Fugitive hacker Kevin Mitnick impersonated a vacationing Novell employee on a "top-secret" project, defeated a support analyst's voicemail-based identity check by first hijacking that employee's voicemail, and talked his way into a dial-in account used to steal Novell NetWare source code.
Reviewed by the Social Engineering Examples team.
While a fugitive living under a false identity in Denver, Colorado (holding a day job at a law firm), Kevin Mitnick targeted Novell, Inc.'s technical support and network staff by phone to obtain NetWare source code. Having done reconnaissance on Novell's staff and internal projects, Mitnick impersonated a real Novell employee who was on vacation, calling Novell's wide-area-networking department and requesting direct inbound dial-up access to the company network, citing an urgent need to make changes to a genuine internal project ("Snowbird") while away. The WAN engineer on duty referred the request to Shawn Nunley, the only person authorized to create such dial-in accounts. Mitnick called Nunley, including at home, and Nunley, suspicious that the request skipped required manager approval and the company's secure callback dial-in policy, asked him to first leave a voicemail on the impersonated employee's office extension as proof. Mitnick had already, via a separate earlier pretext call, obtained that employee's voicemail password from a Novell telecom staffer and rerecorded the greeting to match the vacation story. Satisfied by the voicemail, Nunley created the dial-in account; Mitnick immediately used it to connect into Novell's network and copy proprietary NetWare source code. Nunley preserved the voicemail on a cassette tape, which became the key evidence in the eventual federal prosecution and made him the government's star witness. The Novell intrusion was folded into a broader 25-count federal indictment (U.S. v. Mitnick, CR 96-881 MRP, C.D. Cal.) covering multiple corporate victims (Novell, Nokia, Motorola, Fujitsu, NEC, Sun, USC) for wire fraud, computer fraud, illegal interception of communications, and possession of unauthorized access devices.
Mitnick's approach combined reconnaissance with a two-stage phone pretext rather than any technical exploit. He first gathered real internal details on Novell (employee names, the name of an actual internal project, technical jargon) so he could speak convincingly as an insider. He impersonated a specific real Novell employee who was on vacation, calling Novell's wide-area-networking department and asking for direct inbound dial-up access, claiming an urgent need to make emergency changes to a genuine internal project while away from the office. The WAN engineer routed the request to Shawn Nunley, the only staffer authorized to create dial-in accounts, and Mitnick called Nunley directly, including once at his home at night. Nunley sensed the request was abnormal (it bypassed the required manager approval and Novell's secure callback-based dial system) and, instead of granting access outright, asked Mitnick to leave a corroborating voicemail on the impersonated employee's office extension. Mitnick had anticipated this: in an earlier, separate pretext call, he had persuaded a Novell telecom staffer to hand over that employee's voicemail password, then rerecorded the greeting himself, referencing the same vacation location the "employee" had mentioned to Nunley. When Nunley checked the voicemail and it matched, he created the dial-in account. Mitnick then dialed in immediately and began copying Novell NetWare source code to a machine outside the company, having earlier also convinced a different Novell engineer to move a compressed copy of the source code to a more accessible server. To avoid being traced by phone company or FBI, Mitnick placed these calls from cloned cellular phones programmed with stolen electronic serial numbers.
Lure: Mitnick posed as "Gabe Nault," a real Novell employee, claiming he was on vacation in Vail and urgently needed direct inbound modem/dial-up access to make emergency changes to a real internal project (referred to by Nunley as the genuine project "Snowbird"). He reinforced the story by matching details (the Vail vacation) to a voicemail greeting he had secretly rerecorded in the impersonated employee's own voice mailbox, after obtaining that mailbox's password from a Novell telecom staffer in an earlier pretext call. The tell: Nunley found the request abnormal on its face, since it bypassed Novell's manager-approval requirement and its secure callback-only dial-in policy, and "it all felt wrong" despite the accurate jargon and plausible story, which is why he insisted on voicemail corroboration (a control Mitnick had already defeated) rather than granting access on the spot.
Novell support analyst Shawn Nunley recorded Mitnick's corroborating voicemail onto a cassette tape, which became the primary evidentiary basis of the federal case's Novell counts and made Nunley the government's star witness. Mitnick was arrested Feb. 15, 1995, in Raleigh, NC, ending a roughly two-week manhunt. He was indicted on 25 federal counts (U.S. v. Mitnick, CR 96-881 MRP, C.D. Cal.), including wire fraud (18 U.S.C. §1343), computer fraud and damage (18 U.S.C. §1030), unlawful interception of electronic communications (18 U.S.C. §2511) for the Novell password-capture program, and possession of unauthorized access devices (18 U.S.C. §1029) for the files of stolen Novell usernames/passwords. Co-defendant Lewis DePayne was charged with aiding and abetting. Mitnick pleaded guilty on March 26, 1999, and was sentenced Aug. 9, 1999, to 46 months' imprisonment (running consecutively to earlier 8- and 14-month sentences from prior cases), 3 years' supervised release, a $350 special assessment, and $4,125 restitution, with no fine. Nunley later grew disillusioned with the prosecution's handling of the case, reached out to Mitnick's defense team, and the two former adversaries became close friends after Mitnick's release. Nunley went on to give his own talks on social engineering, and after attending one, Mitnick asked to reuse material from Nunley's presentation in his own talks.
This is one of the most cited foundational case studies in social engineering/pretexting, predating the term's mainstream use in security training. It demonstrates that a support desk's own verification control (voicemail corroboration) can be turned against it if an earlier, seemingly unrelated pretext call has already compromised that same channel, illustrating why social engineering defenses must consider chained/multi-call attacks, not just single interactions. It is the direct historical basis for the modern security-awareness standard of independently-initiated callback verification (calling back a number from a trusted directory, never one supplied by the requester) rather than accepting caller-supplied "proof." Mitnick and Nunley later publicly used the story (including in Mitnick's memoir "Ghost in the Wires") to teach vishing/pretexting awareness, and the same psychological mechanics (urgency, insider jargon, absence/vacation framing, borrowed trust) persist in modern vishing and AI voice-cloning attacks against IT help desks.
Then-available and still-relevant controls that would have stopped or slowed this: (1) callback/dial-back verification to a number pulled from an internal directory, not one supplied by the caller, since Novell nominally had a "secure dial-back" policy for modem access that Nunley bypassed under pressure; (2) treating voicemail as weak/spoofable identity proof rather than sufficient verification, since Mitnick had already hijacked the impersonated employee's voicemail via a separate pretext call to Novell's telecom department; (3) mandatory manager sign-off for any new dial-in/remote-access account, enforced without exception even for "emergency" or vacationing-employee requests; (4) treating urgency plus an employee's stated absence (vacation, being unreachable) as a red flag requiring extra verification, not a reason to skip it; (5) monitoring/alerting on new dial-in account creation and unusual after-hours activity. These same principles (independent callback verification, no identity-by-voicemail, no bypassing access-approval workflows under time pressure) remain the standard defense against modern vishing/pretexting, including AI voice-cloning variants.
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
To unmask a boardroom leaker, HP's leak investigators and their hired data brokers impersonated directors and journalists to trick phone…
Between 2006 and 2008 the FTC sued 16 data-broker and private-investigation defendants who pretexted telecom carriers, posing as account holders…