Former AT&T worker accused of SIM-swap scheme targeting $600,000 from victims

1 hour ago 4
Chattythat Icon

A former AT&T worker used employee access for SIM swaps; prosecutors say the conspiracy tried to steal nearly $600,000 from victims’ bank accounts

A cellphone number can appear to be a simple way to reach someone, but it is also often tied to bank accounts, password resets and two factor authentication. Federal prosecutors say a former AT&T retail employee exploited that connection by helping a hacker transfer customers’ phone numbers to devices controlled by criminals.

The scheme allegedly gave co conspirators access to victims’ banking information and enabled fraudulent wire transfers. Three identified victims faced a combined intended loss of at least $593,963, according to court records and the US Department of Justice. As reported by AOL, former Oregon AT&T worker Kenneth Carter was sentenced to 16 months in federal prison and ordered to pay $99,528 in restitution after pleading guilty to conspiracy charges.How SIM swapping worksA SIM swap occurs when a mobile phone number is moved from the legitimate customer’s SIM card to a different SIM card controlled by someone else. Once the transfer is completed, calls and text messages intended for the victim can reach the criminal’s device instead.That can be especially damaging when a bank sends password reset links or security codes by text message. If a criminal already has personal information about the account holder, control of the phone number may provide the final step needed to enter an online bank account.

The attacker can then change passwords, intercept verification messages and attempt to move money.SIM swapping does not necessarily require sophisticated hacking in the traditional sense. Often, the criminal relies on social engineering, stolen personal information or help from someone inside a telecommunications company. An employee with access to customer accounts may be able to make changes that an ordinary outsider could not.That insider access is what made the alleged scheme particularly serious. According to prosecutors, Carter did not merely provide information. He used his position at an AT&T store to carry out unauthorised changes on customer accounts.The alleged role of the former employeeCarter, 44, of Portland, Oregon, worked at an AT&T retail store from May 2018 through November 2019. Prosecutors said a co-conspirator identified potential victims, gathered personal identifying information and sent the details to Carter along with the victims’ cellphone numbers.Carter then allegedly used his employee access to cause AT&T to transfer each victim’s number from the legitimate SIM card to another phone controlled by him or his co conspirators. The criminals could then receive texts and calls meant for the account holder.The co-conspirator allegedly used that control to obtain password reset information and two-factor authentication codes for online bank accounts. Those details were then passed to another participant, who accessed the accounts and arranged fraudulent wire transfers.The indictment and plea materials describe a division of labour. One person gathered information, Carter performed the telecommunications changes and other conspirators used the stolen access to target bank accounts. Prosecutors said Carter and others typically received between $1,000 and $2,000 for each SIM swap.Nearly $600,000 in intended lossesThe case involved at least three identified victims, who prosecutors said faced a combined intended loss of $593,963.

One victim had nearly $100,000 transferred to a Portuguese bank account controlled by co-conspirators. Carter was ordered to pay $99,528 in restitution connected to that loss.The term “intended loss” is important in federal cases. It refers to the amount the conspirators sought or attempted to steal, not necessarily the amount that successfully left every victim’s account. Prosecutors said fraud prevention systems at some banks stopped additional transfers before the money could be wired overseas.The alleged losses demonstrate why control of a mobile phone number can be so valuable to criminals. A phone number may serve as a gateway to accounts containing far more money than the cost of a phone plan or SIM card. Once the criminal intercepts security messages, the victim may find that familiar protections work against them.The victim may still have a working phone, but it suddenly loses service when the number is transferred.

In other cases, the change may not be immediately noticed, giving attackers time to reset passwords and initiate transfers.Evidence found during the investigationIn November 2019, law enforcement searched Carter’s Oregon residence and found personal identifying information connected to victims, according to prosecutors. The materials included names, cellphone numbers and Social Security numbers.The discovery helped connect the employee’s access to the broader conspiracy.

Carter later admitted that he performed SIM swaps involving other AT&T customers beyond the three victims whose intended losses were detailed in the case.The investigation involved several federal agencies, including the FBI, the FDIC Office of Inspector General and IRS Criminal Investigation. Their involvement reflected the case’s overlap between telecommunications fraud, identity theft and bank fraud.After the investigation, Carter pleaded guilty on March 24, 2026, to one count of conspiracy to commit wire fraud and bank fraud.

A federal judge later sentenced him to 16 months in prison and ordered restitution, as per the report.A breach of trustProsecutors described the conduct as an abuse of employer trust. Carter’s access existed so he could serve legitimate customers, but authorities said he sold that access to a hacker and used it to redirect customers’ phone numbers.The case highlights a difficult security problem for telecommunications companies.

Employees need enough access to resolve account issues, activate devices and make authorised changes. At the same time, that access can become dangerous if internal controls are weak or if employees cooperate with criminals.Companies can reduce the risk through stronger identity verification, detailed audit logs, limits on employee privileges and alerts for unusual account changes. A SIM transfer involving a high value customer account or a recent password reset may deserve additional review.

Employee training and background checks can also play a role, although no single measure eliminates insider threats.For customers, the incident is a reminder that mobile carrier accounts should be treated as part of financial security, not merely as communication services.Why text message security can failMany people use text messages for two-factor authentication because they are convenient. A code sent by text is safer than a password alone, but it depends on the phone number remaining under the customer’s control.

A successful SIM swap breaks that assumption.Security specialists often recommend using an authentication app or a physical security key for important accounts when those options are available. Customers can also ask their carrier about account PINs, port out protections and alerts for SIM changes. These controls may make it harder for an attacker to move a number without the account holder’s knowledge.No security method is perfect, especially when criminals possess personal information from data breaches or social media.

However, using stronger authentication can reduce the damage if a phone number is stolen.Customers should also respond quickly to warning signs. Sudden loss of mobile service, unexpected password reset messages, banking alerts or unfamiliar transactions should be treated seriously. Contacting the mobile carrier and financial institution through verified channels can help limit further loss.The lasting lessonThe alleged scheme shows how cybercrime can combine human access with ordinary digital tools.

The criminals did not need to break through every layer of a bank’s security system if they could first take control of the victim’s phone number. An insider at a telecommunications store made that step possible.For the victims, the consequences extended beyond financial loss. A stolen phone number can expose private messages, disrupt access to email and social accounts, and create weeks or months of recovery work.

For employers, the case demonstrates why access must be monitored even when employees are authorised to use the system.Carter’s sentence closes one part of the case, but the broader risk remains. As more financial services rely on mobile numbers for identity verification, SIM swapping will continue to attract criminals. The best defence combines carrier safeguards, stronger account authentication, bank fraud monitoring and careful protection of personal information.

Read Entire Article