/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Three SIM-swapping gangs separately claimed multiple times on Telegram to have phished staff at T-Mobile throughout 2022, far more often than other US carriers

Krebs on Security Brian Krebs

Context & Ripple Effects

This report slots into a long arc of T-Mobile security failures: the carrier had already confirmed a breach caused by SIM swap attacks in late 2021, its seventh since 2018, and weeks later disclosed that a hacker had taken data on roughly 37 million customers in an SEC filing. What Krebs adds is attribution texture — three separate Telegram-based gangs independently converged on T-Mobile staff as their preferred phishing target through 2022.

The pattern also fits earlier research flagging that AT&T, T-Mobile, Tracfone, US Mobile, and Verizon all ran vulnerable customer-support procedures that expose users to SIM swapping, and it foreshadows the 2024 indictment of a SIM-swap gang leader whose crew posed as customers in carrier stores and the subsequent texts offering employees up to $300 to perform swaps at T-Mobile and Verizon.

First-order effects

  • T-Mobile's internal staff become the demonstrated weak point: multiple criminal groups found phishing its employees more productive than attacking other US carriers, meaning the carrier must treat its own workforce as the compromised perimeter rather than its network edge.
  • The Telegram claims give T-Mobile investigators named channels and gang identities to work from, converting what it previously characterized as isolated breaches into evidence of coordinated, repeated campaigns across 2022.

Second-order effects

  • Rival carriers face pressure to harden identical support workflows — the 2020 research showed the same vulnerable procedures across AT&T, Verizon, Tracfone, and US Mobile — because gangs demonstrably shop for whichever carrier's staff is easiest to phish.
  • A cash-for-swaps insider market becomes visible, later surfacing as the $300-per-swap text offers to T-Mobile and Verizon employees, forcing carriers to police their own support staff as a fraud vector rather than trusting employee access.

Third-order effects

  • If gangs keep preferring human targets over technical exploits, carrier identity verification shifts structurally away from SMS-based authentication and call-center trust toward cryptographic or app-based controls, with regulators likely to scrutinize how carriers verify account holders.
  • The concentration of breaches at one carrier risks consolidating consumer and enterprise skepticism about which networks are safe for number-linked accounts — banking, crypto, and two-factor flows — turning carrier security posture into a competitive differentiator.

The trend: SIM-swapping crews are shifting from exploiting carrier systems to recruiting and phishing carrier insiders, making employee-facing fraud the defining battleground of mobile identity theft.

Discussion

  • @karlbode Karl Bode on x
    T-Mobile's network was compromised 100 times in ONE YEAR! And this is after years of criticism and wrist slap fines for being sloppy on location data collection and SIM hijacking. https://twitter.com/...