A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained via carrier pretexting, and the resulting exposé triggered FTC enforcement, congressional hearings, and the 2006 federal law criminalizing pretexting for phone records.
Reviewed by the Social Engineering Examples team.
In November 2005, an online data-broker site, CellTolls.com, obtained 100 consecutive calls made to and from retired Gen. Wesley Clark's personal T-Mobile (Omnipoint) cell phone between Nov. 15 and 18, 2005, by pretexting the carrier: impersonating the account holder to a customer-service representative to get the call log released. In January 2006, blogger John Aravosis of AMERICAblog purchased that call log from CellTolls.com for $89.95, needing only Clark's cell number and a credit card, and received the data within 24 hours. Aravosis had first tested the market on himself, buying his own Cingular Wireless records for $110 from a related site, LocateCell.com. He published the Clark purchase on AMERICAblog on Jan. 12, 2006 (having verified authenticity by calling the number and hearing Clark's own voicemail greeting, then notifying Clark), as a deliberate proof-of-concept that any person's private communications metadata, including a high-profile former general's, could be bought online with no verification of buyer intent or relationship to the subject. This followed a Jan. 5, 2006 Chicago Sun-Times story by reporter Frank Main documenting the same broker market, and CNET amplified the story nationally on Jan. 20, 2006.
Web-based data broker sites such as LocateCell.com and CellTolls.com advertised the ability to produce a target's cell-phone call log for a fee, needing only the target's phone number and a credit card. Behind the storefront, these brokers (or subcontracted "information specialists," later identified in FCC/FTC actions as firms like 1st Source Information Specialists) used pretexting: broker employees called the carrier's customer service line impersonating the account holder (or otherwise misrepresenting their identity/authority), supplying enough guessed or researched identifying details to pass the carrier's weak verbal verification, and induced the customer-service rep to read out or fax the call detail records. The broker then repackaged that data and sold it to the online purchaser within about 24 hours, no additional identity proof required from the buyer.
The "lure" operated on two levels. First, the data-broker sites themselves lured paying customers with a simple e-commerce promise: "give us any phone number and a credit card, get someone's call log in 24 hours," with no verification of the buyer's relationship to the subject. Second, inside the transaction, the broker's own pretext to the carrier was impersonation of the account holder calling in for routine customer service, a low-friction social engineering script exploiting call-center reps trained to be helpful and not adversarial toward callers who "sound like" the customer. The "tell": John Aravosis publicly disclosed the entire transaction himself on AMERICAblog on Jan. 12, 2006, explicitly as a deliberate proof-of-concept. He first bought his own Cingular Wireless records for $110, then bought Gen. Clark's for $89.95 specifically to demonstrate that even a high-profile, national-security-relevant figure's private communications metadata (calls to Arkansas, to foreign countries, to a Washington Post reporter) could be trivially bought by anyone. He verified authenticity by calling Clark's number and hearing Clark's own voicemail greeting, then contacted Clark to disclose what he'd done.
The Jan. 2006 disclosure (following a Jan. 5, 2006 Chicago Sun-Times story by Frank Main showing the same broker market) escalated into a national policy scandal. The FTC testified before the House Energy and Commerce Committee ("Phone Records for Sale: Why Aren't Phone Records Safe From Pretexting?", Feb. 1, 2006) and the Senate Commerce Subcommittee on Consumer Affairs, Product Safety, and Insurance ("Protecting Consumers' Phone Records", Feb. 8, 2006), both citing the Clark purchase as the emblematic example. The FTC filed five federal enforcement actions against phone-record broker companies (complaints dated May 1, 2006, publicly announced May 3, 2006). The FCC issued a Notice of Apparent Liability for Forfeiture against 1st Source Information Specialists (d/b/a LocateCell.com). The Senate Commerce Committee's report on S. 2389 (Report 109-253, ordered printed May 9, 2006) cited the $89.95 Clark purchase directly as justification for the bill. Congress passed the Telephone Records and Privacy Protection Act of 2006 (Public Law 109-476), enacted Jan. 12, 2007, criminalizing pretexting to obtain confidential customer phone records. Separately, when Hewlett-Packard's own pretexting scandal broke in Sept. 2006 (disclosed to the SEC Sept. 6, 2006), the House Energy and Commerce Subcommittee on Oversight and Investigations held a follow-on hearing ("Hewlett-Packard's Pretexting Scandal," Sept. 28, 2006) that explicitly built on the legislative momentum the Clark case had already created earlier that year.
This incident is a textbook demonstration of pretexting as a commercial service: brokers turned carrier social-engineering into a repeatable, priced product (under $100, 24-hour turnaround) sold to any buyer with a credit card. It shows how impersonating an account holder over the phone to a call-center rep, not a technical hack, was sufficient to defeat major carriers' CPNI safeguards. Using a nationally recognizable figure (a retired four-star general and former presidential candidate) as the proof-of-concept converted an obscure privacy/consumer-protection issue into front-page news and direct congressional testimony citations, illustrating how a single well-chosen public-figure target can catalyze federal legislation (Public Law 109-476) faster than abstract harm to ordinary consumers alone. It is also a rare case where the "attacker" (Aravosis) was a journalist/activist deliberately exposing the vulnerability rather than exploiting it maliciously, and it directly set the legislative and public-attention stage that the HP boardroom pretexting scandal (Sept. 2006) then amplified further.
The episode exposed that carriers (T-Mobile/Omnipoint, Cingular and others) had weak authentication for releasing Customer Proprietary Network Information (CPNI) over the phone, letting pretexters impersonate account holders to extract call logs. Fixes that followed: FTC filed five federal enforcement actions (complaints dated May 1, 2006, announced May 3, 2006) against data-broker sites; the FCC issued a Notice of Apparent Liability against 1st Source Information Specialists (d/b/a LocateCell.com); the FCC subsequently tightened CPNI rules (password/PIN authentication, notification of account changes, audit trails); Congress passed the Telephone Records and Privacy Protection Act of 2006 (Public Law 109-476, enacted Jan. 12, 2007), which criminalized pretexting to obtain confidential phone records; carriers (Cingular, T-Mobile) also filed civil suits against data brokers. For organizations generally, the case underscores the need for out-of-band verification and knowledge-based/PIN authentication before releasing any account or call-detail data by phone, and awareness that "public figure" status increases resale value of illicitly obtained personal records.
To unmask a boardroom leaker, HP's leak investigators and their hired data brokers impersonated directors and journalists to trick phone…
Between 2006 and 2008 the FTC sued 16 data-broker and private-investigation defendants who pretexted telecom carriers, posing as account holders…
The FTC's first-ever case under the FACTA Disposal Rule: a Northbrook, Illinois mortgage lender repeatedly dumped intact customer credit reports…