LIVE · cybersecurity feed
Live wire
security

Former AT&T store worker jailed after moonlighting as a SIM-swap gang’s inside man

44-year-old Kenneth Carter from Portland, Oregon, used to work in an AT&T retail store. But now he has been sentenced to 16 months in a federal prison. That should be plenty of time for him to rue the day he agreed to increase his monthly income by helping a SIM swap gang in their attempt to steal over half a million dollars. Read more in my article on the Hot for Security blog.

zeroday.news ·

A former AT&T retail store employee, Kenneth Carter, has been sentenced to 16 months in federal prison for his role in a SIM-swapping scheme that aimed to steal over half a million dollars from victims. Carter, 44, of Portland, Oregon, admitted to using his insider access at AT&T to facilitate the fraudulent activities.

According to Carter's plea agreement, the scheme operated from May 2018 to November 2019 and involved at least three co-conspirators. Carter's role was to transfer a victim's phone number to a SIM card controlled by himself or an accomplice. Once the number was hijacked, co-conspirators would initiate password resets for the victim's online banking accounts. The two-factor authentication codes and reset links would then be sent to the criminals' controlled device instead of the victim's. These codes were then forwarded to another gang member who would attempt to log into the accounts and transfer funds, typically to a bank account in Portugal.

In one instance in May 2018, while working a shift in Portland, Carter swapped a victim's number onto an Alcatel handset. A co-conspirator then attempted to wire $247,652.74 from the victim's account, but the transfer was blocked by the bank's fraud detection systems. Another attempt in November 2018, following a SIM swap at an AT&T store in Lancaster, California, involved an attempted transfer of $246,782.70, which was also foiled.

However, not all attempts were unsuccessful. In December 2018, Carter successfully hijacked the number of a victim identified as "S.Q.T." in Portland, resulting in the successful draining of $99,528.33 from their account. Carter's compensation for his involvement typically ranged from $1,000 to $2,000 per SIM swap, with his share from the successful December 2018 theft amounting to $2,000.

Investigators searched Carter's home in November 2019, where they discovered sensitive personal data belonging to victims, including Social Security numbers. Prosecutors stated that the total intended losses from the three identified victims amounted to $593,963.77. Carter also admitted to performing SIM swaps against other AT&T customers beyond those detailed in the plea agreement.

Although the scheme concluded in 2019, Carter was not indicted until 2023, four years after the search of his residence. Authorities noted that such investigations can be lengthy, especially when some members of a conspiracy may still be at large or are being pursued separately.

SIM swapping is a favored tactic among fraudsters due to its reliance on social engineering rather than technical expertise. It often involves tricking customer service representatives into porting a number, or, as in this case, leveraging an insider. Cybersecurity experts advise individuals to enhance their online account security by switching from SMS-based authentication codes to authentication apps or hardware security keys. Additionally, mobile phone carriers often allow customers to set up a PIN or passcode that must be provided before any SIM changes can be authorized.

ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

malware

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and

malware

Iranian spies hit Windows machines with Chosen Brick data-stealing malware

'Enemies of the regime' on notice

patch

Before You Patch. Why Patch Reliability Matters for Confident Deployment

Executive Summary Microsoft’s September 2026 security updates, KB5124008 and KB5124012, have been linked to USB audio failures on some Windows systems, highlighting the operational risk that can accompany security patching. Qualys TruRisk Eliminate classified both updates as Low Reliability, signaling the need for additional validation before production deployment. Patch Reliability helps IT and s