Case Library / Pretexting & Impersonation / FTC Pretexting Sweep Against Telephone Record Sellers (2006-2008)

FTC Pretexting Sweep Against Telephone Record Sellers (2006-2008)

Between 2006 and 2008 the FTC sued 16 data-broker and private-investigation defendants who pretexted telecom carriers, posing as account holders or carrier employees, to obtain consumers' confidential call records and resell them, resulting in permanent injunctions and over $1 million in combined settlements and default-judgment disgorgement.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

Between May 2006 and May 2008 the FTC brought six related civil actions, collectively covering 16 corporate and individual defendants, against data-broker and private-investigation operations that obtained consumers' confidential telephone call records from carriers under false pretenses and resold them to paying clients. The first five complaints (Integrity Security & Investigation Services/Edmund Edmister, Information Search Inc./David Kacala, AccuSearch Inc./Jay Patel, CEO Group Inc./Scott Joseph, and 77 Investigations Inc./Reginald Kimbro) were filed the same day, May 1, 2006, in five different federal district courts. A sixth complaint, against Action Research Group, Inc. and principals Joseph DePante, Matthew DePante, and Bryan Wagner, plus their subcontractor Eye in the Sky Investigations, Inc. and Cassandra Selvage, was filed February 14, 2007 in the Middle District of Florida. The FTC alleged each defendant violated Section 5 of the FTC Act by using false pretenses, impersonating account holders or, in the Action Research/Eye in the Sky matter, carrier employees, to induce phone companies to disclose confidential call detail records, which were then sold as a paid service. Integrity Security additionally used the same pretext technique against banks and credit-card issuers. Two individuals originally named alongside Integrity (Tracey Edmister and F. Lynn Moseley) had their charges dismissed after the FTC determined they had no operational role in the business, leaving the 16-defendant count cited elsewhere in this record. Outcomes varied: Integrity, Information Search, Action Research/DePantes, and CEO Group settled via stipulated final orders with monetary judgments mostly suspended for inability to pay; AccuSearch litigated to a court-ordered permanent injunction and monetary judgment (affirmed on appeal by the Tenth Circuit in 2009); and Bryan Wagner and Eye in the Sky/Selvage, who did not defend, had default judgments entered against them for full disgorgement of ill-gotten gains ($428,085 and $110,762 respectively).

How the Attack Worked

The defendants operated as "information broker" or private-investigation businesses that, for a fee (typically $75-$200 per record set), promised clients they could obtain a target's telephone call detail records, cell records, or (in Integrity's case) bank/credit-card records. To fulfill orders they or their subcontractors called telecom carriers' customer-service lines and used false pretenses to defeat identity verification: claiming to be the account holder, providing partial personal information (name, address, sometimes a guessed or pretexted SSN/last-four) to pass knowledge-based authentication, and in some instances impersonating a carrier employee or third party with a purported legitimate need for the records (e.g., a company representative). Once a carrier representative was convinced, they read, faxed, or emailed the call logs, which the brokers then packaged and resold to the paying client: commonly skip tracers, collection agencies, private investigators, and in some documented cases stalkers or estranged spouses. The scheme relied entirely on exploiting weak phone-based identity verification at the carriers; no technical intrusion or malware was involved.

The Lure & the Tell

There was no consumer-facing lure or email in this case. The "pretext" was a live phone script deployed against carrier customer-service representatives, in which the caller claimed to be the account holder (or, in the Action Research/Eye in the Sky matter, a carrier employee) and supplied enough plausible personal details to pass the rep's identity check. The scheme unraveled not because a target spotted a tell, but because the FTC, spurred by the 2006 Hewlett-Packard boardroom pretexting scandal and congressional hearings that same year, opened an investigation into online data brokers advertising "cell phone records" and "reverse cell phone lookup" services, traced the paid orders back to the brokers, and used undercover test purchases and civil investigative demands to document the pretexting methodology before filing suit. The two matters were not merely contemporaneous: Action Research Group defendant Bryan Wagner separately pleaded guilty to federal identity-theft charges arising directly from the HP boardroom spying scandal, and contemporaneous press (AP/Denver Post, InfoWorld, Macworld) covered the FTC's 2008 settlement in this sweep as "FTC settles with PIs in HP spying scandal."

Outcome

All confirmed defendants were permanently enjoined from pretexting for, obtaining, or selling consumers' confidential telephone (and in Integrity's case, financial) records. Settling defendants (Integrity/Edmister, Information Search/Kacala, Action Research Group/the DePantes, CEO Group/Joseph) entered stipulated final orders with judgments mostly suspended down to token collected amounts based on documented inability to pay ($2,700 to $25,000 actually collected). Defendants who did not appear or defend (Bryan Wagner and Eye in the Sky Investigations/Cassandra Selvage in the Action Research matter) had default judgments entered against them for their full ill-gotten gains ($428,085 and $110,762 respectively). AccuSearch/Jay Patel litigated to a court-ordered permanent injunction and $199,692.71 judgment, which the Tenth Circuit affirmed on appeal (2009-06-29). The sweep, run alongside parallel FTC action against AccuSearch's Abika.com service, was cited by the FTC as establishing that CPNI pretexting violates Section 5 of the FTC Act, and ran concurrently with Congress's passage of the Telephone Records and Privacy Protection Act of 2006, which criminalized the same conduct.

Why It Matters

This sweep is a foundational, well-documented case study in "pretexting for hire": a commercial business model built entirely around exploiting weak identity verification at customer-service call centers to extract sensitive records, with no hacking or malware required. It predates and directly foreshadows later techniques such as SIM-swap social engineering, call-center vishing against telecoms/banks, and helpdesk impersonation attacks; the core exploited weakness (agents trusting a caller's self-asserted identity) is unchanged two decades later. The sweep's overlap with the 2006 HP boardroom pretexting scandal was not merely coincidental timing: Action Research Group defendant Bryan Wagner separately pleaded guilty to federal identity-theft charges tied directly to the HP spying affair, and contemporaneous press covered the FTC's 2008 settlement in this matter as the regulatory coda to the HP scandal itself. It also shows the regulatory response pattern: FTC Act Section 5 civil enforcement plus new federal criminal legislation (the Telephone Records and Privacy Protection Act of 2006) and tightened carrier/FCC authentication rules, illustrating how a wave of similar pretexting incidents can drive durable regulatory and industry countermeasures.

Defenses

Following the sweep and the parallel 2006 congressional/HP pretexting scandal, Congress enacted the Telephone Records and Privacy Protection Act of 2006, making pretexting for phone records a federal crime; the FCC strengthened CPNI rules (47 CFR 64.2010) requiring customer-set passwords/PINs and callback verification before phone carriers may disclose call detail records; carriers tightened customer-service authentication (knowledge-based verification, account PINs, restrictions on online account access changes) to close the exact gap these data brokers exploited; the FTC continued a multi-year enforcement program (this sweep plus related actions against AccuSearch/Abika.com and CEO Group) establishing that obtaining/reselling CPNI via false pretenses violates the FTC Act Section 5, resulting in permanent injunctions against all confirmed defendants.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance and target sourcing: Per the FTC complaints, the defendants advertised online (e.g., "cell phone records" and "reverse cell phone lookup" services) and took paid orders directly from clients such as skip tracers, collection agencies, and private investigators who supplied a target's name, phone number, and other identifying details, meaning the initial targeting information typically came from the paying customer rather than from the broker's own research.
Countering Stage 1: A carrier or regulator has little visibility into which paying customers of a data broker are commissioning record requests, so the more effective control sits downstream at Stage 4, hardening the carrier's authentication process itself rather than trying to police who requests records from a broker.
2
Pretext construction: To defeat a carrier's knowledge-based authentication, the brokers or their subcontractors typically assembled enough of a target's personal information, such as name, address, and a real or guessed Social Security number fragment, to plausibly answer a customer-service representative's identity questions, consistent with the FTC's description of "false pretenses, fraudulent statements, fraudulent or stolen documents or other misrepresentations."
Countering Stage 2: Limiting how much personal identifying information (address, partial Social Security numbers) is exposed or guessable for a given phone number reduces the raw material available for building a passable pretext, though this is difficult to fully control given how widely such data circulates among data brokers and prior breaches.
3
Pretext call to the carrier: The caller telephoned the carrier's customer-service line and impersonated either the account holder or, per the Action Research Group/Eye in the Sky complaint, a carrier employee or other party with an ostensible legitimate need, asking the representative to read out or send the account's call detail records.
Countering Stage 3: Carrier customer-service staff trained to treat any request framed as coming from an account holder calling in from an unrecognized number, or from a claimed carrier employee via an external line, as requiring stronger verification before disclosure, closes off the social engineering opening this stage relies on.
4
Exploitation of weak identity verification: Carrier representatives, relying on routine knowledge-based checks rather than a customer-set password or callback verification, accepted the caller's self-asserted identity and disclosed the confidential call records by phone, fax, or email, the exact authentication gap the FTC and FCC later moved to close.
Countering Stage 4: This is the pivotal control point. The FCC's post-sweep CPNI rules (47 CFR 64.2010) requiring customer-set passwords or PINs and callback verification before releasing call detail records, plus carrier-side knowledge-based authentication upgrades, directly close the gap these brokers exploited and are the single most effective countermeasure in the chain.
5
Packaging and resale: The broker compiled the obtained call records into a deliverable and sold them to the paying client for a fee (typically $75 to $200 per record set), completing the transaction that generated the ill-gotten gains later subject to FTC disgorgement.
Countering Stage 5: Federal criminalization of pretexting for phone records under the Telephone Records and Privacy Protection Act of 2006, combined with FTC Section 5 civil enforcement seeking disgorgement of resale proceeds, removes the financial incentive for the resale step by making the ill-gotten gains recoverable and the underlying conduct a federal crime.
Quick Facts
Victim
US consumers whose confidential telephone call records (Customer Proprietary Network Information / CPNI) were obtained without authorization from their carriers and sold to third parties; secondarily, the telecom carriers whose customer-service identity checks were defeated
Location
United States. Cases filed in U.S. District Courts for the Eastern District of Virginia (Newport News), District of Maryland (Northern Division), Middle District of Florida (Orlando), District of Wyoming, Southern District of Florida, and Central District of California
Date
2006-05-01 to 2008-05-28 (FTC complaints filed 2006-05-01 and 2007-02-14; settlements and default judgments entered from 2006-10-05 through 2008-05-28)
Impact
Verified monetary judgments across confirmed sweep defendants (from primary FTC complaint/order documents) total approximately $1,070,695.71 combined: Integrity Security & Investigation Services/Edmund Edmister $2,700 (paid in full, described by FTC as entire ill-gotten gains); Information Search Inc./David Kacala $40,075 judgment with all but $3,000 suspended for inability to pay; Action Research Group/Joseph & Matthew DePante $67,000 judgment with all but $3,000 suspended; Bryan Wagner (Action Research) $428,085 disgorgement via default judgment; Eye in the Sky Investigations/Cassandra Selvage $110,762 disgorgement via default judgment; CEO Group/Scott Joseph $222,381 judgment with all but $25,000 suspended; AccuSearch Inc./Jay Patel $199,692.71 monetary judgment (affirmed on appeal by the Tenth Circuit, 2009-06-29). No verified monetary figure was located in primary sources for the 16th defendant, 77 Investigations/Reginald Kimbro. Actual cash collected was far below the nominal totals because most judgments were suspended based on defendants' documented inability to pay.
Status
Confirmed
Case Type
Real-World Incident
Sector
Government & Public Sector, Professional & Business Services, Telecommunications
Threat Actor
Organized Crime
Related

Related Cases

Gen. Wesley Clark Phone Records Pretexting Incident (2005-2006)

A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…

Incident 2005Read →

Hewlett-Packard Boardroom "Pretexting" Spying Scandal (2006)

To unmask a boardroom leaker, HP's leak investigators and their hired data brokers impersonated directors and journalists to trick phone…

Incident 2005Read →

Federal Pretexting Prosecutions Post-2006: Bunch and Anderson Charged Under New Anti-Pretexting Statute (2008)

In the first-ever prosecutions under the federal anti-pretexting statute Congress passed after the 2006 HP boardroom spying scandal, Nicholas Shaun…

Incident 2008Read →