Verification

What Compromised Means on a CheckMend Report (and How It Differs From a GSMA Blacklist)

A CheckMend report comes back "compromised" and the seller swears the lot is GSMA clean. Both can be true at once, because they are answers from two different databases. Here is exactly what the status flags and which one to trust.

From above, a dealer checks a cellphone screen at a desk.

"Compromised" on a CheckMend report means the device's serial has a recorded history event, such as a loss report, theft report, settled insurance claim, or network block, in CheckMend's own database. It is CheckMend's vocabulary, not a GSMA status, and the two databases do not always agree.

Key takeaways
  • Compromised is CheckMend's umbrella term for a device whose history checks did not all come back clear. It is provider-specific wording, not an industry-wide status.
  • CheckMend is powered by Recipero and draws on police, insurer, retailer, recycler, and network records, so it can flag events the GSMA Device Registry never sees.
  • A lot can be compromised on CheckMend and clean on GSMA at the same time. That is a data-source difference, not an error.
  • For a bulk purchase decision, do not pick one database. Screen the manifest against both and treat any red flag from either as a title or resale risk.
  • Get the check date and the exact result vocabulary into the deal terms, so a dispute is about a documented snapshot, not memory.

What is CheckMend?

CheckMend is a device-history checking service operated by Recipero. Where a plain blacklist check asks one question, "is this IMEI flagged as lost or stolen right now," CheckMend runs a serial number against a much wider set of records: police and public loss/theft reports, settled insurance claims, network block data, retailer and recycler records, and its own crowd-reported incidents. Recipero states its datasets cover tens of billions of serial numbered items.

That breadth is the whole point, and it is also why CheckMend results confuse traders. The report is not answering "will this phone work on a network." It is answering "does this device have any recorded history that could affect legal title or resale value." Those are different questions with different answers.

What does "compromised" actually mean?

On CheckMend, a device is described as compromised when one or more of its history checks returns a warning instead of a clear result. CheckMend reports use a traffic-light convention: each individual check comes back green (clear), amber or orange (caution), or red (warning). A report where everything is green is a clean report. A report with red or amber results is what CheckMend's own material calls a lost, stolen, or compromised device.

What a compromised result can be driven by:

The critical nuance: compromised does not tell you which of these fired. Two compromised units can carry completely different risk, one is an insurer-owned theft payout, the other is a phone with a registered previous owner. Always open the per-check detail before pricing the risk.

Trading this stock yourself? Aikon is a live floor for wholesale electronics: registered companies post buy and sell offers and deal with each other directly. Join free.

CheckMend result vocabulary, decoded

These are the result types a CheckMend report works from, and what each one should mean to a wholesale buyer:

Result on the reportSeverityWhat it means for a bulk buyer
All checks clear (clean report)GreenNo recorded history event in CheckMend's datasets at the time of the check. Snapshot, not a permanent guarantee.
Currently blockedRedA network has the IMEI blocked due to loss or theft. Unsellable as a working phone in enforcing regions.
Lost / stolen reportRedReported by an owner, the police, or another source. Title risk even if no network block exists yet.
Insurance claim settledRedThe insurer paid out and owns the device. A buyer does not acquire legal title. Walk away or resolve with the insurer.
Ever blocked (since unblocked)AmberThe IMEI carried a block in the past. Worth questioning: who unblocked it and why.
Possible cloneAmberThe same serial appears in more than one device. Genuine phones never share an IMEI, so at most one unit is real.
Possible counterfeitAmberThe serial is reported as used on counterfeit devices. Physical inspection required.
Registered owner / asset recordAmberA previous owner or corporate monitoring record exists. Often benign in used stock, but confirm the seller's chain of ownership.

Format matters here: run every manifest through a free bulk IMEI format check first, so typos and fabricated IMEIs are caught before you pay for history reports on them.

CheckMend vs GSMA vs carrier blacklist: three different databases

Traders use "blacklisted" loosely, but there are three distinct layers. The GSMA Device Registry is the operator-contributed global list of lost, stolen, and finance-defaulted IMEIs. Individual carrier blacklists are what each network actually enforces. CheckMend is a commercial history database that overlaps both and adds records neither holds.

CheckMend (Recipero)GSMA Device RegistryCarrier blacklist
Who runs itRecipero, a commercial providerGSMA, the mobile operator industry bodyEach individual network
Source dataPolice, insurers, retailers, recyclers, networks, owner reportsFlags contributed by member operatorsThat carrier's own loss, theft, and finance records
Question it answersDoes this serial have any recorded history eventIs this IMEI flagged lost, stolen, or unpaid by a contributing operatorWill this specific network refuse service to this IMEI
Typical vocabularyClean vs compromised, per-check green / amber / redClean, flagged, or unknownBlacklisted or not blacklisted
What it can missEvents never reported into its datasetsInsurance claims with no operator flag, incidents from non-contributing carriers and regionsEverything outside that one network
Strongest useTitle and provenance risk on used stockThe contractual clean/flagged trigger in wholesale dealsConfirming usability in a specific destination market

For the GSMA side of this comparison in depth, see what GSMA blacklist status "clean" means, and use the GSMA status decoder to translate raw check results.

Compromised on CheckMend but clean on GSMA: why it happens

This split is the single most common source of confusion, and it is not a glitch. CheckMend and the GSMA Device Registry are fed by different reporters. A theft reported to the police, or an insurance payout, can sit in CheckMend's records without any operator ever adding a GSMA flag. The reverse also happens: an operator flag can reach GSMA before any record lands in a commercial history database.

Typical reasons a unit shows compromised on CheckMend while GSMA says clean:

Which one do you trust for a bulk lot?

Neither, alone. GSMA answers usability: whether networks in enforcing regions will serve the device. CheckMend answers title: whether someone else may have a legal claim on it. A phone can work perfectly and still belong to an insurer. For a purchase decision, a red CheckMend flag on a GSMA-clean unit is a title problem you cannot see from the registry, and it should be treated as disqualifying until the seller documents provenance.

The distinction also runs the other way. A GSMA flag makes a device commercially dead in enforcing markets regardless of what CheckMend says, because carriers act on the registry, not on commercial history reports. The two checks are complements, not substitutes. This is the same reason a device can be "blacklisted" in one country and usable in another; the glossary entry on blacklisted IMEIs covers that regional asymmetry.

Trader playbook: screening a consignment across both

For a bulk lot, screening is a sequence, cheapest check first, so you never pay for history reports on IMEIs that fail basic validation:

  1. Get the manifest before money moves. One IMEI per row, with model and grade. A seller who will not produce a manifest before payment is a seller to walk away from.
  2. Validate format and Luhn first. Run the CSV through the free bulk IMEI check. Typos, duplicates, and fabricated IMEIs surface here at zero cost.
  3. Run the GSMA-layer check on the full manifest. Through an authorised service, since the registry has no public direct query. Any lost, stolen, or finance flag prices those units at parts tier or removes them.
  4. Run device history on the survivors. A CheckMend report per unit, or at minimum on a meaningful random sample of a large used lot. Read the per-check detail: an insurance-claim red is a walk-away, an old registered-owner amber may just need a provenance question.
  5. Physically sample against the manifest. Dial *#06# on random units and compare to the paperwork. A clean pair of database results is worthless if the physical IMEIs do not match the manifest you checked.
  6. Anchor the deal terms to the check date. Both databases are snapshots. Write "clean per [service] as of [date]" into the terms, keep the result exports, and keep the window between check and payment short.

Counterparty screening matters as much as device screening: a manifest that fails these checks is one of the classic warning signs covered in wholesale electronics fraud and scam patterns. On discovery platforms such as Aikon, where companies find counterparties and then deal directly with each other, this verification workflow is the buyer's own responsibility, so build it into your process rather than treating it as optional.

Frequently asked questions

Does compromised on CheckMend mean the phone is blacklisted?

Not necessarily. Compromised means CheckMend found a recorded history event, which can be a network block but can also be a loss report, a settled insurance claim, or a clone or counterfeit indicator with no block at all. Check the per-item detail: only a "currently blocked" result means the IMEI is actually barred by a network.

Is CheckMend the same database as the GSMA blacklist?

No. The GSMA Device Registry holds flags contributed by mobile operators. CheckMend is a commercial database run by Recipero that combines network block data with police, insurer, retailer, recycler, and owner-reported records. They overlap on operator blocks but each holds records the other does not.

Why is my phone compromised on CheckMend but clean on a GSMA check?

Because the triggering event was never reported to an operator. A police loss report or a settled insurance claim goes into CheckMend's datasets directly, without any carrier adding a registry flag. The device stays GSMA clean and fully usable while carrying a title risk that only the history report can see.

Can a compromised CheckMend result be removed or disputed?

If a record is wrong or resolved, the route is through the source of the record: Recipero's support process for disputing a flag, the insurer for a settled claim, or the reporting network for a block. A legitimate owner with proof of purchase can pursue it. As a wholesale buyer, treat "the seller says it will be cleared" as an unresolved red flag until the report itself changes.

Is a clean CheckMend report a guarantee the device is safe to buy?

No database check is a guarantee. A clean report means no recorded event existed in the checked datasets at that moment. An unreported theft, a claim filed next week, or an event held only in a dataset the service does not cover will not appear. That is why the check date belongs in your deal terms and why physical sampling against the manifest still matters.

Trade on the structured layer

Aikon is free for registered companies. Post buy and sell offers, browse a live feed of company-posted offers, and connect across iOS, Android and the web.