Between 2006 and 2008 the FTC sued 16 data-broker and private-investigation defendants who pretexted telecom carriers.
Social Engineering Examples·20 sources
Between May 2006 and May 2008 the FTC brought six related civil actions, collectively covering 16 corporate and individual defendants, against data-broker and private-investigation operations that obtained consumers' confidential telephone call records from carriers under false pretenses and resold them to paying clients. The first five complaints (Integrity Security & Investigation Services/Edmund Edmister, Information Search Inc./David Kacala, AccuSearch Inc./Jay Patel, CEO Group Inc./Scott Joseph, and 77 Investigations Inc./Reginald Kimbro) were filed the same day, May 1, 2006, in five different federal district courts.
A sixth complaint, against Action Research Group, Inc. and principals Joseph DePante, Matthew DePante, and Bryan Wagner, plus their subcontractor Eye in the Sky Investigations, Inc. and Cassandra Selvage, was filed February 14, 2007 in the Middle District of Florida. The FTC alleged each defendant violated Section 5 of the FTC Act by using false pretenses, impersonating account holders or, in the Action Research/Eye in the Sky matter, carrier employees, to induce phone companies to disclose confidential call detail records, which were then sold as a paid service.
Integrity Security additionally used the same pretext technique against banks and credit-card issuers. Two individuals originally named alongside Integrity (Tracey Edmister and F. Lynn Moseley) had their charges dismissed after the FTC determined they had no operational role in the business, leaving the 16-defendant count cited elsewhere in this record.
Outcomes varied: Integrity, Information Search, Action Research/DePantes, and CEO Group settled via stipulated final orders with monetary judgments mostly suspended for inability to pay; AccuSearch litigated to a court-ordered permanent injunction and monetary judgment (affirmed on appeal by the Tenth Circuit in 2009); and Bryan Wagner and Eye in the Sky/Selvage, who did not defend, had default judgments entered against them for full disgorgement of ill-gotten gains ($428,085 and $110,762 respectively).
The defendants operated as "information broker" or private-investigation businesses that, for a fee (typically $75-$200 per record set), promised clients they could obtain a target's telephone call detail records, cell records, or (in Integrity's case) bank/credit-card records. To fulfill orders they or their subcontractors called telecom carriers' customer-service lines and used false pretenses to defeat identity verification: claiming to be the account holder, providing partial personal information (name, address, sometimes a guessed or pretexted SSN/last-four) to pass knowledge-based authentication, and in some instances impersonating a carrier employee or third party with a purported legitimate need for the records (e.g., a company representative).
Once a carrier representative was convinced, they read, faxed, or emailed the call logs, which the brokers then packaged and resold to the paying client: commonly skip tracers, collection agencies, private investigators, and in some documented cases stalkers or estranged spouses. The scheme relied entirely on exploiting weak phone-based identity verification at the carriers; no technical intrusion or malware was involved.
There was no consumer-facing lure or email in this case. The "pretext" was a live phone script deployed against carrier customer-service representatives, in which the caller claimed to be the account holder (or, in the Action Research/Eye in the Sky matter, a carrier employee) and supplied enough plausible personal details to pass the rep's identity check.
The scheme unraveled not because a target spotted a tell, but because the FTC, spurred by the 2006 Hewlett-Packard boardroom pretexting scandal and congressional hearings that same year, opened an investigation into online data brokers advertising "cell phone records" and "reverse cell phone lookup" services, traced the paid orders back to the brokers, and used undercover test purchases and civil investigative demands to document the pretexting methodology before filing suit.
The two matters were not merely contemporaneous: Action Research Group defendant Bryan Wagner separately pleaded guilty to federal identity-theft charges arising directly from the HP boardroom spying scandal, and contemporaneous press (AP/Denver Post, InfoWorld, Macworld) covered the FTC's 2008 settlement in this sweep as "FTC settles with PIs in HP spying scandal."
All confirmed defendants were permanently enjoined from pretexting for, obtaining, or selling consumers' confidential telephone (and in Integrity's case, financial) records. Settling defendants (Integrity/Edmister, Information Search/Kacala, Action Research Group/the DePantes, CEO Group/Joseph) entered stipulated final orders with judgments mostly suspended down to token collected amounts based on documented inability to pay ($2,700 to $25,000 actually collected).
Defendants who did not appear or defend (Bryan Wagner and Eye in the Sky Investigations/Cassandra Selvage in the Action Research matter) had default judgments entered against them for their full ill-gotten gains ($428,085 and $110,762 respectively). AccuSearch/Jay Patel litigated to a court-ordered permanent injunction and $199,692.71 judgment, which the Tenth Circuit affirmed on appeal (2009-06-29).
The sweep, run alongside parallel FTC action against AccuSearch's Abika.com service, was cited by the FTC as establishing that CPNI pretexting violates Section 5 of the FTC Act, and ran concurrently with Congress's passage of the Telephone Records and Privacy Protection Act of 2006, which criminalized the same conduct.
This sweep is a foundational, well-documented case study in "pretexting for hire": a commercial business model built entirely around exploiting weak identity verification at customer-service call centers to extract sensitive records, with no hacking or malware required. It predates and directly foreshadows later techniques such as SIM-swap social engineering, call-center vishing against telecoms/banks, and helpdesk impersonation attacks; the core exploited weakness (agents trusting a caller's self-asserted identity) is unchanged two decades later.
The sweep's overlap with the 2006 HP boardroom pretexting scandal was not merely coincidental timing: Action Research Group defendant Bryan Wagner separately pleaded guilty to federal identity-theft charges tied directly to the HP spying affair, and contemporaneous press covered the FTC's 2008 settlement in this matter as the regulatory coda to the HP scandal itself.
It also shows the regulatory response pattern: FTC Act Section 5 civil enforcement plus new federal criminal legislation (the Telephone Records and Privacy Protection Act of 2006) and tightened carrier/FCC authentication rules, illustrating how a wave of similar pretexting incidents can drive durable regulatory and industry countermeasures.
Following the sweep and the parallel 2006 congressional/HP pretexting scandal, Congress enacted the Telephone Records and Privacy Protection Act of 2006, making pretexting for phone records a federal crime; the FCC strengthened CPNI rules (47 CFR 64.2010) requiring customer-set passwords/PINs and callback verification before phone carriers may disclose call detail records; carriers tightened customer-service authentication (knowledge-based verification, account PINs, restrictions on online account access changes) to close the exact gap these data brokers exploited; the FTC continued a multi-year enforcement program (this sweep plus related actions against AccuSearch/Abika.com and CEO Group) establishing that obtaining/reselling CPNI via false pretenses violates the FTC Act Section 5, resulting in permanent injunctions against all confirmed defendants.
Social Engineering Examples. “FTC Pretexting Sweep Against Telephone Record Sellers (2006-2008)”. Accessed 19 September 2026. https://socialengineeringexamples.com/ftc-pretexting-sweep-telephone-record-sellers-2006-2008
Per the FTC complaints, the defendants advertised online (e.g., "cell phone records" and "reverse cell phone lookup" services) and took paid orders directly from clients such as skip tracers, collection agencies, and private investigators who supplied a target's name, phone number, and other identifying details, meaning the initial targeting information typically came from the paying customer rather than from the broker's own research.
A carrier or regulator has little visibility into which paying customers of a data broker are commissioning record requests, so the more effective control sits downstream at Stage 4, hardening the carrier's authentication process itself rather than trying to police who requests records from a broker.
To defeat a carrier's knowledge-based authentication, the brokers or their subcontractors typically assembled enough of a target's personal information, such as name, address, and a real or guessed Social Security number fragment, to plausibly answer a customer-service representative's identity questions, consistent with the FTC's description of "false pretenses, fraudulent statements, fraudulent or stolen documents or other misrepresentations."
Limiting how much personal identifying information (address, partial Social Security numbers) is exposed or guessable for a given phone number reduces the raw material available for building a passable pretext, though this is difficult to fully control given how widely such data circulates among data brokers and prior breaches.
The caller telephoned the carrier's customer-service line and impersonated either the account holder or, per the Action Research Group/Eye in the Sky complaint, a carrier employee or other party with an ostensible legitimate need, asking the representative to read out or send the account's call detail records.
Carrier customer-service staff trained to treat any request framed as coming from an account holder calling in from an unrecognized number, or from a claimed carrier employee via an external line, as requiring stronger verification before disclosure, closes off the social engineering opening this stage relies on.
Carrier representatives, relying on routine knowledge-based checks rather than a customer-set password or callback verification, accepted the caller's self-asserted identity and disclosed the confidential call records by phone, fax, or email, the exact authentication gap the FTC and FCC later moved to close.
This is the pivotal control point. The FCC's post-sweep CPNI rules (47 CFR 64.2010) requiring customer-set passwords or PINs and callback verification before releasing call detail records, plus carrier-side knowledge-based authentication upgrades, directly close the gap these brokers exploited and are the single most effective countermeasure in the chain.
The broker compiled the obtained call records into a deliverable and sold them to the paying client for a fee (typically $75 to $200 per record set), completing the transaction that generated the ill-gotten gains later subject to FTC disgorgement.
Federal criminalization of pretexting for phone records under the Telephone Records and Privacy Protection Act of 2006, combined with FTC Section 5 civil enforcement seeking disgorgement of resale proceeds, removes the financial incentive for the resale step by making the ill-gotten gains recoverable and the underlying conduct a federal crime.
Browse by what this case has in common with others in the library.
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
To unmask a boardroom leaker, HP's leak investigators and their hired data brokers impersonated directors and journalists to trick phone…
In the first-ever prosecutions under the federal anti-pretexting statute Congress passed after the 2006 HP boardroom spying scandal.
A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool…
Fraudsters built a fake WhatsApp profile of WPP CEO Mark Read and staged a Microsoft Teams call using an AI…
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
Air Canada admitted in a sworn Ontario Superior Court affidavit that it hired private investigators who twice took trash from…
Two New Jersey men ran US "laptop farms" and shell companies that let North Korean IT workers pose as American…
A Bengaluru retiree lost Rs 6.88 lakh after an AI-generated deepfake Facebook video falsely showed Finance Minister Nirmala Sitharaman endorsing…
A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool…
An Atlantic City woman posed as a life-insurance/retirement-benefit representative on burner-phone calls to recently widowed elderly victims.
Censys researchers used passive DNS to unravel a live USPS/UPS "package awaiting action" smishing operation.
Chinese state-linked hackers used spear-phishing links and an unpatched Internet Explorer zero-day to breach Google, Adobe.
A small Columbus, Ohio manufacturer disclosed in a February 2026 SEC 8-K that it lost $898,325 to an imposter scam…
Scammers hijacked a real invoice thread between an Arkansas school district, its contractor, and its architect.
DOJ/IRS-CI unsealed four indictments charging 28 members of a Chinese organized-crime money-laundering ring tied to India-based "mistaken refund".
Scammers impersonating PG&E threaten customers and small businesses with immediate service disconnection.
Scammers impersonating Southern California Edison used real-time-negotiated "pay now or we shut off your power in 30 minutes" phone and…
Two Quebec fraudsters acting as courier and driver for an AI-voice-cloned "grandchild in crisis" vishing scheme that defrauded Saskatchewan seniors.
Tejay Fletcher founded and ran iSpoof, a Bitcoin-subscription caller-ID spoofing and OTP-interception platform that let fraudsters impersonate bank.
A single compromised Microsoft employee account gave LAPSUS$ (DEV-0537) "limited access" to an Azure DevOps repository.
A Dominican Republic call-center network ran a multi-role "grandparent"/"family-in-need-of-bail" scam: openers posed as a distressed grandchild.
A four-man Manhattan fraud ring compromised a nonprofit CFO's and a portfolio company employee's business email accounts to redirect $3.49M…
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…