The Anatomy of a SIM-Swap Breach
In a stark reminder of the risks posed by internal threats, a former AT&T retail worker has been sentenced to 16 months in federal prison for participating in a criminal conspiracy that facilitated massive financial theft. Kenneth Carter, a 44-year-old formerly based in Portland, Oregon, leveraged his authorized access to corporate systems to conduct unauthorized SIM swaps, a tactic that allowed remote attackers to hijack victims' mobile identities to bypass security protocols.
The scheme, which operated between 2018 and 2019, functioned like a precision-engineered attack on financial security. A lead co-conspirator, identified in court records as the operation's "hacker," would source victim data—including sensitive online banking credentials—and relay the information to Carter. Carter would then perform the SIM swap, porting the victim's phone number onto a device controlled by the criminals, typically an inexpensive burner phone. With the phone number under their control, the group successfully intercepted SMS-based two-factor authentication (2FA) codes, effectively locking legitimate users out of their accounts while draining their financial assets.
The Scale of the Fraud
While Carter claimed in a letter to the presiding judge that he earned less than $4,000 for his "side hustle," the financial scope of the operation told a much grimmer story. Federal prosecutors revealed that the conspiracy targeted significant sums of money, with an intended loss total reaching nearly $600,000. Fortunately, the aggressive intervention of banking fraud detection systems prevented the majority of these thefts, stopping over $490,000 in fraudulent transfers from leaving the victims' accounts.
However, one victim was not as lucky. Investigators confirmed that $99,528.33 was successfully siphoned from a victim and transferred to an account in Portugal. Following a raid on Carter's residence in 2019, law enforcement discovered physical evidence of the crime, including the victim's Social Security number and other personal data used to execute the unauthorized swaps. Carter pleaded guilty in March 2026 to conspiracy to commit wire fraud and bank fraud. Beyond his 16-month custodial sentence, the court has ordered him to pay the full $99,528.33 in restitution to the victim.
Why It Matters
- Insider Threats: This case highlights that the most effective firewalls and security software cannot always defend against authorized employees who abuse their administrative privileges.
- SMS Vulnerability: The success of the scheme underscores why security experts have moved toward hardware security keys and app-based authenticators, as SMS-based 2FA is highly susceptible to carrier-level interception.
- Accountable Access: Companies are under increasing pressure to implement stricter "least-privilege" access models to prevent retail-level employees from performing sensitive functions like SIM porting without secondary verification or manual review.
Ultimately, the sentencing serves as a stern warning against the growing "SIM-swap as a service" model. By turning a job function into a criminal enterprise, individuals facilitate a bridge that connects cyber-criminals directly to the pockets of unsuspecting consumers, causing lasting financial and personal damage.











