Former AT&T retail employee Kenneth Carter of Portland, Oregon, received a 16-month federal prison sentence for using authorized store-system access to conduct SIM swaps for cybercriminals between May 2018 and November 2019. Carter transferred victims' phone numbers to SIM cards controlled by himself or co-conspirators, allowing them to reset account passwords and intercept SMS-based multifactor authentication codes tied to online banking accounts.
The conspiracy attempted to steal $593,963.77 from three victims. Fraud controls stopped two attempted bank transfers of roughly $247,000 each, but a third victim lost $99,528.33; a 2019 search of Carter's home also recovered victims' sensitive data, including Social Security numbers. The case illustrates the risk of insider-enabled SIM swapping and reliance on SMS-based authentication for high-value financial accounts.

See the reporting duties and controls this puts on the clock.
6 events from the most recent confirmed update back to the earliest known activity.
Carter was indicted in 2023, four years after authorities searched his home, for his role in the SIM-swapping conspiracy.
Authorities searched Carter's home in November 2019 and found sensitive information belonging to victims, including Social Security numbers.
In December 2018, Carter hijacked the phone number of a Portland victim identified as S.Q.T. The conspirators drained $99,528.33 from the victim's account following the SIM swap.
In November 2018, a SIM swap at an AT&T store in Lancaster, California, preceded an attempted transfer of $246,782.70. Bank fraud controls blocked the transfer.
In May 2018, Kenneth Carter used his AT&T store access in Portland to transfer a victim's number to an Alcatel handset. The conspirators then attempted to transfer $247,652.74 from the victim's bank account, but fraud controls blocked it.
Former AT&T retail employee Kenneth Carter was sentenced to 16 months in federal prison for using authorized store-system access to hijack customers' telephone numbers for cybercriminals. The SIM swaps enabled interception of authentication codes and access to victims' bank accounts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
bitdefender.com
Open sourcemalware.news
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.