Kid Fakes Dad to Get a New Phone Line Installed

Security Week Feed · Low sophistication
Last updated October 1, 2026

A future security executive describes how, as a young teenager, he used deception to get a phone company to install a second phone line at his home. He posed as his father using a forged letter and a believable technical-sounding request (“dedicated low-noise line for a modem”), successfully convincing the installer. The story is a real example of social engineering: exploiting trust and weak identity checks to get unauthorized service.

Key findings

  • The attacker (as a teen) impersonated a parent to order and authorize installation of a second phone line.
  • The scam relied on weak verification: the installer had “nothing to verify the signature against.”
  • The pretext sounded legitimate and technical: a “dedicated low-noise line for a modem.”
  • The attacker ensured they were home alone at installation time and presented a forged authorization letter.

Who’s being targeted

  • Commonly targeted roles: Field Technicians, Customer Service / Call Center, Provisioning / Service Activation Teams, Operations Managers (service providers).
  • Affected industries: Telecommunications, Field services / on-site technicians, Utilities and service providers (identity verification processes).
  • Attack channels: physical.
  • Impersonated: Customer’s parent/account holder (father).

Awareness takeaways

  • Do not approve service changes or installations based only on a letter or signature, verify the requester using a known, independent method.
  • Treat technical-sounding requests as a potential pressure tactic; require standard verification even when the story sounds knowledgeable.
  • Be alert when the authorized account holder is not present during on-site work; confirm authorization before proceeding.

Red flags to watch for

  • Authorization is only a letter/signature with no independent verification
  • Account holder is not present; a minor/other person is attempting to approve work
  • Request is framed with convincing technical detail to reduce scrutiny
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Picture this: a teenager gets a brand‑new phone line installed at home… by faking a note from his dad. He calls the phone company, orders a second line, and when the engineer shows up, he’s home alone with a forged letter: “My dad approves a dedicated low‑noise line for a modem.” No one checks anything. That’s social engineering in the real world: a confident story, some techy language, and a signature no one can compare against. The only “proof” is a piece of paper the engineer has nothing to verify. If the account holder isn’t standing in front of you, don’t trust the letter. Stop, and call the customer back using the official number on file before you touch the work order.

MITRE ATT&CK techniques

Similar attacks

Fraudsters Can Remotely “Brick” Phones for $3

Fraudsters Can Remotely “Brick” Phones for $3

Researchers showed that attackers can abuse mobile carriers’ “lost/stolen phone” reporting process to get devices blocked from the cellular network, even when the devices were never lost. With only a prepaid account and a target device’s IMEI number, blocking can cost just a few dollars and take…

September 11, 2026
Fake Tech Support Trick Led to WINDTRE Breaches

Fake Tech Support Trick Led to WINDTRE Breaches

Italy’s privacy regulator fined telecom operator WINDTRE €1.7M after two breaches where attackers used social engineering, posing as support technicians, to persuade store staff to grant system access. The intruders then pulled personal data for over 365,000 customers, including payment-related…

July 20, 2026
Fake Gmail Attachment Lure Drops Antino Backdoor

Fake Gmail Attachment Lure Drops Antino Backdoor

A China-nexus threat group targeted government and policy organizations across Asia using spear-phishing emails tailored to the victim’s interests. The emails used spoofed trusted senders and a realistic fake Gmail attachment preview that linked to attacker-controlled pages, ultimately installing…

October 2, 2026
Fake Zoom Installer Drops CloudSyncD Backdoor

Fake Zoom Installer Drops CloudSyncD Backdoor

Researchers found macOS users being tricked into installing a fake Zoom app that actually installs a persistent backdoor called CloudSyncD. The installer guides the victim through a normal-looking setup and prompts for the user’s password so it can run with elevated privileges and stay on the Mac…

October 2, 2026
TA419 Poses as White House to Steal Cloud Logins

TA419 Poses as White House to Steal Cloud Logins

A China-aligned espionage group (TA419) targeted U.S. AI policy experts by impersonating well-known public figures and sending credible policy-related invitations. After victims replied, the attackers sent shortened links that led to a fake OneDrive login designed to capture passwords, MFA codes,…

October 2, 2026
China-Linked Phishers Target AI Policy Experts

China-Linked Phishers Target AI Policy Experts

Researchers reported two China-aligned campaigns that used phishing and impersonation to target AI policy experts and multiple Asian government organizations. One campaign built rapport with “AI policy” themed outreach before sending links to a OneDrive credential-harvesting page, while another…

October 1, 2026