Telecom Fraud Evidence Matrix

Telecom Fraud Evidence Matrix

Summary. Maps public-source evidence for subscriber-identity and account-takeover paths to harness COAs, defensive controls, and dumpster artifacts. Rows are claims — not verified operator policy.

How to use

Column Meaning
Evidence ID Stable row ID (EV-TF-###)
Finding Defensive claim supported
Source ID Register key (SS-##, SIM-##, IR-##, ATT-##)
COA Harness program that tests the control (A / B / C)
Tabletop Scenario ID from mdmp/17–19
Artifact path Dumpster or harness file
Confidence High / Med / Low — source quality, not exploitability

Fraud-chain overview

flowchart LR
  subgraph identity["Identity obtain"]
    IR[IR-01 Iridium IMSI/MSISDN cleartext]
    SIM[SIM-01 Temp SMS OTP]
    SS[SS-01 Help-desk MFA reset]
  end
  subgraph gate["Human / policy gate"]
    CARE[ATT-01 Care SIM/recovery]
    BPO[ATT-02 BPO workforce]
  end
  subgraph impact["Blast radius"]
    BIZ[ATT-03 Delegated admin bulk]
  end
  IR --> CARE
  SIM --> CARE
  SS --> BPO
  SS --> BIZ
  CARE --> ATO[Account takeover - defensive framing]
  BPO --> ATO
  BIZ --> ATO

Scattered Spider register (SS-01 – SS-06)

Source ID Citation Use in matrix
SS-01 CISA AA23-320A Help-desk vishing, AiTM addendum
SS-02 CISA AA24-190A Infostealer → cloud SaaS
SS-03 Public MGM reporting (Sep 2023) ~10 min help-desk MFA reset chain
SS-04 Public Caesars reporting (Sep 2023) Trusted IT vendor (T1199)
SS-05 UNC3944 telecom/BPO targeting Twilio-era overlap
SS-06 Mobility intake SIMCartel/Hendricks (2026-08-01) OTP + care-channel chain

Evidence matrix

Evidence ID Finding Source ID Type Artifact path Claim supported COA Tabletop Control theme Confidence
EV-TF-001 Scattered Spider obtains enterprise access via help-desk MFA reset after employee impersonation SS-01, SS-03 Advisory + news mdmp/18-scattered-spider-coa-annotations.md IT help desk is primary enterprise front door C RT-TT-C01 No phone MFA reset for privileged; FIDO2 High
EV-TF-002 Reverse vishing pushes RMM (AnyDesk, ScreenConnect) to employees SS-01 Advisory mdmp/18 § V2 Fake-IT prompts must be reported C RT-TT-C01 Simulation reporting + EDR High
EV-TF-003 Trusted IT vendor compromise bypasses victim help desk SS-04 News mdmp/18 Caesars table Vendor VDI/CRM is separate trust boundary C RT-TT-C01 Role cap, offboarding T+60 Med
EV-TF-004 Infostealer creds reach cloud SaaS without help desk SS-02 Advisory mdmp/18 Snowflake Consumer care solid ≠ enterprise safe B RT-TT-B02 Delegated bulk cap, tenant isolation High
EV-TF-005 SIM swap / carrier recovery social engineering parallels SS care pretext SS-05 Industry mdmp/18 § COA-A Care channel is carrier-side MGM analog A RT-TT-07 SIM hold, proof fail-closed Med
EV-TF-006 SIM farm / temp SMS defeats app-layer OTP at scale SS-06, SIM-01 Intake + news dumpster/Mobility/2026-08-01-linkedin-dlaskov-sim-farms/ OTP SMS not possession-proof A (context) Device binding, temp-number intel High
EV-TF-007 SIMCartel seized ~1,200 SIM-boxes, 40k SIMs, sites gogetsms.com / apisim.com SS-06 News 2. Artifacts/securityaffairs-simcartel.html CaaS fraud infra is law-enforcement-visible MNO fraud analytics Med
EV-TF-008 Hendricks demo: live virtual-number OTP registration SS-06 Video meta youtube-lEbD10UsB08-metadata.json SMS OTP bypass is reproducible in talks A (defensive) Rate limits, step-up Med
EV-TF-009 Retention-queue pressure may weaken exception handling ATT-01 Reviews intel/artifacts/workforce-sentiment-dossier.md Queue archetype matters for case design A RT-TT-07 Named approver in CRM Low–Med
EV-TF-010 Stale proof should fail closed before account detail in chat ATT-01 Tabletop mdmp/17 COA-A step 2 AndiVA must not leak on bad proof A RT-TT-07 P1-A02 Plan
EV-TF-011 "Supervisor already approved" urgency without approver ID SS-03, ATT-01 SS case + tabletop mdmp/17 step 4–5 MGM pretext pattern on care side A RT-TT-07 P1-A06 Plan
EV-TF-012 Cross-channel voice + chat attempts must correlate ATT-01 Tabletop mdmp/17 step 6 Repeat calls before success (SS pattern) A RT-TT-07 P1-A09 Plan
EV-TF-013 Delegated admin bulk suspend capped at manifest (3 lines) ATT-03, SS-04 Tabletop mdmp/17 COA-B step 3 Post-compromise blast radius B RT-TT-B02 P2-B03 Plan
EV-TF-014 Cross-tenant object invisible to delegated admin ATT-03 Tabletop mdmp/17 COA-B step 4 Snowflake-style lateral scope B RT-TT-B02 P2-B02 Plan
EV-TF-015 Vendor CRM export blocked with DLP audit ATT-02 Tabletop mdmp/17 COA-C step 4 Insider path after valid vendor session C RT-TT-C01 P3-C03 Plan
EV-TF-016 Vendor offboarding kills access by T+60 ATT-02 Tabletop mdmp/17 COA-C step 5 Caesars-class vendor risk C RT-TT-C01 P3-C05 Plan
EV-TF-017 Iridium L-band exposes IMSI on location update (rare, long capture) IR-01 Research post + video dumpster/Mobility/2026-08-01-linkedin-rifky-ahmad-iridium-imsi-msisdn/ Air-interface identity leak on satellite — (mobility lane) Signaling encryption / TMSI Med
EV-TF-018 Iridium SMS exposes originating MSISDN (+881) — separate from IMSI event IR-01 Research post + video youtube-pScLhSL5ot4-metadata.json Two leaks, not linked pair SMS OA privacy Med
EV-TF-019 Iridium signaling described as GSM-derived, cleartext at ~780 km IR-01 Post text 2. Artifacts/linkedin-post-text.md Satellite segment belongs in mobility model See Theory_Satellite_Telecom_Infrastructure Med
EV-TF-020 Fraud kill switch halts exercise; line state unchanged ATT-01 Tabletop mdmp/17 step 7 Controller SLA A RT-TT-07 P1-A10 Plan

COA quick map

COA Primary evidence rows Facilitator block
A — Consumer care EV-TF-005–012, 020 mdmp/19 Block 2
B — Business admin EV-TF-004, 013–014 mdmp/19 Block 3
C — Workforce/vendor EV-TF-001–003, 015–016 mdmp/19 Block 1 (MGM anchor)

Mobility intake index

Intake folder Rows
dumpster/Mobility/2026-08-01-linkedin-dlaskov-sim-farms EV-TF-006–008
dumpster/Mobility/2026-08-01-linkedin-rifky-ahmad-iridium-imsi-msisdn EV-TF-017–019
offsec-pipeline/.../att-callcenter-2026-07-31/mdmp/ EV-TF-009–016, 020

Harness artifacts

Open gaps

00-index · Theory_Threat_Model · Theory_Satellite_Telecom_Infrastructure