SIM swapping does not necessarily require sophisticated hacking in the traditional sense. Often, the criminal relies on social engineering, stolen personal information or help from someone inside a telecommunications company. That insider access is what made the alleged scheme particularly serious. According to prosecutors, Carter did not merely provide information. The alleged role of the former employeeCarter, 44, of Portland, Oregon, worked at an AT&T retail store from May 2018 through November 2019.
Carter then allegedly used his employee access to cause AT&T to transfer each victim’s number from the legitimate SIM card to another phone controlled by him or his co conspirators. The co-conspirator allegedly used that control to obtain password reset information and two-factor authentication codes for online bank accounts. The indictment and plea materials describe a division of labour.
One person gathered information, Carter performed the telecommunications changes and other conspirators used the stolen access to target bank accounts. Nearly $600,000 in intended lossesThe case involved at least three identified victims, who prosecutors said faced a combined intended loss of $593,963. One victim had nearly $100,000 transferred to a Portuguese bank account controlled by co-conspirators.
The term “intended loss” is important in federal cases. It refers to the amount the conspirators sought or attempted to steal, not necessarily the amount that successfully left every victim’s account. The alleged losses demonstrate why control of a mobile phone number can be so valuable to criminals. A phone number may serve as a gateway to accounts containing far more money than the cost of a phone plan or SIM card.
The victim may still have a working phone, but it suddenly loses service when the number is transferred. Evidence found during the investigationIn November 2019, law enforcement searched Carter’s Oregon residence and found personal identifying information connected to victims, according to prosecutors.
The discovery helped connect the employee’s access to the broader conspiracy. The investigation involved several federal agencies, including the FBI, the FDIC Office of Inspector General and IRS Criminal Investigation. After the investigation, Carter pleaded guilty on March 24, 2026, to one count of conspiracy to commit wire fraud and bank fraud. A breach of trustProsecutors described the conduct as an abuse of employer trust.
The case highlights a difficult security problem for telecommunications companies. Employees need enough access to resolve account issues, activate devices and make authorised changes. Companies can reduce the risk through stronger identity verification, detailed audit logs, limits on employee privileges and alerts for unusual account changes. A SIM transfer involving a high value customer account or a recent password reset may deserve additional review.
Why text message security can failMany people use text messages for two-factor authentication because they are convenient. A code sent by text is safer than a password alone, but it depends on the phone number remaining under the customer’s control. Security specialists often recommend using an authentication app or a physical security key for important accounts when those options are available.
Customers can also ask their carrier about account PINs, port out protections and alerts for SIM changes. No security method is perfect, especially when criminals possess personal information from data breaches or social media. Customers should also respond quickly to warning signs. Sudden loss of mobile service, unexpected password reset messages, banking alerts or unfamiliar transactions should be treated seriously.
The lasting lessonThe alleged scheme shows how cybercrime can combine human access with ordinary digital tools. The criminals did not need to break through every layer of a bank’s security system if they could first take control of the victim’s phone number. For the victims, the consequences extended beyond financial loss.
A stolen phone number can expose private messages, disrupt access to email and social accounts, and create weeks or months of recovery work. Carter’s sentence closes one part of the case, but the broader risk remains. As more financial services rely on mobile numbers for identity verification, SIM swapping will continue to attract criminals.