To unmask a boardroom leaker, HP's leak investigators and their hired data brokers impersonated directors and journalists to trick phone carriers into handing over private call records, triggering a congressional hearing and California felony charges.
Reviewed by the Social Engineering Examples team.
Beginning in April 2005 (an investigation code-named "Kona I," renewed as "Kona II" in January 2006), Hewlett-Packard's leadership set out to find which director was leaking confidential board discussions to the press. The effort was ordered by Chairwoman Patricia Dunn, overseen day-to-day by chief ethics officer Kevin Hunsaker, and known to General Counsel Ann Baskins. HP retained an outside security firm (Security Outsourcing Solutions), which subcontracted a data-brokerage operation (Action Research Group), which in turn used a contractor, Bryan Wagner, to obtain targets' private telephone records.
Rather than subpoena the records, the investigators used "pretexting": pretending to be the account holders to fool telephone carriers into releasing confidential billing and call logs. Wagner later admitted that on March 8, 2006 he set up an online telephone-service account in the name of a Wall Street Journal reporter and used the reporter's Social Security number to reach that reporter's call records. The California criminal complaint said false pretenses were used to obtain phone-company records on 12 individuals; press accounts citing the complaint said records of roughly 1,750 phone calls across 157 cell phones and 413 landlines were compiled, and that more than two dozen people were compromised. The probe also included physical surveillance of directors and journalists and a "tracer"/beacon email sting sent to a reporter.
The scheme unraveled from inside the boardroom: director Tom Perkins resigned in May 2006 in protest and pressed HP to disclose why. HP reported the pretexting to the SEC in a filing at the end of August 2006, setting off a media firestorm. On September 28, 2006 the House Energy and Commerce Committee's Subcommittee on Oversight and Investigations held a hearing titled "Hewlett-Packard's Pretexting Scandal"; Dunn and CEO Mark Hurd testified, while numerous investigators and contractors invoked the Fifth Amendment. Notably, an internal warning existed: HP investigator Vince Nye had emailed superiors saying he had "serious reservations" and asking that the phone-number-gathering method cease immediately.
On October 4, 2006, California Attorney General Bill Lockyer filed four felony counts each against Dunn, Hunsaker, DeLia, DePante, and Wagner. HP settled the state's civil complaint for $14.5M on December 7, 2006. Wagner pleaded guilty to federal conspiracy and aggravated-identity-theft charges in January 2007 and cooperated. In March 2007 a judge dismissed the charges against Dunn (who had cancer) and allowed the remaining defendants' charges to be reduced to a misdemeanor conditioned on community service, so the case ended with only Wagner's federal conviction.
At an awareness level, the con worked because the phone carriers verified callers by knowledge of the account holder's personal details rather than by any strong, out-of-band proof of identity. Kill-chain view: (1) Recon: investigators collected targets' names, home/cell/office numbers, and Social Security numbers; Dunn herself supplied board members' numbers to the investigator. (2) Pretext: a caller (or someone creating an online self-service account) posed as the legitimate subscriber. (3) Exploitation: presenting the "right" identifying data, the impersonator satisfied the carrier's routine identity check and was treated as the customer. (4) Exfiltration: the carrier released billing and call-detail records, which flowed back up the contractor chain to HP. The chain of deniability (company to security firm to data broker to individual contractor) is exactly what let senior executives claim they didn't know the methods were illegal, and what prosecutors said made those who kept using the results culpable. The point for defenders is that "we just confirmed some info the person already knew" is not authentication.
The pretext was mundane by design: a call or online-account setup in which someone claimed to be the account holder and recited enough personal data (name, phone number, and Social Security number) to look legitimate to a support rep. Red flags visible in hindsight: requests for another person's full call history routed through third-party "data brokers"; identity "verification" that relied only on knowable data (SSN, address, phone number) with no callback to a number on file or other out-of-band check; investigators unwilling to use lawful process (a subpoena) to obtain the same records; and an internal expert explicitly warning in writing that the method should stop. As a lawmaker put it to Dunn, no ordinary person would simply hand over their phone records to a stranger who called and asked.
HP disclosed the conduct to the SEC (late August / early September 2006), Dunn was forced out as chairwoman, and General Counsel Ann Baskins resigned. A September 28, 2006 congressional hearing spotlighted the practice. California AG Lockyer filed felony charges against five defendants on October 4, 2006; HP settled the state's civil case for $14.5M on December 7, 2006 without admitting liability and agreed to five years of governance/investigation reforms (new chief ethics/compliance officer, vendor conduct standards, board oversight). Contractor Bryan Wagner pleaded guilty to federal conspiracy and aggravated identity theft in January 2007; his state charges were dropped as duplicative. In March 2007, charges against Dunn were dismissed and the remaining defendants' charges reduced to a misdemeanor with 96 hours of community service. The episode helped drive federal and state legislation against phone-record pretexting (the Telephone Records and Privacy Protection Act of 2006).
This is the landmark corporate-America pretexting case: it showed that "social engineering" is not just a hacker technique but a business risk that can implicate a company's own chairwoman, general counsel, and chief ethics officer, and that outsourcing dirty work to contractors does not insulate leaders who use the results. It demonstrates that knowledge-based verification (SSN, address, phone number) is trivially defeated by impersonation, and it directly motivated a federal law criminalizing the fraudulent acquisition of phone records. For an awareness audience it is a clean illustration of pretexting against a help-desk, plus the governance lesson that a written internal warning ("please stop, this may be illegal") must be escalated, not ignored.
Carrier/help-desk side: authenticate account-record requests with out-of-band factors (callback to the number on file, one-time codes, or documented account PINs) rather than knowledge of SSN/address alone; flag and rate-limit third-party or bulk record requests; require lawful process for release of another person's records. Organizational side: any investigation touching third parties' personal data should route through counsel and use lawful discovery (subpoenas), with written standards for outside investigators and contractual bans on deceptive methods; treat an employee's ethics/legal warning as a mandatory stop-and-escalate trigger; separate duties so no single "deniable" contractor chain can obtain sensitive data unchecked. Individual side: set a spoken/PIN password on telecom and financial accounts so knowing your SSN is not enough to impersonate you.
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
A nation-state cyberweapon crossed an air gap into Iran's Natanz nuclear facility on infected USB drives carried in by trusted…
A single spear-phishing email titled "2011 Recruitment Plan," with a booby-trapped Excel attachment, breached security giant RSA and led to…