A former AT&T retail employee helped a SIM-swap crew hijack customers’ phone numbers, letting the criminals intercept SMS two-factor codes and reset online banking passwords. The gang then attempted (and in one case succeeded) to wire large sums from victims’ bank accounts, often to accounts in Portugal.
Key findings
- An AT&T store employee used privileged access to move victims’ phone numbers to SIMs controlled by the criminals.
- After hijacking the number, co-conspirators reset online banking passwords so SMS 2FA codes and reset links went to the attackers.
- The crew attempted multiple large wire transfers (about $247K each); one victim loss succeeded for $99,528.33.
- The scheme relied on insider access and SMS-based authentication weaknesses rather than advanced technical hacking.
- Investigators found victims’ sensitive personal data (including Social Security numbers) at the insider’s home.
Who’s being targeted
- Commonly targeted roles: Retail Store Staff, Mobile Carrier Call Center/Customer Support, Fraud/Payments Teams, Bank Operations, Security Awareness/Insider Risk Programs.
- Affected industries: Telecommunications, Retail (mobile carrier stores), Banking/Financial Services.
- Attack channels: physical, website.
- Impersonated: Legitimate mobile customer account change (abusing AT&T store access), Bank customer (using victim identity data and control of the victim’s phone number).
Awareness takeaways
- Treat SIM swaps as a high-risk event: require strict verification, logging, and rapid escalation for number/SIM changes.
- Move away from SMS-based MFA for critical accounts; prefer authenticator apps or hardware keys.
- Add a carrier-level PIN/passcode requirement before any SIM change can be approved.
- Train staff to recognize and report insider-risk signals (repeated unusual account changes, unexplained sensitive data handling).
Red flags to watch for
- SIM change request doesn’t match the real customer’s presence/identity checks
- Unusual repeated SIM swaps tied to the same employee/store
- Requests tied to high-value targets followed by immediate account-reset activity
- Unexpected loss of mobile service followed by bank password reset messages
- Password reset attempts or wires immediately after a SIM change
- Wire destination to unfamiliar/foreign accounts
Read the video transcript
An AT&T store worker was paid up to two grand a pop to quietly move customers’ phone numbers onto SIM cards for a criminal crew. Once your number was hijacked, they’d trigger bank password resets. All the SMS two-factor codes and reset links went to the crew, and they tried wiring about two hundred forty-seven thousand dollars per victim, one account lost ninety-nine thousand five hundred twenty-eight dollars and thirty-three cents. Here’s the scary part: this wasn’t fancy hacking. It was insider access plus the weakness of SMS codes. One insider ran this from 2018 to 2019, getting paid per SIM swap, and investigators later found victims’ Social Security numbers sitting at his home. Your move: for any important account, drop SMS codes. Switch to an authenticator app or hardware key today, and treat any sudden loss of mobile service as an emergency.