Three SIM-swapping gangs separately claimed multiple times on Telegram to have phished staff at T-Mobile throughout 2022, far more often than other US carriers
Context & Ripple Effects
This report slots into a long arc of T-Mobile security failures: the carrier had already confirmed a breach caused by SIM swap attacks in late 2021, its seventh since 2018, and weeks later disclosed that a hacker had taken data on roughly 37 million customers in an SEC filing. What Krebs adds is attribution texture — three separate Telegram-based gangs independently converged on T-Mobile staff as their preferred phishing target through 2022.
The pattern also fits earlier research flagging that AT&T, T-Mobile, Tracfone, US Mobile, and Verizon all ran vulnerable customer-support procedures that expose users to SIM swapping, and it foreshadows the 2024 indictment of a SIM-swap gang leader whose crew posed as customers in carrier stores and the subsequent texts offering employees up to $300 to perform swaps at T-Mobile and Verizon.
First-order effects
- T-Mobile's internal staff become the demonstrated weak point: multiple criminal groups found phishing its employees more productive than attacking other US carriers, meaning the carrier must treat its own workforce as the compromised perimeter rather than its network edge.
- The Telegram claims give T-Mobile investigators named channels and gang identities to work from, converting what it previously characterized as isolated breaches into evidence of coordinated, repeated campaigns across 2022.
Second-order effects
- Rival carriers face pressure to harden identical support workflows — the 2020 research showed the same vulnerable procedures across AT&T, Verizon, Tracfone, and US Mobile — because gangs demonstrably shop for whichever carrier's staff is easiest to phish.
- A cash-for-swaps insider market becomes visible, later surfacing as the $300-per-swap text offers to T-Mobile and Verizon employees, forcing carriers to police their own support staff as a fraud vector rather than trusting employee access.
Third-order effects
- If gangs keep preferring human targets over technical exploits, carrier identity verification shifts structurally away from SMS-based authentication and call-center trust toward cryptographic or app-based controls, with regulators likely to scrutinize how carriers verify account holders.
- The concentration of breaches at one carrier risks consolidating consumer and enterprise skepticism about which networks are safe for number-linked accounts — banking, crypto, and two-factor flows — turning carrier security posture into a competitive differentiator.
The trend: SIM-swapping crews are shifting from exploiting carrier systems to recruiting and phishing carrier insiders, making employee-facing fraud the defining battleground of mobile identity theft.