{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:20:21.301Z","total":1,"returned":1,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"Mobile carrier employee took $500-a-day bribes to perform SIM swaps","date":"2018-10","date_precision":"month","victim_org":"Unnamed US mobile carrier ('Phone Company A') and at least 19 of its customers","sector":"Telecom","country":"United States","primary_vector":"Insider Recruitment","secondary_vectors":["SIM Swap"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported.","outcomes":["Insider Access","Identity Theft","Cryptocurrency Theft"],"loss_usd":null,"loss_note":"DOJ did not state aggregate victim losses in the charging announcement. Defiore received approximately $2,325 across twelve bribe payments, at roughly $500 per day of swaps.","records_affected":19,"threat_actor":"Stephen Daniel Defiore and unnamed co-conspirators","summary":"A US Attorney's Office charged a former mobile phone company employee with accepting bribes to perform unauthorized SIM swaps on customer accounts. Between October 20 and November 9, 2018, a co-conspirator sent him customer phone numbers, four-digit PINs and destination SIM numbers, and he executed the swaps from inside the carrier's systems. At least 19 customers were targeted in the wider conspiracy, including a New Orleans physician.","how_it_worked":"The deceived party here was the carrier itself, not a customer. Rather than talk a retail rep into a fraudulent swap, the conspiracy simply put one on payroll. A co-conspirator messaged Defiore a target's phone number, account PIN and the SIM identifier to swap the line to; Defiore, who worked at the carrier from August 2017 to November 2018, used his legitimate employee access to execute the change and was paid roughly $500 per day. Because the change was made by an authorized account with a valid business reason on its face, none of the carrier's customer-facing verification controls applied. The hijacked numbers then received the victims' SMS authentication codes.","lessons":"SIM-change transactions need behavioral monitoring on the employee side, including per-rep swap-rate baselining and out-of-band customer confirmation, since insider abuse looks identical to authorized work in the logs.","confidence":"Confirmed","sources":[{"title":"Former Phone Company Employee Charged for Role in SIM Swap Scam That Targeted at Least 19 Customers","url":"https://www.justice.gov/usao-edla/pr/former-phone-company-employee-charged-rolein-sim-swap-scam-targeted-least-19-customers","publisher":"U.S. Department of Justice"}],"entry_type":"incident","slug":"2018-mobile-carrier-employee-took-500-a-day-bribes-to-perform-sim-swaps","year":2018,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2018-mobile-carrier-employee-took-500-a-day-bribes-to-perform-sim-swaps"}]}