Feeds

Feds crack phone clone scam that cost Sprint $15m

More than 10,000 accounts spoofed

High performance access to file storage

Federal prosecutors have uncovered a scam that used tens of thousands of cloned cellphones to defraud Sprint out of $15m in lost long distance revenue.

The operation dates back to at least the latter half of 2009, when cellular customers began complaining that they were billed for international calls they didn't make, according to court documents made public on Wednesday. When Sprint employees looked into the matter, they discovered that many of the calls were made from hundreds of miles away from where the customers lived and within minutes of other calls made from the customers' homes.

Eventually, the Sprint investigators discovered that electronic credentials belonging to “tens of thousands of its customers” were used to make international calls that would have cost $15m had they been billed at the going rate. What's more, many of the defrauded customers' online accounts were breached so that changes could be made to passwords, international calling features and other settings.

The fraud came to light in a criminal complaint that accused nine Sprint employees of illegally accessing customer accounts more than 16,000 times between January and June of this year. Among the information they took were the MSID, or mobile station ID, and the ESN, or electronic serial number, that are used to uniquely identify each handset on the Sprint network. By plugging the credentials into new cellphones, people were able to make phone calls that were charged to the accounts of the defrauded customers.

The complaint didn't identify the cellular carrier, but Sprint officials confirmed the fraud after its name came up during court hearings on Wednesday.

“Sprint regularly monitors and works aggressively to identify and respond to fraudulent activity,” Sprint said in a statement. “The company has been assisting authorities in this case. Should a Sprint customer notice this sort of suspicious activity on their account, we would encourage them to contact our Care representatives for assistance.”

Sprint has credited the defrauded customers for the value of the calls, a press release from the US Attorney in the Bronx, New York, said.

Based on the allegations, the employees charged appear to be low-level operatives who used their access to Sprint's customer database to supply the credentials to people higher up in the scam.

One defendant, Tampa, Florida-based Princetta Dorisma, said a co-worker approached her and offered $1,000 in return for information associated with a range of phone numbers, according to the complaint, which was filed in US District Court for the Southern District of New York. Dorisma received two payments of $500 in exchange for sending the customers' names, cell phone numbers and ESNs associated with each number to an email address specified by the co-worker.

The other defendants named in the complaint are Pedro Rodriguez and Johnny Santana, who worked at Sprint stores in located in the Bronx; Luis Abad, Mathews Angel, Francis Lopez, and Luis Orriols, who worked at a store in North Bergen, New Jersey; and Lesly Esquea and Jacklin Volny, who also worked at a store in Tampa.

They are each charged with one count each of conspiracy to commit wire fraud, access device fraud and aggravated identity theft. If convicted on all counts, they face a maximum of 32 years in prison, in addition to fines. ®

High performance access to file storage

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Parent gabfest Mumsnet hit by SSL bug: My heart bleeds, grins hacker
Natter-board tells middle-class Britain to purée its passwords
Web data BLEEDOUT: Users to feel the pain as Heartbleed bug revealed
Vendors and ISPs have work to do updating firmware - if it's possible to fix this
OpenSSL Heartbleed: Bloody nose for open-source bleeding hearts
Bloke behind the cockup says not enough people are helping crucial crypto project
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
Experian subsidiary faces MEGA-PROBE for 'selling consumer data to fraudster'
US attorneys general roll up sleeves, snap on gloves
Oz bank in comedy Heartbleed blog FAIL
Bank: 'We are now safely patched.' Customers: 'You were using OpenSSL?'
prev story

Whitepapers

Mainstay ROI - Does application security pay?
In this whitepaper learn how you and your enterprise might benefit from better software security.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Mobile application security study
Download this report to see the alarming realities regarding the sheer number of applications vulnerable to attack, as well as the most common and easily addressable vulnerability errors.