Phone Masters, also rendered as Phonemasters, was a U.S.-based hacker ring associated with advanced telephone-system intrusion, phone phreaking, and social-engineering operations. The group became known for penetrating telecommunications company systems, accessing sensitive records, and compromising law-enforcement-related systems. Reported activity attributed to the group included unauthorized access to telephone company infrastructure, abuse of telecom features to disrupt or reroute communications, and intrusion into criminal justice information systems. Members were also linked to manipulation of phone services for harassment and operational disruption, including rerouting an FBI office phone system to a premium-rate service. The group’s tradecraft centered on deep knowledge of telecom operations and procedures combined with persuasive impersonation of carrier personnel. Documented behaviors included social engineering to obtain restricted information, unauthorized access to call-related records, spoofing, and service manipulation. The broader milieu around the group overlapped with SWATing-era abuse of telephony, where attackers made emergency calls appear to originate from victim locations in order to trigger armed police responses. Known members publicly associated with the group include Corey Lindsley, also known as Tabas, described as a purported leader; Calvin Cantrell, also known as Zibby, identified as an early detected member; and Jonathan Bosanac, also known as Gatsby, identified as a member. The actor’s activity was criminal rather than state-directed, with a primary emphasis on unauthorized access, telecom abuse, and acquisition of sensitive information. High-confidence reporting supports capabilities in initial access through social engineering and telecom compromise, credential or access abuse, reconnaissance against phone and account data, spoofing, and post-compromise disruption and information access.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Phone-phreaking group known for compromising telephone systems, including redirecting the local FBI phone system to a phone sex line.
A named hacker ring involved in penetrating telephone company systems, accessing credit reports, and compromising the FBI's NCIC computer.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.