A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained via carrier pretexting.
Social Engineering Examples·11 sources
In November 2005, an online data-broker site, CellTolls.com, obtained 100 consecutive calls made to and from retired Gen. Wesley Clark's personal T-Mobile (Omnipoint) cell phone between Nov. 15 and 18, 2005, by pretexting the carrier: impersonating the account holder to a customer-service representative to get the call log released. In January 2006, blogger John Aravosis of AMERICAblog purchased that call log from CellTolls.com for $89.95, needing only Clark's cell number and a credit card, and received the data within 24 hours.
Aravosis had first tested the market on himself, buying his own Cingular Wireless records for $110 from a related site, LocateCell.com. He published the Clark purchase on AMERICAblog on Jan. 12, 2006 (having verified authenticity by calling the number and hearing Clark's own voicemail greeting, then notifying Clark), as a deliberate proof-of-concept that any person's private communications metadata, including a high-profile former general's, could be bought online with no verification of buyer intent or relationship to the subject.
This followed a Jan. 5, 2006 Chicago Sun-Times story by reporter Frank Main documenting the same broker market, and CNET amplified the story nationally on Jan. 20, 2006.
Web-based data broker sites such as LocateCell.com and CellTolls.com advertised the ability to produce a target's cell-phone call log for a fee, needing only the target's phone number and a credit card. Behind the storefront, these brokers (or subcontracted "information specialists," later identified in FCC/FTC actions as firms like 1st Source Information Specialists) used pretexting: broker employees called the carrier's customer service line impersonating the account holder (or otherwise misrepresenting their identity/authority), supplying enough guessed or researched identifying details to pass the carrier's weak verbal verification, and induced the customer-service rep to read out or fax the call detail records.
The broker then repackaged that data and sold it to the online purchaser within about 24 hours, no additional identity proof required from the buyer.
The "lure" operated on two levels. First, the data-broker sites themselves lured paying customers with a simple e-commerce promise: "give us any phone number and a credit card, get someone's call log in 24 hours," with no verification of the buyer's relationship to the subject. Second, inside the transaction, the broker's own pretext to the carrier was impersonation of the account holder calling in for routine customer service, a low-friction social engineering script exploiting call-center reps trained to be helpful and not adversarial toward callers who "sound like" the customer.
The "tell": John Aravosis publicly disclosed the entire transaction himself on AMERICAblog on Jan. 12, 2006, explicitly as a deliberate proof-of-concept. He first bought his own Cingular Wireless records for $110, then bought Gen. Clark's for $89.95 specifically to demonstrate that even a high-profile, national-security-relevant figure's private communications metadata (calls to Arkansas, to foreign countries, to a Washington Post reporter) could be trivially bought by anyone.
He verified authenticity by calling Clark's number and hearing Clark's own voicemail greeting, then contacted Clark to disclose what he'd done.
The Jan. 2006 disclosure (following a Jan. 5, 2006 Chicago Sun-Times story by Frank Main showing the same broker market) escalated into a national policy scandal. The FTC testified before the House Energy and Commerce Committee ("Phone Records for Sale: Why Aren't Phone Records Safe From Pretexting?", Feb. 1, 2006) and the Senate Commerce Subcommittee on Consumer Affairs, Product Safety, and Insurance ("Protecting Consumers' Phone Records", Feb. 8, 2006), both citing the Clark purchase as the emblematic example.
The FTC filed five federal enforcement actions against phone-record broker companies (complaints dated May 1, 2006, publicly announced May 3, 2006). The FCC issued a Notice of Apparent Liability for Forfeiture against 1st Source Information Specialists (d/b/a LocateCell.com). The Senate Commerce Committee's report on S. 2389 (Report 109-253, ordered printed May 9, 2006) cited the $89.95 Clark purchase directly as justification for the bill.
Congress passed the Telephone Records and Privacy Protection Act of 2006 (Public Law 109-476), enacted Jan. 12, 2007, criminalizing pretexting to obtain confidential customer phone records. Separately, when Hewlett-Packard's own pretexting scandal broke in Sept. 2006 (disclosed to the SEC Sept. 6, 2006), the House Energy and Commerce Subcommittee on Oversight and Investigations held a follow-on hearing ("Hewlett-Packard's Pretexting Scandal," Sept. 28, 2006) that explicitly built on the legislative momentum the Clark case had already created earlier that year.
This incident is a textbook demonstration of pretexting as a commercial service: brokers turned carrier social-engineering into a repeatable, priced product (under $100, 24-hour turnaround) sold to any buyer with a credit card. It shows how impersonating an account holder over the phone to a call-center rep, not a technical hack, was sufficient to defeat major carriers' CPNI safeguards.
Using a nationally recognizable figure (a retired four-star general and former presidential candidate) as the proof-of-concept converted an obscure privacy/consumer-protection issue into front-page news and direct congressional testimony citations, illustrating how a single well-chosen public-figure target can catalyze federal legislation (Public Law 109-476) faster than abstract harm to ordinary consumers alone.
It is also a rare case where the "attacker" (Aravosis) was a journalist/activist deliberately exposing the vulnerability rather than exploiting it maliciously, and it directly set the legislative and public-attention stage that the HP boardroom pretexting scandal (Sept. 2006) then amplified further.
The episode exposed that carriers (T-Mobile/Omnipoint, Cingular and others) had weak authentication for releasing Customer Proprietary Network Information (CPNI) over the phone, letting pretexters impersonate account holders to extract call logs. Fixes that followed: FTC filed five federal enforcement actions (complaints dated May 1, 2006, announced May 3, 2006) against data-broker sites; the FCC issued a Notice of Apparent Liability against 1st Source Information Specialists (d/b/a LocateCell.com); the FCC subsequently tightened CPNI rules (password/PIN authentication, notification of account changes, audit trails); Congress passed the Telephone Records and Privacy Protection Act of 2006 (Public Law 109-476, enacted Jan. 12, 2007), which criminalized pretexting to obtain confidential phone records; carriers (Cingular, T-Mobile) also filed civil suits against data brokers.
For organizations generally, the case underscores the need for out-of-band verification and knowledge-based/PIN authentication before releasing any account or call-detail data by phone, and awareness that "public figure" status increases resale value of illicitly obtained personal records.
Social Engineering Examples. “Gen. Wesley Clark Phone Records Pretexting Incident (2005-2006)”. Accessed 19 September 2026. https://socialengineeringexamples.com/wesley-clark-phone-records-pretexting-2006
The broker needed only the subject's cell number to begin, not privileged access; reporting from the period indicates such numbers circulated through personal contacts, prior press coverage, or public directories, reflecting how low the entry bar was for targeting even a high-profile figure like Gen. Clark.
A public figure's phone number is nearly impossible to fully suppress once it has circulated through contacts, campaigns, or prior reporting; the realistic control is not hiding the number but hardening what a caller can do with it once obtained, which is addressed at Stage 3.
Consistent with contemporaneous reporting on the same broker market (commercial data-broker lookup services and cross-referenced personal data such as partial SSNs or dates of birth), brokers and their subcontracted "information specialists" typically assembled enough identifying detail about the account holder to sound plausible to a carrier's phone-based verification process.
Limiting how much identity-verifying data (partial SSNs, dates of birth) commercial data-broker and people-search services expose for lookup or resale reduces the raw material pretexters use to sound convincing; this is a data-minimization control on the broader personal-data industry rather than on the phone carrier itself.
A broker employee called the carrier's (T-Mobile/Omnipoint's) customer-service line impersonating the account holder and used the gathered details to talk a representative into reading out or faxing the call-detail records, exploiting reps trained to be helpful toward callers who "sounded like" the customer rather than treating the request as adversarial.
This is the core fix. Carriers should require account-specific out-of-band or knowledge-based authentication (a customer-set PIN or password) before releasing CPNI or call-detail records by phone, rather than relying on a caller sounding like the account holder; this is exactly the CPNI rule change (password/PIN authentication, account-change notification, audit trails) the FCC adopted after this episode.
The broker aggregated the extracted call log and listed a fee-for-any-target lookup service on a public e-commerce storefront (CellTolls.com / LocateCell.com), advertising fast turnaround with no check on the buyer's identity, intent, or relationship to the subject.
A data broker publicly advertising the sale of any individual's confidential phone records is itself the unlawful, targetable activity that FTC and FCC enforcement went after (five FTC actions in 2006; an FCC forfeiture order against 1st Source Information Specialists d/b/a LocateCell.com); shutting down the storefront removes the resale channel even when a given pretext call succeeds.
John Aravosis paid $89.95 online with nothing more than Clark's cell number and a credit card, received the 100-call log within about 24 hours, and independently verified it was genuine by calling the number and hearing Clark's own voicemail greeting.
Requiring documented buyer purpose or written customer authorization before a broker or carrier releases any call-detail data mirrors the consent standard Public Law 109-476 later imposed criminally on exactly this no-questions-asked resale model.
Aravosis published the purchase and the redacted call log on AMERICAblog on Jan. 12, 2006 as a deliberate proof-of-concept, converting the transaction into national exposure that fed directly into FTC and FCC enforcement action and the 2006 federal pretexting law, completing the objective of using a public figure's data to prove the vulnerability at scale.
There is no technical control that prevents public disclosure once leaked data exists in someone's hands. In this case the disclosure itself functioned as the corrective mechanism, converting a hidden vulnerability into congressional testimony and the resulting 2006 law, so the realistic posture for organizations is to plan for responsible/coordinated disclosure norms rather than to assume all such exposure can be prevented.
Browse by what this case has in common with others in the library.
To unmask a boardroom leaker, HP's leak investigators and their hired data brokers impersonated directors and journalists to trick phone…
Between 2006 and 2008 the FTC sued 16 data-broker and private-investigation defendants who pretexted telecom carriers.
The FTC's first-ever case under the FACTA Disposal Rule: a Northbrook, Illinois mortgage lender repeatedly dumped intact customer credit reports.
A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool…
Fraudsters built a fake WhatsApp profile of WPP CEO Mark Read and staged a Microsoft Teams call using an AI…
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
Criminals impersonated a trusted vendor over email and redirected two building-fund payments totaling $4.92M from a North Dakota school district.
Dow Chemical and Sasol paid PR firms who subcontracted a private intelligence firm to run over 120 dumpster-diving raids on…
A forged "change your remittance bank account" email tricked a Puerto Rico government corporation into wiring $2.6M to a fraudster-controlled…
A Bengaluru retiree lost Rs 6.88 lakh after an AI-generated deepfake Facebook video falsely showed Finance Minister Nirmala Sitharaman endorsing…
An Atlantic City woman posed as a life-insurance/retirement-benefit representative on burner-phone calls to recently widowed elderly victims.
A mass SMS phishing campaign impersonating U.S. toll agencies spoofed 'unpaid toll' notices, drawing 2,000+ FBI complaints within weeks.
Attackers stood up a real Azure subscription and Azure Monitor alert rule to make Microsoft's own mail servers send a…
ESET researchers found "PromptLock," a Go-based ransomware sample on VirusTotal that used a locally-run open-weight AI model.
A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT…
In the first-ever prosecutions under the federal anti-pretexting statute Congress passed after the 2006 HP boardroom spying scandal.
A mass-phishing malware infection at Target's small HVAC contractor harvested vendor-portal credentials that attackers reused to pivot.
Chinese state-linked hackers used spear-phishing links and an unpatched Internet Explorer zero-day to breach Google, Adobe.
eSentire's Threat Response Unit blocked 10 separate attacks across six unnamed law firms in Jan-Feb 2023, foiling two parallel campaigns.
A phishing email tricked Unatrac's CFO into surrendering his Office365 credentials on a fake Microsoft login page.
A retired 60-year-old Malaysian bank manager in Johor Baru lost RM936,000 (life savings) after a Macau-scam vishing syndicate posing successively.
Tejay Fletcher founded and ran iSpoof, a Bitcoin-subscription caller-ID spoofing and OTP-interception platform that let fraudsters impersonate bank.
NTS IT Care used fake Microsoft/Apple security pop-ups to scare consumers, mostly older Americans.
Costa Rica-based ringleader Roger Roger used spoofed government caller ID to convince hundreds of elderly victims they had won sweepstakes…