In the first-ever prosecutions under the federal anti-pretexting statute Congress passed after the 2006 HP boardroom spying scandal.
Social Engineering Examples·4 sources
In late 2008, federal prosecutors brought what the Department of Justice described as the first-ever criminal charges under 18 U.S.C. Section 1039, the pretexting statute Congress created via the Telephone Records and Privacy Protection Act of 2006 (signed into law January 12, 2007) as a direct legislative response to the 2006 Hewlett-Packard boardroom spying scandal, in which HP-hired investigators had used victims' Social Security numbers and impersonation to obtain journalists' and directors' phone records.
Two unrelated defendants were charged: Nicholas Shaun Bunch, accused in the Northern District of Alabama (via criminal information) of using a T-Mobile customer's name and the last four digits of that customer's Social Security number to obtain the customer's confidential phone records; and Vaden Anderson, indicted by a federal grand jury on December 30, 2008 in the Northern District of Ohio (Case No. 1:08CR528) for serving Sprint/Nextel with a fictitious U.S. District Court civil subpoena to obtain a customer's confidential call records.
Both cases turned on the same underlying vulnerability the 2006 law targeted: telecom carriers' processes for verifying who was entitled to receive a customer's call detail records were exploitable either through weak identity-verification scripts (name plus a partial SSN) or through insufficiently scrutinized legal-process paperwork.
Two distinct pretexting techniques were used to defeat carrier account-security processes that predated the FCC's stronger 2007 CPNI password rules. Bunch is alleged to have called T-Mobile customer service and verbally impersonated the account holder, presenting the victim's name and the last four digits of the victim's Social Security number as identity "verification," information that was treated by phone reps as sufficient proof of ownership, even though it is exactly the kind of low-entropy, widely-exposed personal data pretexting statutes were written to stop being used as an authentication factor.
Anderson used a different vector: rather than talking his way past a live customer-service rep, he served Sprint/Nextel with what the indictment describes as a fictitious U.S. District Court civil subpoena, exploiting the carrier's legal-compliance and subpoena-response unit, which processed the document as a valid compulsory legal order rather than independently confirming its authenticity with the purported issuing court before releasing the target's confidential call detail records.
Bunch's play was pure social engineering of a customer-service script: presenting himself by phone as the legitimate subscriber and offering two commonly-breached, low-friction identifiers (full name plus last four SSN digits) that reps were trained to accept as adequate proof of account ownership. The "tell" was that neither piece of information is secret to anyone who has done even modest reconnaissance on a target.
Anderson's play leaned on institutional trust in the *form* of legal process rather than personal familiarity: producing a document formatted to look like a genuine U.S. District Court civil subpoena was enough to move it through Sprint/Nextel's subpoena-compliance channel, betting (correctly, for a time) that the compliance staff would honor the paperwork's appearance of authority rather than call the clerk's office to confirm a real case and subpoena existed.
Vaden Anderson, 28, was indicted by a federal grand jury on December 30, 2008 in the Northern District of Ohio (Case No. 1:08CR528, Judge Christopher Boyko) for violating 18 U.S.C. Section 1039(a)(3) by providing Sprint/Nextel a false or fraudulent document (the fictitious civil subpoena) to obtain confidential phone records; DOJ characterized this as the first indictment ever obtained under the statute, carrying a maximum of 10 years' imprisonment and a $250,000 fine.
Secondary reporting (Tech Law Journal) indicates Anderson later pleaded guilty around March 2009 and was sentenced to 21 months in prison, but Diopter could not confirm this specific plea and sentencing detail against a primary DOJ press release or court docket within available research tools, so it should be treated as reported but unverified. Nicholas Shaun Bunch was separately charged in November 2008 (with a companion criminal information filed via the Northern District of Alabama roughly three weeks before Jan. 8, 2009, per Tech Law Journal) with using a T-Mobile customer's name and the last four digits of that customer's Social Security number to obtain the customer's confidential phone records, and was also charged with aggravated identity theft for use of the victim's Social Security number.
Per Wired's contemporaneous reporting, Bunch agreed to plead guilty to both charges and to pay restitution in an amount to be determined by the court, with prosecutors agreeing to recommend a reduced sentence in exchange for his cooperation; however, the final restitution amount, sentence, and any fine actually imposed on Bunch are not documented in the available public record.
These cases matter as the real-world test of whether the law Congress passed in reaction to a marquee corporate-espionage scandal (HP's boardroom pretexting) would actually be used against the everyday pretexting economy: the skip-tracers, private investigators, and individuals who had for years bought and sold confidential phone records through data brokers.
They show that more than two years after the HP scandal exposed how trivially carriers could be fooled by someone who simply supplied a name and a few digits of a Social Security number, that exact technique (Bunch) and a second, entirely different pretext, fabricating official legal process rather than impersonating a customer (Anderson), were still succeeding against T-Mobile and Sprint/Nextel.
For an education audience, the pairing is a clean illustration that pretexting is not one technique but a category: the same underlying goal (extract a confidential record from an institution) can be reached either by social-engineering a live human on a support line or by counterfeiting the institutional paperwork that supposedly compels release, and defenders have to close both doors.
The FCC's 2007 CPNI Order (issued in the same legislative wave as the TRPPA) required carriers to move beyond name/SSN-digit verification: mandatory customer-set passwords for phone-based account access, opt-in consent before sharing call records with joint-venture partners, and delayed/limited disclosure windows after password-reset requests, directly closing the "name plus last-4-of-SSN" verification gap Bunch is alleged to have exploited.
For the Anderson vector (a fabricated court subpoena), the structural defense is a carrier legal-compliance workflow that independently verifies subpoenas/legal process with the issuing court or clerk's office before releasing records, rather than accepting the face validity of a served document; treating "it looks like an official court paper" as sufficient authority was the exploited weakness.
More broadly, both cases illustrate why any process that authenticates a requester using static, breachable personal identifiers (SSN digits, DOB, address) or unverified paper credentials remains pretext-able, and why callback-to-known-number verification, out-of-band confirmation, and document-authenticity checks are the durable countermeasures.
Social Engineering Examples. “Federal Pretexting Prosecutions Post-2006: Bunch and Anderson Charged Under New Anti-Pretexting Statute (2008)”. Accessed 19 September 2026. https://socialengineeringexamples.com/federal-pretexting-prosecutions-bunch-anderson-2008
The public record does not describe exactly how Bunch obtained the victim's name and last four Social Security number digits, or how Anderson produced a document formatted to resemble a genuine U.S. District Court civil subpoena, but pretexting operations of this era typically relied on cheaply available personal data (data brokers, prior breaches, public records) for the name-plus-SSN-digits method, and on copying real court caption formats and case-numbering conventions, which are publicly visible on court filings, for the fake-subpoena method.
The underlying personal data (SSN digits, names) and public court-filing formats are widely available and hard to suppress at the source; the realistic control sits downstream, at Stage 4, where the institution receiving the pretext can be hardened rather than trying to keep this information from ever circulating.
Bunch prepared a verbal script built around presenting himself as the legitimate account holder; Anderson prepared a physical document designed to be facially indistinguishable from a real federal civil subpoena, each pretext tailored to the specific carrier process it targeted.
Because the pretext itself (a rehearsed phone script, a formatted paper document) leaves no trace before delivery, there is no practical pre-delivery control; defenses have to intercept the pretext at delivery and verification, covered in Stages 3 and 4.
Bunch called T-Mobile customer service directly and verbally impersonated the account holder; Anderson instead served his fabricated subpoena on Sprint/Nextel's legal or compliance department, the unit carriers designate to receive and act on legitimate court process, deliberately choosing the channel built for trusted institutional requests rather than a live phone rep.
Restricting which channels can even reach an account or trigger a records release, for example requiring stronger verification for any phone-based CDR request and routing all purported legal process through a single, specifically trained compliance function rather than any inbound channel, narrows the attack surface Bunch and Anderson each exploited.
T-Mobile's phone representatives accepted the victim's name and last four Social Security number digits as sufficient proof of account ownership, per the criminal information; Sprint/Nextel's subpoena-compliance staff accepted the document's face validity as sufficient proof of legal authority, per the indictment; in both cases without an independent, out-of-band check against a source the requester did not control.
This is the core fix illustrated by the case. Per the FCC's 2007 CPNI Order, carriers must not rely on static SSN or DOB-style identifiers for phone-based verification, instead requiring a customer-set password or callback-to-known-number confirmation; for legal process, compliance staff should independently verify subpoenas with the issuing court or clerk's office, calling a number they look up themselves rather than one printed on the document, before releasing any customer data.
Having cleared the carrier's respective checkpoint, both defendants obtained the target's confidential call detail records, the CPNI data Congress had specifically moved to protect via the Telephone Records and Privacy Protection Act of 2006, completing the theft of confidential records that is the core criminal objective in both matters.
Once verification is bypassed, the carrier's own logging and anomaly detection is the backstop, for example flagging a name-plus-SSN request from an unrecognized inbound number or a subpoena whose docket number does not resolve at the stated court, before the disclosure is finalized rather than after.
The available record does not disclose what either defendant did with the phone records after obtaining them (a common downstream use in the pretexting economy of that era was resale to private investigators or data brokers, or direct use for surveillance of the victim, consistent with the objectives Congress cited when passing the statute); the schemes ended when the fraudulent access was identified, leading to federal charges under the newly enacted 18 U.S.C. Section 1039, a criminal information against Bunch and a grand jury indictment against Anderson.
Neither defendant's downstream use of the records nor exactly how the scheme surfaced is documented in the available record, so there is no case-specific control to point to at this final stage; the durable defense remains upstream, at Stage 4's verification chokepoint, since once confidential records leave the carrier undetected, recovery depends on victim reporting or, as happened here, unrelated law-enforcement attention to the broader pretexting and data-broker ecosystem.
Browse by what this case has in common with others in the library.
Between 2006 and 2008 the FTC sued 16 data-broker and private-investigation defendants who pretexted telecom carriers.
The FTC's first-ever case under the FACTA Disposal Rule: a Northbrook, Illinois mortgage lender repeatedly dumped intact customer credit reports.
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
A Pakistani national in Sydney allegedly ran a callback-vishing scheme impersonating Optus and TPG Telecom support.
A scammer posing as GCI's CFO emailed payroll and, after the employee's initial pushback, persuaded them to hand over 2015…
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
A scammer posing as GCI's CFO emailed payroll and, after the employee's initial pushback, persuaded them to hand over 2015…
A Pakistani national in Sydney allegedly ran a callback-vishing scheme impersonating Optus and TPG Telecom support.
A single SMS-phishing campaign lured employees to fake Okta login pages, harvested ~9,931 credentials and 5,441 MFA codes across 136…
Between 2006 and 2008 the FTC sued 16 data-broker and private-investigation defendants who pretexted telecom carriers.
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
An Atlantic City woman posed as a life-insurance/retirement-benefit representative on burner-phone calls to recently widowed elderly victims.
A joint FBI-Dubai Police-Chinese MPS-Royal Thai Police operation arrested 276+ people and dismantled 9 pig-butchering scam compounds abroad.
The FBI's 2025 Internet Crime Report introduced its first dedicated AI-fraud tracking category, logging $893 million in losses.
A single phishing email opened by an Anthem subsidiary employee in Feb 2014 seeded a nation-state intrusion that stole data…
To unmask a boardroom leaker, HP's leak investigators and their hired data brokers impersonated directors and journalists to trick phone…
A US Attorney's Office (EDVA) court order seized seven domains spoofing the Singapore International Monetary Exchange that pig-butchering scammers used.
Vidoc Security Lab, a Polish-founded, US-headquartered cybersecurity startup.
A retired New Jersey man lost $390,000 in two days after a fake Norton/PayPal refund call escalated into a bogus…
Attackers phoned Twitter employees posing as IT help desk, harvested VPN credentials.
A Telegram/dark-web "blackhat ChatGPT" sold $200/month subscriptions promising AI-generated phishing pages, malware and BEC lures.
Toronto podcast-analytics company CoHost spent two months and seven interview rounds with a candidate later revealed as an AI-fabricated persona…
A Tennessee school district's finance director wired $3.36M in state education funds to fraudsters impersonating textbook vendor Pearson from a…