The AT&T unlocking scheme: bribed call center staff and 1.9 million phones
For about 7 years, a man in Pakistan paid AT&T's own call center workers to unlock phones, and prosecutors say it cost the carrier more than $200 million across 1.9 million devices.[1] This case file covers how bribes turned into malware inside a customer service floor, how the scheme was finally shut down, and the one control that would have exposed it years sooner.
What happened
In mid-2012, Muhammad Fahd, a citizen of Pakistan and Grenada, reached out on Facebook to an employee at an AT&T call center in Bothell, Washington, using a false name.[1][3] He offered money to unlock phones. A locked phone can be used only on AT&T's network until the customer has finished paying for it or meets the terms of their contract. Unlocking it early lets the customer walk away with the device and stop paying.[2][4]
Fahd recruited more employees at the same center and paid them to submit unlock requests for phones that did not qualify.[1] Over the course of the scheme, the bribes added up to more than $1 million, and one worker alone received about $428,500 over 5 years.[3][4] To make the payments look normal, he had employees set up fake businesses with their own bank accounts and write invoices for services that were never provided.[2]
In spring 2013 AT&T upgraded its unlocking system, which should have ended the scheme. Instead, Fahd hired a software developer and had the bribed employees help plant unauthorized software on AT&T's computers, so the unlocking could be done remotely from Pakistan.[1][2] Prosecutors said the scheme ran from 2012 into 2019.[1]
How it worked
The whole scheme rested on insiders with legitimate access. Call center staff had the power to approve unlocks as part of their job, so their requests looked like ordinary work.[1]
When AT&T tightened the process, the insiders did what outsiders could not. They passed along confidential details about AT&T's systems and installed the malicious software on work computers.[2] According to reporting on the case, the first version recorded what was typed, collecting credentials and network information, and a later version gave the operators remote control. The software then sent unlock requests using real employee credentials, so each one appeared to come from a trusted worker.[3][4] Unlocking was sold as a service to customers who wanted out of their payment plans.[2][3]
How it was caught
AT&T's own investigators eventually noticed. When the company confronted several employees around 2014, they left, and the scheme recruited new ones to keep going.[4] Charges followed in 2017.[1]
Fahd was arrested in Hong Kong in 2018 and extradited to the US in August 2019. He pleaded guilty to conspiracy to commit wire fraud in September 2020.[1] A co-conspirator in Pakistan died before he could be brought to court.[3] Bribed AT&T employees were prosecuted separately.[1] The acting US Attorney described Fahd as a modern cybercriminal who paired technical skill with old-school bribery and intimidation.[2]
What it cost
Forensic analysis found that 1,900,033 phones were unlocked fraudulently, and AT&T's losses came to about $201.5 million.[1] On September 16, 2021, a federal judge in Seattle sentenced Fahd to 12 years in prison and ordered about $200.6 million in restitution.[1][2]
The missing control
The missing control: monitoring what privileged support staff actually do. That means reviewing the actions taken with employee access, such as how many unlocks each person approves, for whom and when, rather than assuming a valid login means valid work.
A handful of workers pushing through large numbers of unlocks for customers who did not qualify is a pattern that stands out in plain numbers. Regular per-employee reports, alerts for unusual volume, and spot checks of approvals against eligibility rules would have flagged the first recruits early. Watching for new software on call center machines, and for requests arriving from outside the building, would have caught the second phase.
What to do in your business
- Know which staff actions cost you money. Refunds, credits, discounts, account unlocks and write-offs are the ones to watch. List who can do each.
- Run a monthly per-person report. Count those actions by employee. Anyone far above their peers gets a friendly question and a closer look.
- Spot-check approvals. Each month, pull 10 random approvals and confirm the customer really qualified.
- Lock down work computers. Stop staff from installing software on customer service machines, and have your IT provider alert you when new programs appear.
- Give people a safe way to report offers. Tell staff plainly that approaches offering money for access happen, and that reporting one is rewarded, not punished.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- How the Hot Lotto was rigged: the security director who wrote the numbers
- The Ubiquiti hack was an inside job: how a senior developer extorted his employer
- How the Coinbase data breach happened: bribed support agents and a $20 million demand
- How one trader brought down Barings Bank: account 88888
- How a Twitter employee sold user data to Saudi Arabia for a watch and cash
- The Tesla insider bribe plot: the $1 million offer an employee reported
- Every insider risk control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- U.S. Department of Justice: Fraudster sentenced to prison for long-running phone unlocking scheme that defrauded AT&T
- U.S. Attorney's Office, Western District of Washington: Pakistan resident sentenced to prison for long-running phone unlocking scheme to defraud AT&T
- The Record: Man who bribed AT&T employees to install malware on the company's network gets 12 years in prison
- GeekWire: Seattle-area AT&T employees bribed to install phone-unlocking malware on company network, authorities say