Powered By InformationWeek Business Technology Network
 
Welcome Guest. | Log In| Register | Membership Benefits
  • Email this page E-mail this page
  • |  Print Print this page
  • |   Bookmark and Share

Eight Indicted For $22M Identity Theft Scam Against AT&T, T-Mobile

Defendants allegedly hijacked customers' identities to steal millions of dollars in wireless gear

Aug 20, 2009 | 05:08 PM

By Tim Wilson
DarkReading

Eight defendants were arraigned in a Brooklyn court yesterday for allegedly using the stolen identities of AT&T, T-Mobile, and Asurion customers to steal some $22 million worth of wireless equipment and services.

An indictment was unsealed in Brooklyn federal court yesterday morning charging Courtney Beckford, Gabe Beizem, Rawl Davis, Lennox Lambert, Marsha Montayne, Saul Serrano, Ron Shealey, and Rohan Stewart, with conspiracy to commit mail fraud and wire fraud. Beizem, Montayne, and Stewart were also charged with wire fraud and aggravated identity theft.

According to the indictment, between February 2005 and July 2009, Beizem -- an owner of Got Wireless (aka USA Wireless), a former authorized AT&T and T-Mobile dealer that operated in Brooklyn -- obtained dealer access codes for AT&T's and T-Mobile's online customer databases. Stewart, the owner of KP Wireless -- an authorized T-Mobile wireless device dealer operating in West Palm Beach, Florida -- also obtained dealer access codes for T-Mobile's customer database.

Using these access codes, Beizem, Stewart, and Montayne, and others, allegedly obtained existing customer information from the customer databases, including customers' names, addresses, and personal identifying information, the indictment says. Montayne, and others, then fraudulently assumed the identities of existing customers and obtained new wireless devices without payment and without the customers' permission.

In some cases, the indictment says, the defendants called AT&T and T-Mobile, adding new lines of service to existing customers' accounts, and requesting new wireless devices to support the new lines. In other cases, they allegedly called AT&T and T-Mobile, falsely claiming that a wireless device belonging to an existing customer was damaged or defective and requesting replacements. In still other cases, the defendants allegedly called AT&T and Asurion, falsely claiming that existing customers' wireless devices were lost or stolen and requested new wireless devices under AT&T's insurance program with Asurion.

As a result of these fraudulent requests, AT&T and T-Mobile shipped new or replacement wireless devices for express mail delivery by FedEx, DHL or UPS, according to the indictment. The FedEx and DHL shipments from AT&T were generally shipped to addresses along the routes of private express mail drivers whom Beckford, Davis, Lambert, and Stewart, and others, allegedly recruited and paid to divert the packages.

FedEx and DHL drivers, including Serrano and Shealey, then allegedly scanned the packages into their respective carrier's computerized tracking systems as "delivered" to the stated delivery addresses, but actually diverted the packages to Beckford, Davis, Lambert, and Stewart, and others. UPS shipments from T-Mobile were shipped directly to addresses connected to the defendants and their associates.

Beckford, Beizem, Davis, and Montayne, and others, allegedly then sold the fraudulently obtained wireless devices to others. When charges were incurred on these devices, they were billed to existing AT&T and T-Mobile customers' accounts. When the customers reported or confirmed the fraud on their accounts to AT&T and T-Mobile, the companies absorbed the losses, which included the cost of the devices, insurance payments, shipping costs, and wireless service and other calling charges.

"Identity theft can ruin customers' credit and seriously disrupt their lives," stated U.S. Attorney Benton Campbell. "The type of fraud alleged in the indictment strikes at the very heart of our modern digital economy and imposes substantial costs on commercial businesses. It is a serious problem that requires serious action. Those who commit identity theft can expect to be investigated and prosecuted to the full extent of the law."

If convicted of conspiracy to commit mail fraud and wire fraud, the defendants each face maximum sentences of 20 years of imprisonment. Defendants Beizem, Stewart, and Montayne also face additional mandatory two year consecutive sentences if convicted of aggravated identity theft.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.


Subscribe to RSS



Database Security Reports

report You've Been Breached: Responding to a Database Compromise
Criminals are after your corporate databases, and sometimes, despite your best efforts, they get in and steal credit card numbers, personally identifiable information, proprietary business data or sensitive intellectual property. What do you do then? In this Dark Reading Tech Center report, we discuss the basics of incident response; discovering what was breached, and how; and the best way to protect your assets going forward.

report Beyond the Database: Protecting Unstructured Data
Corporate databases may be the crown jewels, but unstructured data stores contain plenty of diamonds in the rough. Organizations can be burned by an exposed spreadsheet of credit card numbers, an e-mail with patient information or a file share containing reports on a pharmaceutical company's new wonder drug. In this Dark Reading Tech Center report, we show how to classify, find and protect unstructured data across the enterprise.

report Protecting Databases from Web Applications
Most external hacks of databases occur because of flaws in Web applications that link to those databases. Yet, enterprises are increasingly exposing their most valuable data to these outward-facing interfaces. In this Dark Reading Tech Center report, we'll discuss how security teams, database administrators and application developers can work together to improve the defenses of both front-end Web applications and back-end databases to prevent these attacks from succeeding, and offer a look at the most frequent Web-borne database attacks.

Other reports from the Database Security Tech Center:

Related Content

HOWTO Secure and Audit Oracle 10g and 11g
Read the "Hardening Your Database" chapter from the 454-page book "HOWTO Secure and Audit Oracle 10g and 11g" and learn how to navigate the many security options within Oracle (authored by database security expert and Guardium CTO, Ron Ben Natan, Ph.D.)

HOWTO Monitor Database Activity
Read the "Database Activity Monitoring (DAM)" chapter from "HOWTO Secure and Audit Oracle 10g and 11g" (CRC Press, 2009) and learn how to leverage DAM to prevent cyberattacks, monitor privileged users and track access to sensitive data.

8 Steps to Holistic Database Security
Get the 8 essential best practices for a holistic approach to both safeguarding databases and achieving compliance with key regulations such as SOX, PCI-DSS, NIST 800-53 and data protection laws.

Essential Steps to Implementing Database Security and Auditing
Learn best practices and specific tips for effectively securing Oracle, SQL Server, DB2, MySQL and Sybase environments, including tracking security vulnerabilities, the anatomy of buffer overflow vulnerabilities and database auditing.

Databases at Risk: Current State of Database Security (ESG Research)
This recently published ESG report analyzes the current state of database security -- concluding it depends upon too many manual processes -- and also offers concrete steps to improve database security across the enterprise.