Case Library / Phishing / Hewlett-Packard Boardroom "Pretexting" Spying Scandal (2006)

Hewlett-Packard Boardroom "Pretexting" Spying Scandal (2006)

To unmask a boardroom leaker, HP's leak investigators and their hired data brokers impersonated directors and journalists to trick phone carriers into handing over private call records, triggering a congressional hearing and California felony charges.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

Beginning in April 2005 (an investigation code-named "Kona I," renewed as "Kona II" in January 2006), Hewlett-Packard's leadership set out to find which director was leaking confidential board discussions to the press. The effort was ordered by Chairwoman Patricia Dunn, overseen day-to-day by chief ethics officer Kevin Hunsaker, and known to General Counsel Ann Baskins. HP retained an outside security firm (Security Outsourcing Solutions), which subcontracted a data-brokerage operation (Action Research Group), which in turn used a contractor, Bryan Wagner, to obtain targets' private telephone records.

Rather than subpoena the records, the investigators used "pretexting": pretending to be the account holders to fool telephone carriers into releasing confidential billing and call logs. Wagner later admitted that on March 8, 2006 he set up an online telephone-service account in the name of a Wall Street Journal reporter and used the reporter's Social Security number to reach that reporter's call records. The California criminal complaint said false pretenses were used to obtain phone-company records on 12 individuals; press accounts citing the complaint said records of roughly 1,750 phone calls across 157 cell phones and 413 landlines were compiled, and that more than two dozen people were compromised. The probe also included physical surveillance of directors and journalists and a "tracer"/beacon email sting sent to a reporter.

The scheme unraveled from inside the boardroom: director Tom Perkins resigned in May 2006 in protest and pressed HP to disclose why. HP reported the pretexting to the SEC in a filing at the end of August 2006, setting off a media firestorm. On September 28, 2006 the House Energy and Commerce Committee's Subcommittee on Oversight and Investigations held a hearing titled "Hewlett-Packard's Pretexting Scandal"; Dunn and CEO Mark Hurd testified, while numerous investigators and contractors invoked the Fifth Amendment. Notably, an internal warning existed: HP investigator Vince Nye had emailed superiors saying he had "serious reservations" and asking that the phone-number-gathering method cease immediately.

On October 4, 2006, California Attorney General Bill Lockyer filed four felony counts each against Dunn, Hunsaker, DeLia, DePante, and Wagner. HP settled the state's civil complaint for $14.5M on December 7, 2006. Wagner pleaded guilty to federal conspiracy and aggravated-identity-theft charges in January 2007 and cooperated. In March 2007 a judge dismissed the charges against Dunn (who had cancer) and allowed the remaining defendants' charges to be reduced to a misdemeanor conditioned on community service, so the case ended with only Wagner's federal conviction.

How the Attack Worked

At an awareness level, the con worked because the phone carriers verified callers by knowledge of the account holder's personal details rather than by any strong, out-of-band proof of identity. Kill-chain view: (1) Recon: investigators collected targets' names, home/cell/office numbers, and Social Security numbers; Dunn herself supplied board members' numbers to the investigator. (2) Pretext: a caller (or someone creating an online self-service account) posed as the legitimate subscriber. (3) Exploitation: presenting the "right" identifying data, the impersonator satisfied the carrier's routine identity check and was treated as the customer. (4) Exfiltration: the carrier released billing and call-detail records, which flowed back up the contractor chain to HP. The chain of deniability (company to security firm to data broker to individual contractor) is exactly what let senior executives claim they didn't know the methods were illegal, and what prosecutors said made those who kept using the results culpable. The point for defenders is that "we just confirmed some info the person already knew" is not authentication.

The Lure & the Tell

The pretext was mundane by design: a call or online-account setup in which someone claimed to be the account holder and recited enough personal data (name, phone number, and Social Security number) to look legitimate to a support rep. Red flags visible in hindsight: requests for another person's full call history routed through third-party "data brokers"; identity "verification" that relied only on knowable data (SSN, address, phone number) with no callback to a number on file or other out-of-band check; investigators unwilling to use lawful process (a subpoena) to obtain the same records; and an internal expert explicitly warning in writing that the method should stop. As a lawmaker put it to Dunn, no ordinary person would simply hand over their phone records to a stranger who called and asked.

Outcome

HP disclosed the conduct to the SEC (late August / early September 2006), Dunn was forced out as chairwoman, and General Counsel Ann Baskins resigned. A September 28, 2006 congressional hearing spotlighted the practice. California AG Lockyer filed felony charges against five defendants on October 4, 2006; HP settled the state's civil case for $14.5M on December 7, 2006 without admitting liability and agreed to five years of governance/investigation reforms (new chief ethics/compliance officer, vendor conduct standards, board oversight). Contractor Bryan Wagner pleaded guilty to federal conspiracy and aggravated identity theft in January 2007; his state charges were dropped as duplicative. In March 2007, charges against Dunn were dismissed and the remaining defendants' charges reduced to a misdemeanor with 96 hours of community service. The episode helped drive federal and state legislation against phone-record pretexting (the Telephone Records and Privacy Protection Act of 2006).

Why It Matters

This is the landmark corporate-America pretexting case: it showed that "social engineering" is not just a hacker technique but a business risk that can implicate a company's own chairwoman, general counsel, and chief ethics officer, and that outsourcing dirty work to contractors does not insulate leaders who use the results. It demonstrates that knowledge-based verification (SSN, address, phone number) is trivially defeated by impersonation, and it directly motivated a federal law criminalizing the fraudulent acquisition of phone records. For an awareness audience it is a clean illustration of pretexting against a help-desk, plus the governance lesson that a written internal warning ("please stop, this may be illegal") must be escalated, not ignored.

Defenses

Carrier/help-desk side: authenticate account-record requests with out-of-band factors (callback to the number on file, one-time codes, or documented account PINs) rather than knowledge of SSN/address alone; flag and rate-limit third-party or bulk record requests; require lawful process for release of another person's records. Organizational side: any investigation touching third parties' personal data should route through counsel and use lawful discovery (subpoenas), with written standards for outside investigators and contractual bans on deceptive methods; treat an employee's ethics/legal warning as a mandatory stop-and-escalate trigger; separate duties so no single "deniable" contractor chain can obtain sensitive data unchecked. Individual side: set a spoken/PIN password on telecom and financial accounts so knowing your SSN is not enough to impersonate you.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Target identification and PII gathering: HP's leadership and investigators built a target list of directors and journalists suspected of leaking or receiving boardroom information, then compiled each target's name, home/cell/office phone numbers, and in several cases Social Security numbers, drawing on a mix of insider knowledge (Dunn herself supplied board members' phone numbers to the lead investigator) and the kind of commercially available personal-data lookup services typically used by data-broker and skip-tracing operations.
Countering Stage 1: Personal contact information for directors, executives, and reporters is very hard to fully suppress, so the realistic control is procedural: require that any internal investigation compiling personal data on a director, employee, or journalist be logged and pre-approved by legal/compliance before OSINT or data-broker lookups begin, rather than left to a security team's informal judgment.
2
Vendor-chain layering: HP retained an outside security firm (Security Outsourcing Solutions), which subcontracted a Florida data-brokerage firm (Action Research Group), which in turn engaged an individual contractor (Bryan Wagner) to perform the actual pretext calls and account creation, a layered outsourcing structure consistent with how organizations conducting ethically or legally risky work distance the principal from the party actually doing it.
Countering Stage 2: This is the structural weak point the case turned on. Requiring outside investigative vendors to disclose and get approval for any further subcontracting, and contractually banning deceptive or pretexting methods with audit rights, closes the plausible-deniability gap that let senior executives claim distance from the methods actually used.
3
Pretext construction: using the PII gathered in Stage 1, the contractor prepared to impersonate the legitimate subscriber, assembling the same name, phone number, and Social Security number a real customer would be able to recite to a carrier's support channel.
Countering Stage 3: Treat knowledge-based identifiers (SSN, address, date of birth, phone number) as inherently compromise-prone rather than as secrets, both inside the organization's own vendor-vetting process and in guidance to individuals, since a pretext built entirely from such data should not be assumed to be hard to construct.
4
Impersonation of the carrier's self-service/support channel: the contractor called the phone carrier or created an online self-service account posing as the target, presenting the gathered identifying details, which the carrier accepted as sufficient proof of identity to treat the impersonator as the account holder.
Countering Stage 4: This is the core, most fixable control: carriers should authenticate account-holder requests with out-of-band factors, a callback to the number on file, a one-time passcode, or a dedicated account PIN, rather than accepting recited SSN, address, or phone number as sufficient proof of identity.
5
Data exfiltration: once granted account access, the impersonator retrieved the target's detailed billing statements and call logs (numbers dialed, dates, durations), which were then passed back up the contractor chain from Wagner to ARG to SOS to HP's investigators.
Countering Stage 5: Carriers can flag and rate-limit newly created self-service accounts that immediately pull full call-detail history, and require lawful process (a subpoena) before releasing another person's records to any third-party requester rather than to the account holder alone.
6
Supplementary tradecraft: in parallel with the phone-record pretexting, investigators reportedly used physical surveillance (tailing directors and journalists, examining trash) and sent at least one tracer/beacon email designed to reveal identifying information about a reporter when opened, broadening the intelligence picture beyond phone records alone.
Countering Stage 6: There is no practical technical control a target can deploy against a company's own investigators secretly conducting physical surveillance or sending a tracer email; the realistic defense is the same governance control as Stage 2, contractual bans on deceptive or intrusive investigative tactics plus mandatory legal-counsel sign-off before any such investigation begins, since detecting covert surveillance in the moment is nearly impossible for the person being watched.
7
Analysis and attribution: HP's investigation team cross-referenced the stolen call logs and other gathered intelligence against known contacts and published stories to identify which director's communications pattern matched a leaked report, ultimately attributing the leaks to director George Keyworth II.
Countering Stage 7: Analysis of already-stolen records can't be defended against after the fact; the effective control is upstream escalation discipline. HP investigator Vince Nye's written objection that the method should stop is exactly the signal an organization needs to treat as a mandatory stop-work trigger reviewed by legal/compliance, not something a manager can quietly overrule and continue past.
8
Objective completion and fallout: HP used the attribution to move against the identified leaker (he was not renominated to the board), but the surveillance program itself, once it became known internally and was escalated by director Tom Perkins, became the far larger liability, leading to HP's own SEC disclosure, a congressional hearing, felony charges, and a multimillion-dollar settlement.
Countering Stage 8: Once an unlawful surveillance program's output has been used to make personnel decisions, the harm is largely done, so the effective control at this stage is deterrence and accountability after the fact: mandatory disclosure obligations (here, SEC reporting), personal liability for executives who knowingly use results obtained illegally, and dedicated statutes such as the Telephone Records and Privacy Protection Act of 2006 that this case helped drive, which criminalize the underlying pretexting conduct so it carries real legal risk the next time.
Quick Facts
Victim
Hewlett-Packard board members (including Tom Perkins and George "Jay" Keyworth II), journalists covering HP (among them Pui-Wing Tam of The Wall Street Journal and Dawn Kawamoto of CNET News.com), HP employees, and family members of those targeted. HP itself was both the instigator and, ultimately, the corporate defendant.
Location
Palo Alto / Santa Clara County, California, USA (contractors operating from Massachusetts, Florida, and Colorado)
Date
2005-04
Impact
$14.5M USD (December 2006 civil settlement with the California Attorney General: $13.5M to a new state Privacy and Piracy Fund, $650,000 civil penalties, $350,000 investigation costs; no admission of liability). Separate reputational and governance fallout; a shareholder suit also targeted ~$40M in executive stock sales around the disclosure.
Status
Confirmed
Case Type
Real-World Incident
Sector
Media & Entertainment, Technology & Software
Threat Actor
Corporate / Competitive Intelligence
Related

Related Cases

Gen. Wesley Clark Phone Records Pretexting Incident (2005-2006)

A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…

Incident 2005Read →

Stuxnet: USB-borne sabotage of Iran's air-gapped Natanz enrichment plant

A nation-state cyberweapon crossed an air gap into Iran's Natanz nuclear facility on infected USB drives carried in by trusted…

Incident 2010Read →

RSA SecurID Breach: The "2011 Recruitment Plan" Spear-Phishing Email (2011)

A single spear-phishing email titled "2011 Recruitment Plan," with a booby-trapped Excel attachment, breached security giant RSA and led to…

Incident 2011Read →