In the first-ever prosecutions under the federal anti-pretexting statute Congress passed after the 2006 HP boardroom spying scandal, Nicholas Shaun Bunch and Vaden Anderson were separately charged in late 2008 with tricking T-Mobile and Sprint/Nextel into handing over customers' confidential call records: one by posing as the account holder with a name and partial Social Security number, the other by serving the carrier a fake federal court subpoena.
Reviewed by the Social Engineering Examples team.
In late 2008, federal prosecutors brought what the Department of Justice described as the first-ever criminal charges under 18 U.S.C. Section 1039, the pretexting statute Congress created via the Telephone Records and Privacy Protection Act of 2006 (signed into law January 12, 2007) as a direct legislative response to the 2006 Hewlett-Packard boardroom spying scandal, in which HP-hired investigators had used victims' Social Security numbers and impersonation to obtain journalists' and directors' phone records. Two unrelated defendants were charged: Nicholas Shaun Bunch, accused in the Northern District of Alabama (via criminal information) of using a T-Mobile customer's name and the last four digits of that customer's Social Security number to obtain the customer's confidential phone records; and Vaden Anderson, indicted by a federal grand jury on December 30, 2008 in the Northern District of Ohio (Case No. 1:08CR528) for serving Sprint/Nextel with a fictitious U.S. District Court civil subpoena to obtain a customer's confidential call records. Both cases turned on the same underlying vulnerability the 2006 law targeted: telecom carriers' processes for verifying who was entitled to receive a customer's call detail records were exploitable either through weak identity-verification scripts (name plus a partial SSN) or through insufficiently scrutinized legal-process paperwork.
Two distinct pretexting techniques were used to defeat carrier account-security processes that predated the FCC's stronger 2007 CPNI password rules. Bunch is alleged to have called T-Mobile customer service and verbally impersonated the account holder, presenting the victim's name and the last four digits of the victim's Social Security number as identity "verification," information that was treated by phone reps as sufficient proof of ownership, even though it is exactly the kind of low-entropy, widely-exposed personal data pretexting statutes were written to stop being used as an authentication factor. Anderson used a different vector: rather than talking his way past a live customer-service rep, he served Sprint/Nextel with what the indictment describes as a fictitious U.S. District Court civil subpoena, exploiting the carrier's legal-compliance and subpoena-response unit, which processed the document as a valid compulsory legal order rather than independently confirming its authenticity with the purported issuing court before releasing the target's confidential call detail records.
Bunch's play was pure social engineering of a customer-service script: presenting himself by phone as the legitimate subscriber and offering two commonly-breached, low-friction identifiers (full name plus last four SSN digits) that reps were trained to accept as adequate proof of account ownership. The "tell" was that neither piece of information is secret to anyone who has done even modest reconnaissance on a target. Anderson's play leaned on institutional trust in the *form* of legal process rather than personal familiarity: producing a document formatted to look like a genuine U.S. District Court civil subpoena was enough to move it through Sprint/Nextel's subpoena-compliance channel, betting (correctly, for a time) that the compliance staff would honor the paperwork's appearance of authority rather than call the clerk's office to confirm a real case and subpoena existed.
Vaden Anderson, 28, was indicted by a federal grand jury on December 30, 2008 in the Northern District of Ohio (Case No. 1:08CR528, Judge Christopher Boyko) for violating 18 U.S.C. Section 1039(a)(3) by providing Sprint/Nextel a false or fraudulent document (the fictitious civil subpoena) to obtain confidential phone records; DOJ characterized this as the first indictment ever obtained under the statute, carrying a maximum of 10 years' imprisonment and a $250,000 fine. Secondary reporting (Tech Law Journal) indicates Anderson later pleaded guilty around March 2009 and was sentenced to 21 months in prison, but Diopter could not confirm this specific plea and sentencing detail against a primary DOJ press release or court docket within available research tools, so it should be treated as reported but unverified. Nicholas Shaun Bunch was separately charged in November 2008 (with a companion criminal information filed via the Northern District of Alabama roughly three weeks before Jan. 8, 2009, per Tech Law Journal) with using a T-Mobile customer's name and the last four digits of that customer's Social Security number to obtain the customer's confidential phone records, and was also charged with aggravated identity theft for use of the victim's Social Security number. Per Wired's contemporaneous reporting, Bunch agreed to plead guilty to both charges and to pay restitution in an amount to be determined by the court, with prosecutors agreeing to recommend a reduced sentence in exchange for his cooperation; however, the final restitution amount, sentence, and any fine actually imposed on Bunch are not documented in the available public record.
These cases matter as the real-world test of whether the law Congress passed in reaction to a marquee corporate-espionage scandal (HP's boardroom pretexting) would actually be used against the everyday pretexting economy: the skip-tracers, private investigators, and individuals who had for years bought and sold confidential phone records through data brokers. They show that more than two years after the HP scandal exposed how trivially carriers could be fooled by someone who simply supplied a name and a few digits of a Social Security number, that exact technique (Bunch) and a second, entirely different pretext, fabricating official legal process rather than impersonating a customer (Anderson), were still succeeding against T-Mobile and Sprint/Nextel. For an education audience, the pairing is a clean illustration that pretexting is not one technique but a category: the same underlying goal (extract a confidential record from an institution) can be reached either by social-engineering a live human on a support line or by counterfeiting the institutional paperwork that supposedly compels release, and defenders have to close both doors.
The FCC's 2007 CPNI Order (issued in the same legislative wave as the TRPPA) required carriers to move beyond name/SSN-digit verification: mandatory customer-set passwords for phone-based account access, opt-in consent before sharing call records with joint-venture partners, and delayed/limited disclosure windows after password-reset requests, directly closing the "name plus last-4-of-SSN" verification gap Bunch is alleged to have exploited. For the Anderson vector (a fabricated court subpoena), the structural defense is a carrier legal-compliance workflow that independently verifies subpoenas/legal process with the issuing court or clerk's office before releasing records, rather than accepting the face validity of a served document; treating "it looks like an official court paper" as sufficient authority was the exploited weakness. More broadly, both cases illustrate why any process that authenticates a requester using static, breachable personal identifiers (SSN digits, DOB, address) or unverified paper credentials remains pretext-able, and why callback-to-known-number verification, out-of-band confirmation, and document-authenticity checks are the durable countermeasures.
Between 2006 and 2008 the FTC sued 16 data-broker and private-investigation defendants who pretexted telecom carriers, posing as account holders…
The FTC's first-ever case under the FACTA Disposal Rule: a Northbrook, Illinois mortgage lender repeatedly dumped intact customer credit reports…
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…