How Kevin Mitnick talked his way into Motorola's source code
One of the most valuable software secrets in the 1990s cellphone business did not leak through a hacked server. A fugitive got it by making phone calls.[1] This case file covers why he wanted the code, how talking was enough to get it, how his run ended, and the one control that was missing.
What happened
In 1992, Kevin Mitnick was already a wanted man. He had been in trouble with the law over computer intrusions for years, and to stay out of sight he was living in Denver under a false name.[1]
At the time, Motorola's MicroTAC Ultralite was one of the most desirable cellphones in the world, a small flip phone that was the flagship of its day.[1] Mitnick wanted the software that ran it. His reason, as he later explained it, was practical rather than commercial: with the source code, he hoped to change how the phone identified itself to the network and make it harder for investigators to track him through cell towers.[1]
He got the code by phone. Rather than breaking through Motorola's defenses with technical tricks, he called the company and persuaded people there to help him, a technique known as social engineering.[1] The calls worked, and he came away with the source code for the phone.[1]
How it worked
Social engineering means manipulating people, rather than machines, into giving up access or information. The attacker plays a role: a coworker from another office, a manager in a hurry, a support technician fixing a problem. The target hears a plausible story, a familiar-sounding name and perhaps a bit of inside jargon, and helps.
What made this possible was not a software flaw. It was a gap in process. If the only thing standing between a caller and a sensitive file is the caller's own description of who they are, then anyone who sounds confident and knows enough about the company can get through. Large companies with many offices are especially exposed, because staff routinely help colleagues they have never met.
The public record does not describe exactly who at Motorola was called or how the files were sent, and this case file does not guess at those details.[1] The core lesson is simpler: the company's secret was protected by trust in a voice on the phone.
How it was caught
Mitnick stayed on the run for several more years. He was finally arrested by the FBI on February 15, 1995, in Raleigh, North Carolina, after a computer security researcher whose systems he had attacked helped investigators trace him.[2]
The federal indictment accused him of getting into the systems of major technology companies, including Motorola, Nokia, Fujitsu, Novell, NEC and Sun Microsystems, and copying their proprietary software.[2] He spent nearly 5 years in custody before his case was resolved. In March 1999, about a month before trial, he pleaded guilty to 5 of 25 felony counts.[2]
What it cost
Mitnick was sentenced to 3 years and 10 months in prison, which was largely covered by the time he had already served, plus 3 years of supervised release.[2] Prosecutors argued that his intrusions had cost companies millions of dollars, but the judge ordered only $4,125 in restitution, far below the $1.5 million prosecutors had asked for.[2] He was released on January 21, 2000, under conditions that for a time barred him from using the internet, computers or cellphones.[2]
For Motorola, the cost was the loss of control over code it considered one of its most important assets, and the lesson that its protections had a human back door.
The missing control
The missing control: verifying a caller's identity through a separate, trusted channel before sharing anything sensitive, no matter how convincing the caller sounds.
A simple rule would have been enough: before sending source code or any confidential file to someone who asks by phone, look them up in the company directory, call them back on the number listed there, and confirm the request with their manager or the file's owner. A fugitive using a false name could not have passed any of those checks. Limiting who could send core source code at all, and requiring approval from the code's owner, would have added a second barrier.
What to do in your business
- Call back on a known number. When someone asks by phone for files, passwords, payment changes or customer data, hang up and call them back on a number you already have.
- Decide what never goes out on request. List your most sensitive information, such as customer lists, bank details and pricing, and require manager approval before any of it is shared.
- Make it safe to say no. Tell staff that slowing down a caller to verify them will never get them in trouble, even if the caller claims to be a boss.
- Share files through accounts, not attachments. Use shared folders with named access so you can see and revoke who has what.
- Practice once. Run a short training where someone plays a pushy caller, so the team hears what pressure sounds like before it is real.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: Employee offboarding checklist: how to cut off a former employee's access the same day
- Guide: How to verify callers before password resets, and protect your phone number from SIM swaps
- Guide: Which two-step login actually stops phishing, and how a small office rolls it out
- How the SEC's X account was hacked: a fake ID, a SIM swap and no MFA
- How the Colonial Pipeline hack happened: one unused VPN account and no MFA
- How the 2020 Twitter hack happened: a fake help desk call and an admin tool
- How the Mirai botnet knocked Twitter and Netflix offline with factory passwords
- How the Ronin bridge was hacked: a fake job offer and $600 million
- How Uber got hacked in 2022: a stolen password and one tired tap
- Every identity and access control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.