1997
Underground syndicates commercialized "Clone King" EPROM modification kits, allowing widespread cellular subscription fraud and free international calls across North American carriers.
1998
Attackers spoofed ICMP Echo Requests to IP directed-broadcast addresses — including Portuguese academic backbones FCCN/RCTS — producing 100x amplification floods that downed victims' uplinks.
2005
Hackers breached T-Mobile's backend web customer-care interface, gaining unauthorized access to Danger cloud servers and publishing private celebrity phonebooks, SMS logs, and photos.
2007
Automated botnets scanned global IP blocks for exposed SIP UDP port 5060, brute-forcing default extension credentials on Asterisk PBXs to route millions of unauthorized calls to high-cost premium-rate numbers in Somalia, Cuba, and Latvia.
2015
Security researchers published proof-of-concept exploits showing that WebRTC JavaScript APIs in Chrome and Firefox sent unauthenticated STUN packets that bypassed active VPN tunnels and leaked the user's real public and private LAN IP addresses.
2017
Cybercriminals abused SS7 roaming interfaces to intercept bank-issued SMS one-time passcodes (OTPs), draining accounts of customers at O2 Germany and Metro Bank UK.
2019
An attacker only had to ring a WhatsApp call. NSO Group's Pegasus implant was delivered to ~1,400 targets through a buffer overflow in the VoIP call stack — the victim never had to answer, and the missed-call log was the only trace.
2021
Federal indictments exposed international cybercrime rings bribing retail store employees at AT&T, Verizon, and T-Mobile to execute unauthorized SIM swaps, stealing tens of millions of dollars in cryptocurrency.
2024
Attackers executed an unauthorized SIM swap against the phone number tied to the US SEC official X account, broadcasting a fraudulent Bitcoin ETF approval that caused hundreds of millions in market swings.