Summary
- Cognyte, an Israeli surveillance company, markets a cell-site simulator called FalcoNet that forces nearby mobile phones to connect to it by impersonating a legitimate tower.
- A contract with the state of Texas confirms FalcoNet can be deployed from a concealed vehicle, a backpack, or attached to a helicopter.
- The technology is functionally equivalent to the Stingray, a well-known cell-site simulator originally produced by defence company L3Harris.
- The device captures data from all phones in the vicinity, not just those belonging to specific suspects — raising broad privacy and legal exposure questions.
- There are no corroborating sources beyond the primary reporting; organisations should treat details as preliminary and monitor for further disclosure.
What has been disclosed
A contract between Israeli surveillance company Cognyte and the state of Texas has surfaced details of a mobile cell-site simulator called FalcoNet. The device works by impersonating a legitimate mobile phone tower, compelling nearby handsets to connect to it. Once phones associate with FalcoNet, law enforcement can monitor and track any device in range — regardless of whether the owner is the subject of an investigation.
Form factors and deployment options
According to the contract details reported by Schneier on Security, FalcoNet is designed for flexible, covert deployment. It can be concealed inside a vehicle, carried in a backpack for foot-based operations, or mounted on a helicopter. The multi-platform design suggests it is intended for both fixed surveillance operations and mobile tracking scenarios where ground access is limited or impractical.
Not a new concept, but a widening market
The underlying technology is not novel. Cell-site simulators, colloquially known as Stingrays after the original device produced by US defence company L3Harris, have been in law enforcement use for many years. What this disclosure illustrates is that the market for such tools continues to expand, with additional vendors — including companies operating outside US jurisdiction — now supplying equivalent capabilities to government agencies.
The indiscriminate collection problem
The detail that distinguishes cell-site simulators from more targeted interception methods is their lack of selectivity. When FalcoNet — or any equivalent device — is activated in a public area, it does not distinguish between a suspect’s handset and those of bystanders, journalists, employees, or executives. Every phone in range that connects to the simulated tower is, to varying degrees, subject to monitoring. This has long been the central civil liberties objection to the technology, and it remains unresolved.
Implications for enterprise and executive mobility
For security leaders, the practical concern is straightforward: the mere presence of such a device in an operational area — whether near a courthouse, a government precinct, or any location where law enforcement may be active — creates an environment where mobile communications cannot be assumed private. Corporate devices carried by executives, legal teams, or staff attending sensitive meetings in public or semi-public spaces are potential targets of incidental collection, even where no wrongdoing is alleged.
Limits of what is known
It is worth noting that the source material for this report is a single primary source — Schneier on Security — and there are no corroborating outlets cited. The specifics of what data FalcoNet collects, how it is retained, and under what legal authorities it may be used in Texas or elsewhere are not detailed in the available material. Organisations should treat this as a confirmed product disclosure rather than a comprehensive technical or legal assessment.
Why it matters
Cell-site simulators represent a class of threat that sits outside the conventional enterprise threat model — they are not phishing campaigns or software vulnerabilities, but physical-layer interception tools operated by third parties in public space. For CISOs, the risk is reputational, legal, and operational: sensitive conversations, device identifiers, and location data belonging to executives or staff can be swept up incidentally during legitimate law enforcement activity, or potentially during operations that are later challenged in court. The expanding vendor ecosystem means this capability is no longer limited to a handful of well-resourced agencies. Any organisation with personnel who carry mobile devices into high-risk or high-visibility environments — litigation, regulatory engagement, public protests, or international travel — should factor physical interception into their mobile security posture.
What to do now
- Review your organisation’s mobile device policy for personnel operating in environments where law enforcement activity is likely, including court precincts, government buildings, and public demonstrations.
- Evaluate the use of end-to-end encrypted communications applications for sensitive conversations, as encryption of data in transit reduces the value of layer-level interception.
- Consider briefing executives and legal teams on the existence of cell-site simulator technology and the principle that mobile communications in public spaces carry inherent interception risk.
- Monitor public procurement databases and investigative reporting for further disclosures about FalcoNet deployments or similar tools that may be relevant to your operating jurisdictions.
- Engage your legal and privacy teams to assess whether incidental collection of employee device data by law enforcement tools creates any notification or compliance obligations under applicable privacy frameworks.
