscriber identity, and that identifier can be blocked at network level in its own right. Do both, and the aircraft that lands, gets a fresh card fitted, and takes off again finds the network still refusing it.

The honest caveat is that this is a defence against reuse, not a permanent removal. A hardware identifier is a value the module presents, and on some modules it is not beyond changing; a replaced module defeats it outright. What the blacklist buys is time and cost imposed on the other side — the same currency most counter-drone measures are actually paid in.

None of this is an improvised phone call

Every capability above is available today. None of it is available during an incident to a defender who has not arranged it in advance, and this is where the idea most often dies.

A request that arrives at a mobile operator cold, from an organisation with no standing relationship, becomes a support ticket. It is triaged, escalated, checked with legal, and answered — correctly and responsibly — on a timescale of hours or days. An aircraft's terminal approach is a matter of seconds. The mismatch is total, and no amount of urgency in the phrasing closes it.

What makes the capability real is unglamorous and entirely organisational: a standing real-time coordination channel, agreed with the operator's operations team before anything happens. A named contact, an authenticated path for passing a bearing and a timestamp, a pre-agreed legal basis for the disconnection, and a rehearsed sequence — so identification and disconnection are a procedure being executed rather than a decision being taken. That groundwork is the capability. The technical mechanisms are the easy half.

Where this stops working

Now the limitation, and it is severe enough that it should be read before any of the above is treated as a plan.

Cutting the connection defeats an aircraft that is still relying on the network to navigate. Many are, for most of their flight — the link is how they receive commands and how they send back what they see.

An aircraft that has already switched to self-contained guidance is a different problem entirely. Once it is running on inertial navigation toward a stored coordinate, or has achieved a visual lock on its target and is flying the last stretch on what its own camera sees, it no longer needs the network for anything. Disconnecting it removes the operator's ability to change its mind, and nothing else. It keeps flying. It still arrives.

This matters more than it first appears, because the switch to self-contained guidance is not incidental to the design — it is deliberately placed at the end of the flight, precisely because that is when the link is most likely to be contested. The terminal phase is engineered to survive losing the link. So the window in which network-side disconnection is decisive closes exactly as the threat becomes most acute, and a defence built on it alone has its effect at the moment the aircraft is furthest away and its failure at the moment the aircraft is closest.

The consequence is unavoidable and should be stated as a requirement rather than an afterthought: this approach must be paired with a local physical intercept covering the terminal phase. It buys distance, time, and — through the monitored dead end — attribution. It does not close the kill chain, and anyone presenting it as though it does is selling the easy half of the problem.

The takeaway

The layered-defence argument is usually made about sensors: put enough independent detection methods together that their blind spots do not line up. This is the same argument applied to effects, and it points somewhere the sensor conversation rarely goes — at an actor who is already in the engagement, already has the relevant access, and has never been given the one piece of information that would let them use it.

The transferable idea is narrow and worth separating from everything around it. A thermal track's bearing and timestamp are the parameter that turns a mobile operator's list of thousands into a candidate of one. That is a geometry problem with a fast answer, and it is the only part of this that a detection system contributes.

Everything else is other people's: the operator's network, the operator's lawyers, the operator's console, and — for the terminal phase this cannot touch — somebody else's physical intercept. Which is the correct shape for a counter-drone contribution to have. The failure mode in this field has always been a vendor describing their own layer as the answer.

This piece sets out an approach to cooperation between a counter-drone detection system and a mobile network operator. It describes capabilities in general terms; specific mechanisms, thresholds and legal bases vary by operator, by network generation and by jurisdiction, and none of it should be treated as a substitute for advice from the operator's own engineering and legal teams. GoTeam builds passive thermal detection — it does not operate a mobile network, and this article does not describe or imply an existing arrangement with any carrier. Commentary is GoTeam's; passages marked as our inference are our own reading rather than established practice.

Working the counter-drone problem?

We build passive thermal detection for sites that need a track without waiting for the aircraft to transmit.

REQUEST A BRIEF →