Between 2006 and 2008 the FTC sued 16 data-broker and private-investigation defendants who pretexted telecom carriers, posing as account holders or carrier employees, to obtain consumers' confidential call records and resell them, resulting in permanent injunctions and over $1 million in combined settlements and default-judgment disgorgement.
Reviewed by the Social Engineering Examples team.
Between May 2006 and May 2008 the FTC brought six related civil actions, collectively covering 16 corporate and individual defendants, against data-broker and private-investigation operations that obtained consumers' confidential telephone call records from carriers under false pretenses and resold them to paying clients. The first five complaints (Integrity Security & Investigation Services/Edmund Edmister, Information Search Inc./David Kacala, AccuSearch Inc./Jay Patel, CEO Group Inc./Scott Joseph, and 77 Investigations Inc./Reginald Kimbro) were filed the same day, May 1, 2006, in five different federal district courts. A sixth complaint, against Action Research Group, Inc. and principals Joseph DePante, Matthew DePante, and Bryan Wagner, plus their subcontractor Eye in the Sky Investigations, Inc. and Cassandra Selvage, was filed February 14, 2007 in the Middle District of Florida. The FTC alleged each defendant violated Section 5 of the FTC Act by using false pretenses, impersonating account holders or, in the Action Research/Eye in the Sky matter, carrier employees, to induce phone companies to disclose confidential call detail records, which were then sold as a paid service. Integrity Security additionally used the same pretext technique against banks and credit-card issuers. Two individuals originally named alongside Integrity (Tracey Edmister and F. Lynn Moseley) had their charges dismissed after the FTC determined they had no operational role in the business, leaving the 16-defendant count cited elsewhere in this record. Outcomes varied: Integrity, Information Search, Action Research/DePantes, and CEO Group settled via stipulated final orders with monetary judgments mostly suspended for inability to pay; AccuSearch litigated to a court-ordered permanent injunction and monetary judgment (affirmed on appeal by the Tenth Circuit in 2009); and Bryan Wagner and Eye in the Sky/Selvage, who did not defend, had default judgments entered against them for full disgorgement of ill-gotten gains ($428,085 and $110,762 respectively).
The defendants operated as "information broker" or private-investigation businesses that, for a fee (typically $75-$200 per record set), promised clients they could obtain a target's telephone call detail records, cell records, or (in Integrity's case) bank/credit-card records. To fulfill orders they or their subcontractors called telecom carriers' customer-service lines and used false pretenses to defeat identity verification: claiming to be the account holder, providing partial personal information (name, address, sometimes a guessed or pretexted SSN/last-four) to pass knowledge-based authentication, and in some instances impersonating a carrier employee or third party with a purported legitimate need for the records (e.g., a company representative). Once a carrier representative was convinced, they read, faxed, or emailed the call logs, which the brokers then packaged and resold to the paying client: commonly skip tracers, collection agencies, private investigators, and in some documented cases stalkers or estranged spouses. The scheme relied entirely on exploiting weak phone-based identity verification at the carriers; no technical intrusion or malware was involved.
There was no consumer-facing lure or email in this case. The "pretext" was a live phone script deployed against carrier customer-service representatives, in which the caller claimed to be the account holder (or, in the Action Research/Eye in the Sky matter, a carrier employee) and supplied enough plausible personal details to pass the rep's identity check. The scheme unraveled not because a target spotted a tell, but because the FTC, spurred by the 2006 Hewlett-Packard boardroom pretexting scandal and congressional hearings that same year, opened an investigation into online data brokers advertising "cell phone records" and "reverse cell phone lookup" services, traced the paid orders back to the brokers, and used undercover test purchases and civil investigative demands to document the pretexting methodology before filing suit. The two matters were not merely contemporaneous: Action Research Group defendant Bryan Wagner separately pleaded guilty to federal identity-theft charges arising directly from the HP boardroom spying scandal, and contemporaneous press (AP/Denver Post, InfoWorld, Macworld) covered the FTC's 2008 settlement in this sweep as "FTC settles with PIs in HP spying scandal."
All confirmed defendants were permanently enjoined from pretexting for, obtaining, or selling consumers' confidential telephone (and in Integrity's case, financial) records. Settling defendants (Integrity/Edmister, Information Search/Kacala, Action Research Group/the DePantes, CEO Group/Joseph) entered stipulated final orders with judgments mostly suspended down to token collected amounts based on documented inability to pay ($2,700 to $25,000 actually collected). Defendants who did not appear or defend (Bryan Wagner and Eye in the Sky Investigations/Cassandra Selvage in the Action Research matter) had default judgments entered against them for their full ill-gotten gains ($428,085 and $110,762 respectively). AccuSearch/Jay Patel litigated to a court-ordered permanent injunction and $199,692.71 judgment, which the Tenth Circuit affirmed on appeal (2009-06-29). The sweep, run alongside parallel FTC action against AccuSearch's Abika.com service, was cited by the FTC as establishing that CPNI pretexting violates Section 5 of the FTC Act, and ran concurrently with Congress's passage of the Telephone Records and Privacy Protection Act of 2006, which criminalized the same conduct.
This sweep is a foundational, well-documented case study in "pretexting for hire": a commercial business model built entirely around exploiting weak identity verification at customer-service call centers to extract sensitive records, with no hacking or malware required. It predates and directly foreshadows later techniques such as SIM-swap social engineering, call-center vishing against telecoms/banks, and helpdesk impersonation attacks; the core exploited weakness (agents trusting a caller's self-asserted identity) is unchanged two decades later. The sweep's overlap with the 2006 HP boardroom pretexting scandal was not merely coincidental timing: Action Research Group defendant Bryan Wagner separately pleaded guilty to federal identity-theft charges tied directly to the HP spying affair, and contemporaneous press covered the FTC's 2008 settlement in this matter as the regulatory coda to the HP scandal itself. It also shows the regulatory response pattern: FTC Act Section 5 civil enforcement plus new federal criminal legislation (the Telephone Records and Privacy Protection Act of 2006) and tightened carrier/FCC authentication rules, illustrating how a wave of similar pretexting incidents can drive durable regulatory and industry countermeasures.
Following the sweep and the parallel 2006 congressional/HP pretexting scandal, Congress enacted the Telephone Records and Privacy Protection Act of 2006, making pretexting for phone records a federal crime; the FCC strengthened CPNI rules (47 CFR 64.2010) requiring customer-set passwords/PINs and callback verification before phone carriers may disclose call detail records; carriers tightened customer-service authentication (knowledge-based verification, account PINs, restrictions on online account access changes) to close the exact gap these data brokers exploited; the FTC continued a multi-year enforcement program (this sweep plus related actions against AccuSearch/Abika.com and CEO Group) establishing that obtaining/reselling CPNI via false pretenses violates the FTC Act Section 5, resulting in permanent injunctions against all confirmed defendants.
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
To unmask a boardroom leaker, HP's leak investigators and their hired data brokers impersonated directors and journalists to trick phone…
In the first-ever prosecutions under the federal anti-pretexting statute Congress passed after the 2006 HP boardroom spying scandal, Nicholas Shaun…