Feeds

Feds crack phone clone scam that cost Sprint $15m

More than 10,000 accounts spoofed

Providing a secure and efficient Helpdesk

Federal prosecutors have uncovered a scam that used tens of thousands of cloned cellphones to defraud Sprint out of $15m in lost long distance revenue.

The operation dates back to at least the latter half of 2009, when cellular customers began complaining that they were billed for international calls they didn't make, according to court documents made public on Wednesday. When Sprint employees looked into the matter, they discovered that many of the calls were made from hundreds of miles away from where the customers lived and within minutes of other calls made from the customers' homes.

Eventually, the Sprint investigators discovered that electronic credentials belonging to “tens of thousands of its customers” were used to make international calls that would have cost $15m had they been billed at the going rate. What's more, many of the defrauded customers' online accounts were breached so that changes could be made to passwords, international calling features and other settings.

The fraud came to light in a criminal complaint that accused nine Sprint employees of illegally accessing customer accounts more than 16,000 times between January and June of this year. Among the information they took were the MSID, or mobile station ID, and the ESN, or electronic serial number, that are used to uniquely identify each handset on the Sprint network. By plugging the credentials into new cellphones, people were able to make phone calls that were charged to the accounts of the defrauded customers.

The complaint didn't identify the cellular carrier, but Sprint officials confirmed the fraud after its name came up during court hearings on Wednesday.

“Sprint regularly monitors and works aggressively to identify and respond to fraudulent activity,” Sprint said in a statement. “The company has been assisting authorities in this case. Should a Sprint customer notice this sort of suspicious activity on their account, we would encourage them to contact our Care representatives for assistance.”

Sprint has credited the defrauded customers for the value of the calls, a press release from the US Attorney in the Bronx, New York, said.

Based on the allegations, the employees charged appear to be low-level operatives who used their access to Sprint's customer database to supply the credentials to people higher up in the scam.

One defendant, Tampa, Florida-based Princetta Dorisma, said a co-worker approached her and offered $1,000 in return for information associated with a range of phone numbers, according to the complaint, which was filed in US District Court for the Southern District of New York. Dorisma received two payments of $500 in exchange for sending the customers' names, cell phone numbers and ESNs associated with each number to an email address specified by the co-worker.

The other defendants named in the complaint are Pedro Rodriguez and Johnny Santana, who worked at Sprint stores in located in the Bronx; Luis Abad, Mathews Angel, Francis Lopez, and Luis Orriols, who worked at a store in North Bergen, New Jersey; and Lesly Esquea and Jacklin Volny, who also worked at a store in Tampa.

They are each charged with one count each of conspiracy to commit wire fraud, access device fraud and aggravated identity theft. If convicted on all counts, they face a maximum of 32 years in prison, in addition to fines. ®

New hybrid storage solutions

More from The Register

next story
Google recommends pronounceable passwords
Super Chrome goes into battle with Mr Mxyzptlk
Apple Pay is a tidy payday for Apple with 0.15% cut, sources say
Cupertino slurps 15 cents from every $100 purchase
Reddit wipes clean leaked celeb nudie pics, tells users to zip it
Now we've had all THAT TRAFFIC, we 'deplore' this theft
YouTube, Amazon and Yahoo! caught in malvertising mess
Cisco says 'Kyle and Stan' attack is spreading through compromised ad networks
TorrentLocker unpicked: Crypto coding shocker defeats extortionists
Lousy XOR opens door into which victims can shove a foot
Greater dev access to iOS 8 will put us AT RISK from HACKERS
Knocking holes in Apple's walled garden could backfire, says securo-chap
Microsoft to patch ASP.NET mess even if you don't
We know what's good for you, because we made the mess says Redmond
NORKS ban Wi-Fi and satellite internet at embassies
Crackdown on tardy diplomatic sysadmins providing accidental unfiltered internet access
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
Top 5 reasons to deploy VMware with Tegile
Data demand and the rise of virtualization is challenging IT teams to deliver storage performance, scalability and capacity that can keep up, while maximizing efficiency.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.