Case Library / Pretexting & Impersonation / Kevin Mitnick's Pretexting of Novell Tech Support (NetWare Source Code Theft)

Kevin Mitnick's Pretexting of Novell Tech Support (NetWare Source Code Theft)

Fugitive hacker Kevin Mitnick impersonated a vacationing Novell employee on a "top-secret" project, defeated a support analyst's voicemail-based identity check by first hijacking that employee's voicemail, and talked his way into a dial-in account used to steal Novell NetWare source code.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

While a fugitive living under a false identity in Denver, Colorado (holding a day job at a law firm), Kevin Mitnick targeted Novell, Inc.'s technical support and network staff by phone to obtain NetWare source code. Having done reconnaissance on Novell's staff and internal projects, Mitnick impersonated a real Novell employee who was on vacation, calling Novell's wide-area-networking department and requesting direct inbound dial-up access to the company network, citing an urgent need to make changes to a genuine internal project ("Snowbird") while away. The WAN engineer on duty referred the request to Shawn Nunley, the only person authorized to create such dial-in accounts. Mitnick called Nunley, including at home, and Nunley, suspicious that the request skipped required manager approval and the company's secure callback dial-in policy, asked him to first leave a voicemail on the impersonated employee's office extension as proof. Mitnick had already, via a separate earlier pretext call, obtained that employee's voicemail password from a Novell telecom staffer and rerecorded the greeting to match the vacation story. Satisfied by the voicemail, Nunley created the dial-in account; Mitnick immediately used it to connect into Novell's network and copy proprietary NetWare source code. Nunley preserved the voicemail on a cassette tape, which became the key evidence in the eventual federal prosecution and made him the government's star witness. The Novell intrusion was folded into a broader 25-count federal indictment (U.S. v. Mitnick, CR 96-881 MRP, C.D. Cal.) covering multiple corporate victims (Novell, Nokia, Motorola, Fujitsu, NEC, Sun, USC) for wire fraud, computer fraud, illegal interception of communications, and possession of unauthorized access devices.

How the Attack Worked

Mitnick's approach combined reconnaissance with a two-stage phone pretext rather than any technical exploit. He first gathered real internal details on Novell (employee names, the name of an actual internal project, technical jargon) so he could speak convincingly as an insider. He impersonated a specific real Novell employee who was on vacation, calling Novell's wide-area-networking department and asking for direct inbound dial-up access, claiming an urgent need to make emergency changes to a genuine internal project while away from the office. The WAN engineer routed the request to Shawn Nunley, the only staffer authorized to create dial-in accounts, and Mitnick called Nunley directly, including once at his home at night. Nunley sensed the request was abnormal (it bypassed the required manager approval and Novell's secure callback-based dial system) and, instead of granting access outright, asked Mitnick to leave a corroborating voicemail on the impersonated employee's office extension. Mitnick had anticipated this: in an earlier, separate pretext call, he had persuaded a Novell telecom staffer to hand over that employee's voicemail password, then rerecorded the greeting himself, referencing the same vacation location the "employee" had mentioned to Nunley. When Nunley checked the voicemail and it matched, he created the dial-in account. Mitnick then dialed in immediately and began copying Novell NetWare source code to a machine outside the company, having earlier also convinced a different Novell engineer to move a compressed copy of the source code to a more accessible server. To avoid being traced by phone company or FBI, Mitnick placed these calls from cloned cellular phones programmed with stolen electronic serial numbers.

The Lure & the Tell

Lure: Mitnick posed as "Gabe Nault," a real Novell employee, claiming he was on vacation in Vail and urgently needed direct inbound modem/dial-up access to make emergency changes to a real internal project (referred to by Nunley as the genuine project "Snowbird"). He reinforced the story by matching details (the Vail vacation) to a voicemail greeting he had secretly rerecorded in the impersonated employee's own voice mailbox, after obtaining that mailbox's password from a Novell telecom staffer in an earlier pretext call. The tell: Nunley found the request abnormal on its face, since it bypassed Novell's manager-approval requirement and its secure callback-only dial-in policy, and "it all felt wrong" despite the accurate jargon and plausible story, which is why he insisted on voicemail corroboration (a control Mitnick had already defeated) rather than granting access on the spot.

Outcome

Novell support analyst Shawn Nunley recorded Mitnick's corroborating voicemail onto a cassette tape, which became the primary evidentiary basis of the federal case's Novell counts and made Nunley the government's star witness. Mitnick was arrested Feb. 15, 1995, in Raleigh, NC, ending a roughly two-week manhunt. He was indicted on 25 federal counts (U.S. v. Mitnick, CR 96-881 MRP, C.D. Cal.), including wire fraud (18 U.S.C. §1343), computer fraud and damage (18 U.S.C. §1030), unlawful interception of electronic communications (18 U.S.C. §2511) for the Novell password-capture program, and possession of unauthorized access devices (18 U.S.C. §1029) for the files of stolen Novell usernames/passwords. Co-defendant Lewis DePayne was charged with aiding and abetting. Mitnick pleaded guilty on March 26, 1999, and was sentenced Aug. 9, 1999, to 46 months' imprisonment (running consecutively to earlier 8- and 14-month sentences from prior cases), 3 years' supervised release, a $350 special assessment, and $4,125 restitution, with no fine. Nunley later grew disillusioned with the prosecution's handling of the case, reached out to Mitnick's defense team, and the two former adversaries became close friends after Mitnick's release. Nunley went on to give his own talks on social engineering, and after attending one, Mitnick asked to reuse material from Nunley's presentation in his own talks.

Why It Matters

This is one of the most cited foundational case studies in social engineering/pretexting, predating the term's mainstream use in security training. It demonstrates that a support desk's own verification control (voicemail corroboration) can be turned against it if an earlier, seemingly unrelated pretext call has already compromised that same channel, illustrating why social engineering defenses must consider chained/multi-call attacks, not just single interactions. It is the direct historical basis for the modern security-awareness standard of independently-initiated callback verification (calling back a number from a trusted directory, never one supplied by the requester) rather than accepting caller-supplied "proof." Mitnick and Nunley later publicly used the story (including in Mitnick's memoir "Ghost in the Wires") to teach vishing/pretexting awareness, and the same psychological mechanics (urgency, insider jargon, absence/vacation framing, borrowed trust) persist in modern vishing and AI voice-cloning attacks against IT help desks.

Defenses

Then-available and still-relevant controls that would have stopped or slowed this: (1) callback/dial-back verification to a number pulled from an internal directory, not one supplied by the caller, since Novell nominally had a "secure dial-back" policy for modem access that Nunley bypassed under pressure; (2) treating voicemail as weak/spoofable identity proof rather than sufficient verification, since Mitnick had already hijacked the impersonated employee's voicemail via a separate pretext call to Novell's telecom department; (3) mandatory manager sign-off for any new dial-in/remote-access account, enforced without exception even for "emergency" or vacationing-employee requests; (4) treating urgency plus an employee's stated absence (vacation, being unreachable) as a red flag requiring extra verification, not a reason to skip it; (5) monitoring/alerting on new dial-in account creation and unusual after-hours activity. These same principles (independent callback verification, no identity-by-voicemail, no bypassing access-approval workflows under time pressure) remain the standard defense against modern vishing/pretexting, including AI voice-cloning variants.

Sources
  • Kevin Mitnick's Federal Indictment (U.S. v. Mitnick). U.S. District Court, Central District of California (mirrored) Primary. Full indictment text; Novell counts (1, 4, 17, 21, 22) with exact dates and charged statutes -- fetched and verified verbatim, including the 25-count structure and the Gabe Nault/Colorado-to-San Jose call on 1/4/94.
  • United States v. Mitnick, 2:96-cr-00506 - docket. U.S. District Court, Central District of California / CourtListener Primary. Case docket confirming plea (3/26/99) and sentencing (8/9/99) dates/terms, 46-month sentence, $350 special assessment, and consecutive 8- and 14-month prior sentences -- fetched and verified.
  • #089 Fugitive Computer Hacker Arrested in North Carolina. U.S. Department of Justice Primary. DOJ press release confirming Feb. 15, 1995 arrest details in Raleigh, NC -- fetched and verified.
  • June 7, 1999 Defense Motion. U.S. District Court, C.D. Cal. (defense filing, mirrored) Primary. Defense filing disputing prosecution's loss figures vs. PSR figure of $1,143,129 -- fetched and verified verbatim, including the exact PSR footnote and the $80M bail-filing quote.
  • Judge Accepts Mitnick's Guilty Plea on 7 Counts. Los Angeles Times Secondary. Fetched and verified: confirms guilty plea to seven computer crime and fraud charges on March 26, 1999.
  • Mitnick Meets His Pigeon. Reuters / WIRED Secondary. Detailed 2002 account of the Nunley pretext call, voicemail hijack, and dial-in account creation. wired.com's live page serves only a truncated stub; content verified via a full-text mirror of the same Reuters wire story on seclists.org, confirming the telecom-department voicemail-password detail and the compressed-copy-of-source-code detail.
  • The price tag for Mitnick's attack. ZDNET Secondary. Coverage of the disputed Novell/victim-company loss figures -- fetched and verified (six-company letters totaling ~$300M in claimed R&D value).
  • Kevin Mitnick - In Memoriam (1963-2023). Cloud Security Office Hours (first-person account by Shawn Nunley) Secondary. Nunley's own first-hand account of the pretext call, the 'Gabe Nault'/Snowbird/Vail story, and his role as star witness -- fetched and verified verbatim; also the source confirming the real story appears in 'Ghost in the Wires,' not 'The Art of Deception.'
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance: Per Novell support analyst Shawn Nunley's own first-hand account and contemporaneous reporting, Mitnick is documented as gathering real internal detail on Novell before ever calling, including employee names, organizational structure, the name of a genuine internal project ("Snowbird"), and enough NetWare technical jargon to sound like an insider; this kind of pre-call profiling typically draws on employee directories and other publicly available corporate information.
Countering Stage 1: Employee directories, org charts, and project names are very hard to fully suppress at enterprise scale (Novell's own staff needed to discuss "Snowbird" internally to do their jobs); the realistic control assumes an attacker can gather this and instead hardens the processes this information later gets used against, rather than trying to eliminate the exposure itself.
2
Pretexting a side channel: In a separate, earlier pretext call, Mitnick contacted Novell's telecom department and, posing as an employee, persuaded a staffer to hand over the target employee's voicemail password, a low-stakes call made specifically to pre-stage a verification channel he expected support staff to rely on later.
Countering Stage 2: Any request to a telecom or helpdesk team to reset or reveal a voicemail password for another employee should require independent verification of the requester's identity (for example, a callback to the account owner's known number, or manager sign-off) before the password is disclosed, since this single low-stakes call is what made the entire later pretext work.
3
Compromising the verification channel: Using that password, Mitnick logged into the impersonated employee's voice mailbox and rerecorded the outgoing greeting himself, weaving in the same vacation location ("Vail") he planned to reference in the main pretext, so the mailbox would corroborate his story instead of exposing it.
Countering Stage 3: Voicemail systems should be treated as an asset that itself needs integrity monitoring; alerting the affected employee or IT security whenever a mailbox's greeting or password changes, especially while that employee is reported to be out of office, would have flagged the tampering before it could be used as "proof."
4
Primary pretext call to a lower-friction contact: Mitnick called Novell's wide-area-networking department, impersonating a real employee who was on vacation, and asked for direct inbound dial-up access, citing an urgent need to make changes to the genuine "Snowbird" project while away, a request framed as routine and time-pressured to a WAN engineer who was not the actual account gatekeeper.
Countering Stage 4: Front-line support and network staff should be trained to treat unsolicited, urgency-framed requests for new access, especially ones citing an employee's absence, as requiring escalation and verification rather than accommodation, regardless of how fluent the caller sounds in internal jargon.
5
Escalation to the real approver: The WAN engineer referred the request to Shawn Nunley, the only staffer authorized to create dial-in accounts, and Mitnick called Nunley directly, including at his home, pushing the same urgent vacation-cover story past Novell's manager-approval and secure callback-dial policies.
Countering Stage 5: Enforce manager sign-off and the secure callback-only dial-in policy without exception, including for after-hours or "emergency" requests; Novell had this policy on paper, and the point of failure was that Nunley was pressured in the moment into treating it as optional rather than mandatory.
6
Defeating the support analyst's identity check: Nunley, suspicious, asked Mitnick to leave a corroborating voicemail on the impersonated employee's office extension rather than granting access outright; Mitnick had already hijacked that exact mailbox, so the "proof" he supplied back to Nunley was self-manufactured.
Countering Stage 6: Voicemail should never be accepted as identity proof on its own, since it is a channel the requester could plausibly have already compromised. The realistic control is independently-initiated callback verification: calling a number pulled from a trusted internal directory, never one supplied by, or associated with, the person requesting access.
7
Access and staging: Satisfied by the voicemail, Nunley created the dial-in account. Mitnick had also, in a separate pretext, already persuaded a different Novell engineer to move a compressed copy of the NetWare source code to a more accessible server, and he used cloned cellular phones built with stolen electronic serial numbers so his calls could not be traced back to him.
Countering Stage 7: Monitoring and alerting on new dial-in account creation, unusual after-hours network activity, and unexpected transfers of sensitive source code between internal servers would have surfaced both the compressed-copy staging and the account misuse; cloned-cell-phone call laundering is largely outside a victim company's control and is more properly addressed by telecom carriers' own fraud controls.
8
Objective completion (exfiltration): Mitnick dialed into Novell's network using the newly created account and copied the staged NetWare source code out of the company, completing the trade secret theft that later formed the basis of the federal case's Novell counts.
Countering Stage 8: Once exfiltration is underway, the realistic backstop is detection and response rather than prevention: monitoring for large, unusual transfers of proprietary source code off internal servers, and prompt law-enforcement engagement (as eventually occurred in this case), rather than any single preventive control at this final stage.
Quick Facts
Victim
Novell, Inc., specifically its technical support and network administration staff, targeting support analyst Shawn Nunley
Location
Novell, Inc. headquarters/network access points, San Jose/Utah (Sandy, UT dial-in path), USA; Mitnick calling from Denver, Colorado while a fugitive living under a false identity
Date
Underlying pretext calls and theft: primarily Dec 1993 - Jan 1994 (federal indictment: Count 21 possession of 50+ Novell usernames/passwords dated 12/20/93; Count 22 possession of 900+ Novell usernames/passwords dated 12/24/93; Count 17 alleges a password-interception program installed on Novell computers "in or around December 1993"; Count 1 dates a call from Mitnick, using the alias "Gabe Nault," from Colorado to San Jose to 1/4/94). Mitnick arrested Feb 15, 1995, in Raleigh, NC. Indicted in 1996 as U.S. v. Mitnick, CR 96-881 MRP (C.D. Cal.). Pleaded guilty March 26, 1999. Sentenced Aug 9, 1999.
Impact
Disputed and largely alleged rather than adjudicated as actual loss. In a letter to the FBI, Novell valued the stolen NetWare source code's development cost at "well in excess of $75,000,000"; prosecutors later cited loss figures above $80 million in bail and sentencing filings covering the case's multiple corporate victims (Novell, Nokia, Motorola, Fujitsu, NEC, Sun). Mitnick's defense argued these were sunk R&D costs, not losses actually caused by the disclosure, and the U.S. Probation Office's presentence report put total potential loss across all counts/victims at $1,143,129.00. At sentencing, Judge Mariana R. Pfaelzer ordered only $4,125 in restitution, explicitly calling it a token amount, and imposed no fine.
Status
Confirmed
Case Type
Real-World Incident
Sector
Technology & Software
Threat Actor
Unaffiliated Individual
Related

Related Cases

Gen. Wesley Clark Phone Records Pretexting Incident (2005-2006)

A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…

Incident 2005Read →

Hewlett-Packard Boardroom "Pretexting" Spying Scandal (2006)

To unmask a boardroom leaker, HP's leak investigators and their hired data brokers impersonated directors and journalists to trick phone…

Incident 2005Read →

FTC Pretexting Sweep Against Telephone Record Sellers (2006-2008)

Between 2006 and 2008 the FTC sued 16 data-broker and private-investigation defendants who pretexted telecom carriers, posing as account holders…

Incident 2006Read →