Sources: a common practice among bounty hunters and stalkers is to impersonate cops and claim there's a crisis to get real-time cell location data from telcos
In several cases, a stalker impersonated a US Marshal and reported a fake kidnapping in order to get telecom companies to give them real-time cell phone location data. Tweets: @timkarr , @motherboard , @jason_koebler , @josephfcox , @josephfcox , @josephfcox , @jason_koebler , @josephfcox , and @josephfcox Tweets: @timkarr : Bounty hunters & people with histories of domestic violence have managed to trick telecommunications companies into providing real-time location data by simply impersonating US officials over the phone. http://motherboard.vice.com/ ... by @josephfcox @motherboard : Stalkers and debt collectors have impersonated police to trick telecom companies into handing over cell phone location data http://motherboard.vice.com/ ... http://twitter.com/... Jason Koebler / @jason_koebler : These bounty hunters are taking advantage of so-called “exigent circumstances” policies that allow cops to get location data without a court order or search warrant. Telecom companies seem to have few if any policies in place to confirm whether or not person is *actually* a cop Joseph Cox / @josephfcox : The story focuses on a particular case that is backed up with documents and audio, but two independent sources also described other cases of people tricking telecom companies into providing real-time data. To be clear: non-consensual, criminal, abuse https://motherboard.vice.com/ ... pic.twitter.com/kp9ICUAbVg Joseph Cox / @josephfcox : This is how abusers get access to the real-time location of mobile phones (for free too): just contact T-Mobile etc and pretend to a cop who needs the data urgently. Here are messages where one person fabricated child kidnappings, was given location data https://motherboard.vice.com/ ... pic.twitter.com/lJIUO7DVYz Joseph Cox / @josephfcox : In audio of a phone call we obtained, one convicted stalker (also convicted of beating his wife) boasts about how he can quite easily get the real-time phone location data of T-Mobile customers. Also, it seems, other telcoms: “I can do it for all of them” https://motherboard.vice.com/ ... pic.twitter.com/e61L4i5VbU Jason Koebler / @jason_koebler : NEW: Debt collectors and convicted stalkers have been getting real-time cell phone location data directly from big telecom companies by posing as law enforcement and pretending they need the information to, for example, locate a kidnapped child: https://motherboard.vice.com/ ... pic.twitter.com/H2rKiKn2yz Joseph Cox / @josephfcox : New: docs, audio, sources detail how stalkers, bounty hunters, and people w/ a history of domestic violence are tricking T-Mobile, Verizon etc into giving real-time customer location data. The stuff used by cops to find people now in the hands of abusers https://motherboard.vice.com/ ... Joseph Cox / @josephfcox : Updated with FCC comment: “We're investigating carrier practices regarding location information data can't otherwise comment on that investigation.” https://motherboard.vice.com/ ...
Context & Ripple Effects
This report closes a loop Motherboard opened earlier in 2019: its January investigation showed how cheaply middlemen could buy real-time cell location from T-Mobile, Sprint, and AT&T (real-time location data peddled to middlemen), and February's leak documented roughly 250 bounty hunters holding that access at AT&T, T-Mobile, and Sprint for years (250 bounty hunters with carrier location access). What this piece adds is the acquisition method when formal access isn't there — callers simply claim to be US Marshals reporting a kidnapping, and carriers hand over the data.
First-order effects
- Telecom customer-service verification is exposed as the security boundary: a phone call asserting official identity and an emergency is enough to trigger real-time location disclosure, putting any tracked person's whereabouts in a stalker's hands immediately.
- Carriers including T-Mobile face direct reputational and legal exposure, with the FCC already probing how they handle location information.
Second-order effects
- Carriers must harden emergency-data-request verification — callbacks, documentation, authenticated channels — raising friction for legitimate law enforcement too, since the same channel serves both.
- The attack surface migrates rather than closes: by 2022, hackers were using compromised law-enforcement email accounts to send Emergency Data Requests that ISPs and platforms comply with quickly (hacked police emails used for Emergency Data Requests), showing impersonation evolving into account takeover.
Third-order effects
- If the pattern holds, carriers retreat from selling location data to third parties altogether, collapsing the bounty-hunter and middleman market documented in the leak and concentrating access behind verified government channels.
- Emergency Data Request handling becomes a regulated compliance discipline across telecoms, ISPs, and social platforms alike, since every company honoring urgent verbal or emailed requests inherits the same forgery risk.
The trend: Real-time phone location is being pulled back from commercial resale and informal requests toward tightly verified law-enforcement channels, as each impersonation scandal narrows who carriers will trust.