HawkEye 360 has been doing this for a few years.
In 5G this is somewhat fixed - the handset uses its Home Network Public Key to encrypt the device-specific IMSI (producing a SUCI) which only the Home Network can decrypt. The MCC and MNC (carrier information) are still sent in the clear to allow the encrypted SUCI to route to the correct Home Network for decryption.