AT&T Insider Aided SIM-Swap Bank Heists

Graham Cluley · Medium sophistication
Last updated September 15, 2026

A former AT&T retail employee helped a SIM-swap crew hijack customers’ phone numbers, letting the criminals intercept SMS two-factor codes and reset online banking passwords. The gang then attempted (and in one case succeeded) to wire large sums from victims’ bank accounts, often to accounts in Portugal.

Key findings

  • An AT&T store employee used privileged access to move victims’ phone numbers to SIMs controlled by the criminals.
  • After hijacking the number, co-conspirators reset online banking passwords so SMS 2FA codes and reset links went to the attackers.
  • The crew attempted multiple large wire transfers (about $247K each); one victim loss succeeded for $99,528.33.
  • The scheme relied on insider access and SMS-based authentication weaknesses rather than advanced technical hacking.
  • Investigators found victims’ sensitive personal data (including Social Security numbers) at the insider’s home.

Who’s being targeted

  • Commonly targeted roles: Retail Store Staff, Mobile Carrier Call Center/Customer Support, Fraud/Payments Teams, Bank Operations, Security Awareness/Insider Risk Programs.
  • Affected industries: Telecommunications, Retail (mobile carrier stores), Banking/Financial Services.
  • Attack channels: physical, website.
  • Impersonated: Legitimate mobile customer account change (abusing AT&T store access), Bank customer (using victim identity data and control of the victim’s phone number).

Awareness takeaways

  • Treat SIM swaps as a high-risk event: require strict verification, logging, and rapid escalation for number/SIM changes.
  • Move away from SMS-based MFA for critical accounts; prefer authenticator apps or hardware keys.
  • Add a carrier-level PIN/passcode requirement before any SIM change can be approved.
  • Train staff to recognize and report insider-risk signals (repeated unusual account changes, unexplained sensitive data handling).

Red flags to watch for

  • SIM change request doesn’t match the real customer’s presence/identity checks
  • Unusual repeated SIM swaps tied to the same employee/store
  • Requests tied to high-value targets followed by immediate account-reset activity
  • Unexpected loss of mobile service followed by bank password reset messages
  • Password reset attempts or wires immediately after a SIM change
  • Wire destination to unfamiliar/foreign accounts
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

An AT&T store worker was paid up to two grand a pop to quietly move customers’ phone numbers onto SIM cards for a criminal crew. Once your number was hijacked, they’d trigger bank password resets. All the SMS two-factor codes and reset links went to the crew, and they tried wiring about two hundred forty-seven thousand dollars per victim, one account lost ninety-nine thousand five hundred twenty-eight dollars and thirty-three cents. Here’s the scary part: this wasn’t fancy hacking. It was insider access plus the weakness of SMS codes. One insider ran this from 2018 to 2019, getting paid per SIM swap, and investigators later found victims’ Social Security numbers sitting at his home. Your move: for any important account, drop SMS codes. Switch to an authenticator app or hardware key today, and treat any sudden loss of mobile service as an emergency.

Similar attacks

Phish Adds Passkey That Survives Reset

Phish Adds Passkey That Survives Reset

Researchers described iAuthFlow v2, a phishing toolkit that steals a live Google login session and then uses that access to enroll an attacker-controlled passkey. Because passkeys are separate login methods, the attacker can often get back into the account even after the victim changes their…

August 24, 2026
Scattered Spider Duped TfL Helpdesk to Reset 2FA

Scattered Spider Duped TfL Helpdesk to Reset 2FA

UK authorities said two Scattered Spider members accessed Transport for London (TfL) by buying partial employee credentials and then tricking TfL’s helpdesk into resetting an employee password and 2FA. The attackers kept access for several days, escalated privileges, and ultimately exposed customer…

July 16, 2026
Wall Street Hit by Help Desk Impersonation Calls

Wall Street Hit by Help Desk Impersonation Calls

A real campaign of voice-phishing (vishing) calls targeted major hedge funds and private equity firms by impersonating internal IT/help desk staff. Victims were pressured into completing “routine” security steps and were sent to fake login pages that captured usernames, passwords, and MFA codes in…

August 20, 2026
Redact Rebrand Uses IT Helpdesk Vishing

Redact Rebrand Uses IT Helpdesk Vishing

Google says the BlackFile extortion group (UNC6671) rebranded to “Redact” while keeping the same core scam: phone calls that impersonate IT helpdesk staff and push “urgent security migrations.” Victims are directed to spoofed login pages that steal passwords and MFA codes, enabling attackers to…

August 7, 2026
Passkey-Themed Phishing Hits Microsoft 365

Passkey-Themed Phishing Hits Microsoft 365

Microsoft warns of an active social engineering campaign where attackers pose as an IT help desk and pressure employees to “update” passkeys/MFA/SSO. Victims are sent to fake Microsoft sign-in pages or tricked into approving access via device-code login, enabling attackers to add their own MFA…

September 14, 2026
FBI Warns of OAuth Consent Phishing Tricks

FBI Warns of OAuth Consent Phishing Tricks

A SecurityWeek roundup highlights multiple real-world scams and campaigns where attackers trick people rather than “hack” systems directly. Notable items include OAuth “consent phishing” (getting users to approve a malicious app’s access), and phishing-evasion using invisible Unicode characters…

September 11, 2026