Case Library / Pretexting & Impersonation / Gen. Wesley Clark Phone Records Pretexting Incident (2005-2006)

Gen. Wesley Clark Phone Records Pretexting Incident (2005-2006)

A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained via carrier pretexting, and the resulting exposé triggered FTC enforcement, congressional hearings, and the 2006 federal law criminalizing pretexting for phone records.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

In November 2005, an online data-broker site, CellTolls.com, obtained 100 consecutive calls made to and from retired Gen. Wesley Clark's personal T-Mobile (Omnipoint) cell phone between Nov. 15 and 18, 2005, by pretexting the carrier: impersonating the account holder to a customer-service representative to get the call log released. In January 2006, blogger John Aravosis of AMERICAblog purchased that call log from CellTolls.com for $89.95, needing only Clark's cell number and a credit card, and received the data within 24 hours. Aravosis had first tested the market on himself, buying his own Cingular Wireless records for $110 from a related site, LocateCell.com. He published the Clark purchase on AMERICAblog on Jan. 12, 2006 (having verified authenticity by calling the number and hearing Clark's own voicemail greeting, then notifying Clark), as a deliberate proof-of-concept that any person's private communications metadata, including a high-profile former general's, could be bought online with no verification of buyer intent or relationship to the subject. This followed a Jan. 5, 2006 Chicago Sun-Times story by reporter Frank Main documenting the same broker market, and CNET amplified the story nationally on Jan. 20, 2006.

How the Attack Worked

Web-based data broker sites such as LocateCell.com and CellTolls.com advertised the ability to produce a target's cell-phone call log for a fee, needing only the target's phone number and a credit card. Behind the storefront, these brokers (or subcontracted "information specialists," later identified in FCC/FTC actions as firms like 1st Source Information Specialists) used pretexting: broker employees called the carrier's customer service line impersonating the account holder (or otherwise misrepresenting their identity/authority), supplying enough guessed or researched identifying details to pass the carrier's weak verbal verification, and induced the customer-service rep to read out or fax the call detail records. The broker then repackaged that data and sold it to the online purchaser within about 24 hours, no additional identity proof required from the buyer.

The Lure & the Tell

The "lure" operated on two levels. First, the data-broker sites themselves lured paying customers with a simple e-commerce promise: "give us any phone number and a credit card, get someone's call log in 24 hours," with no verification of the buyer's relationship to the subject. Second, inside the transaction, the broker's own pretext to the carrier was impersonation of the account holder calling in for routine customer service, a low-friction social engineering script exploiting call-center reps trained to be helpful and not adversarial toward callers who "sound like" the customer. The "tell": John Aravosis publicly disclosed the entire transaction himself on AMERICAblog on Jan. 12, 2006, explicitly as a deliberate proof-of-concept. He first bought his own Cingular Wireless records for $110, then bought Gen. Clark's for $89.95 specifically to demonstrate that even a high-profile, national-security-relevant figure's private communications metadata (calls to Arkansas, to foreign countries, to a Washington Post reporter) could be trivially bought by anyone. He verified authenticity by calling Clark's number and hearing Clark's own voicemail greeting, then contacted Clark to disclose what he'd done.

Outcome

The Jan. 2006 disclosure (following a Jan. 5, 2006 Chicago Sun-Times story by Frank Main showing the same broker market) escalated into a national policy scandal. The FTC testified before the House Energy and Commerce Committee ("Phone Records for Sale: Why Aren't Phone Records Safe From Pretexting?", Feb. 1, 2006) and the Senate Commerce Subcommittee on Consumer Affairs, Product Safety, and Insurance ("Protecting Consumers' Phone Records", Feb. 8, 2006), both citing the Clark purchase as the emblematic example. The FTC filed five federal enforcement actions against phone-record broker companies (complaints dated May 1, 2006, publicly announced May 3, 2006). The FCC issued a Notice of Apparent Liability for Forfeiture against 1st Source Information Specialists (d/b/a LocateCell.com). The Senate Commerce Committee's report on S. 2389 (Report 109-253, ordered printed May 9, 2006) cited the $89.95 Clark purchase directly as justification for the bill. Congress passed the Telephone Records and Privacy Protection Act of 2006 (Public Law 109-476), enacted Jan. 12, 2007, criminalizing pretexting to obtain confidential customer phone records. Separately, when Hewlett-Packard's own pretexting scandal broke in Sept. 2006 (disclosed to the SEC Sept. 6, 2006), the House Energy and Commerce Subcommittee on Oversight and Investigations held a follow-on hearing ("Hewlett-Packard's Pretexting Scandal," Sept. 28, 2006) that explicitly built on the legislative momentum the Clark case had already created earlier that year.

Why It Matters

This incident is a textbook demonstration of pretexting as a commercial service: brokers turned carrier social-engineering into a repeatable, priced product (under $100, 24-hour turnaround) sold to any buyer with a credit card. It shows how impersonating an account holder over the phone to a call-center rep, not a technical hack, was sufficient to defeat major carriers' CPNI safeguards. Using a nationally recognizable figure (a retired four-star general and former presidential candidate) as the proof-of-concept converted an obscure privacy/consumer-protection issue into front-page news and direct congressional testimony citations, illustrating how a single well-chosen public-figure target can catalyze federal legislation (Public Law 109-476) faster than abstract harm to ordinary consumers alone. It is also a rare case where the "attacker" (Aravosis) was a journalist/activist deliberately exposing the vulnerability rather than exploiting it maliciously, and it directly set the legislative and public-attention stage that the HP boardroom pretexting scandal (Sept. 2006) then amplified further.

Defenses

The episode exposed that carriers (T-Mobile/Omnipoint, Cingular and others) had weak authentication for releasing Customer Proprietary Network Information (CPNI) over the phone, letting pretexters impersonate account holders to extract call logs. Fixes that followed: FTC filed five federal enforcement actions (complaints dated May 1, 2006, announced May 3, 2006) against data-broker sites; the FCC issued a Notice of Apparent Liability against 1st Source Information Specialists (d/b/a LocateCell.com); the FCC subsequently tightened CPNI rules (password/PIN authentication, notification of account changes, audit trails); Congress passed the Telephone Records and Privacy Protection Act of 2006 (Public Law 109-476, enacted Jan. 12, 2007), which criminalized pretexting to obtain confidential phone records; carriers (Cingular, T-Mobile) also filed civil suits against data brokers. For organizations generally, the case underscores the need for out-of-band verification and knowledge-based/PIN authentication before releasing any account or call-detail data by phone, and awareness that "public figure" status increases resale value of illicitly obtained personal records.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Target selection and number acquisition: The broker needed only the subject's cell number to begin, not privileged access; reporting from the period indicates such numbers circulated through personal contacts, prior press coverage, or public directories, reflecting how low the entry bar was for targeting even a high-profile figure like Gen. Clark.
Countering Stage 1: A public figure's phone number is nearly impossible to fully suppress once it has circulated through contacts, campaigns, or prior reporting; the realistic control is not hiding the number but hardening what a caller can do with it once obtained, which is addressed at Stage 3.
2
Pretext identity-building: Consistent with contemporaneous reporting on the same broker market (commercial data-broker lookup services and cross-referenced personal data such as partial SSNs or dates of birth), brokers and their subcontracted "information specialists" typically assembled enough identifying detail about the account holder to sound plausible to a carrier's phone-based verification process.
Countering Stage 2: Limiting how much identity-verifying data (partial SSNs, dates of birth) commercial data-broker and people-search services expose for lookup or resale reduces the raw material pretexters use to sound convincing; this is a data-minimization control on the broader personal-data industry rather than on the phone carrier itself.
3
Pretext call to the carrier: A broker employee called the carrier's (T-Mobile/Omnipoint's) customer-service line impersonating the account holder and used the gathered details to talk a representative into reading out or faxing the call-detail records, exploiting reps trained to be helpful toward callers who "sounded like" the customer rather than treating the request as adversarial.
Countering Stage 3: This is the core fix. Carriers should require account-specific out-of-band or knowledge-based authentication (a customer-set PIN or password) before releasing CPNI or call-detail records by phone, rather than relying on a caller sounding like the account holder; this is exactly the CPNI rule change (password/PIN authentication, account-change notification, audit trails) the FCC adopted after this episode.
4
Data packaging and storefront listing: The broker aggregated the extracted call log and listed a fee-for-any-target lookup service on a public e-commerce storefront (CellTolls.com / LocateCell.com), advertising fast turnaround with no check on the buyer's identity, intent, or relationship to the subject.
Countering Stage 4: A data broker publicly advertising the sale of any individual's confidential phone records is itself the unlawful, targetable activity that FTC and FCC enforcement went after (five FTC actions in 2006; an FCC forfeiture order against 1st Source Information Specialists d/b/a LocateCell.com); shutting down the storefront removes the resale channel even when a given pretext call succeeds.
5
Commercial purchase and authenticity check: John Aravosis paid $89.95 online with nothing more than Clark's cell number and a credit card, received the 100-call log within about 24 hours, and independently verified it was genuine by calling the number and hearing Clark's own voicemail greeting.
Countering Stage 5: Requiring documented buyer purpose or written customer authorization before a broker or carrier releases any call-detail data mirrors the consent standard Public Law 109-476 later imposed criminally on exactly this no-questions-asked resale model.
6
Disclosure and objective completion: Aravosis published the purchase and the redacted call log on AMERICAblog on Jan. 12, 2006 as a deliberate proof-of-concept, converting the transaction into national exposure that fed directly into FTC and FCC enforcement action and the 2006 federal pretexting law, completing the objective of using a public figure's data to prove the vulnerability at scale.
Countering Stage 6: There is no technical control that prevents public disclosure once leaked data exists in someone's hands. In this case the disclosure itself functioned as the corrective mechanism, converting a hidden vulnerability into congressional testimony and the resulting 2006 law, so the realistic posture for organizations is to plan for responsible/coordinated disclosure norms rather than to assume all such exposure can be prevented.
Quick Facts
Victim
Retired Gen. Wesley Clark (former NATO Supreme Allied Commander Europe, 2004 Democratic presidential candidate); secondarily, T-Mobile/Omnipoint Communications and Cingular Wireless as the carriers whose CPNI-release procedures were exploited
Location
United States (national; purchase transaction online, subject and blogger both US-based)
Date
2005-11-15 to 2006-01-12 (records obtained Nov 15-18, 2005; purchased and publicized by AMERICAblog on/around Jan 12, 2006)
Impact
Direct transaction values were small and personal, not corporate: Clark's 100-call record was purchased for $89.95 from CellTolls.com. Blogger John Aravosis separately paid $110 to LocateCell.com for his own records as a proof-of-concept. The episode's real "cost" was regulatory and legislative: it triggered FTC litigation against five phone-record broker companies (complaints dated May 1, 2006 and publicly announced May 3, 2006) and directly fed a federal law (Public Law 109-476) with compliance and enforcement costs borne industry-wide. No fine amount specific to the Clark purchase itself is documented.
Status
Confirmed
Case Type
Real-World Incident
Sector
Government & Public Sector, Media & Entertainment, Professional & Business Services, Telecommunications
Threat Actor
Organized Crime
Related

Related Cases

Hewlett-Packard Boardroom "Pretexting" Spying Scandal (2006)

To unmask a boardroom leaker, HP's leak investigators and their hired data brokers impersonated directors and journalists to trick phone…

Incident 2005Read →

FTC Pretexting Sweep Against Telephone Record Sellers (2006-2008)

Between 2006 and 2008 the FTC sued 16 data-broker and private-investigation defendants who pretexted telecom carriers, posing as account holders…

Incident 2006Read →

American United Mortgage Company Dumpster Diving / Improper Disposal Case (FTC v. American United Mortgage, 2007-2008)

The FTC's first-ever case under the FACTA Disposal Rule: a Northbrook, Illinois mortgage lender repeatedly dumped intact customer credit reports…

Incident 2006Read →