The 2005 Cell-Phone Records Privacy Scandal: When Data Brokers Sold Call Records

In November 2005, a small mobile-technology blog called Mobility Today ran a short, unsettling post: a Florida television investigation had turned up websites willing to sell a stranger's cell-phone call history for around $100. It wasn't an isolated blog item. It was one of the earliest online mentions of what became a genuine national privacy scandal, one that eventually pulled in the Federal Trade Commission, state attorneys general, the country's biggest wireless carriers, and Congress itself. Here's the history of that scandal: what the data brokers were actually advertising, how they reportedly obtained records, how carriers and regulators fought back, and the federal law that followed.

The 2005 Cell-Phone Records Privacy Scandal: When Data Brokers Sold Call Records
Figure 1 — The 2005 Cell-Phone Records Privacy Scandal: When Data Brokers Sold Call Records

What Was the 2005 Cell-Phone Records Scandal?

By the middle of the 2000s, a market had quietly formed around a strange and troubling product: detailed cell-phone call records belonging to someone other than the customer requesting them. Not public directory listings, and not the kind of name-and-address data people-search sites had traded in for years, but actual call-detail records — the numbers a phone had dialed and received, sometimes with dates and durations attached. That data is supposed to be available only to the account holder and the carrier. Journalists, privacy advocates, and eventually regulators found dozens of websites openly advertising access to it anyway, at prices ranging from roughly $65 for a basic reverse lookup to well over $100 for a full call log.

Data Brokers Selling Call Records Online

The sites themselves were often unremarkable — plain order forms, a short menu of investigative-style services, and a payment page. Many had originally sold conventional skip-tracing and reverse-phone-number lookups, the kind of service built on public and semi-public records. What made the mid-2000s market different was the addition of a new line item: cell-phone call records, sold as a distinct and more expensive product from ordinary lookups. That distinction matters. A reverse lookup draws on records that are, in some form, publicly compiled. A call-detail record comes directly from a telecommunications carrier's protected account systems, and no legitimate public-records process produces it.

What Was Pretexting?

Pretexting is a form of social engineering: creating a false pretext, or cover story, convincing enough that someone hands over information they would never knowingly give to a stranger. In this scandal, journalists and regulators found that data brokers reportedly obtained call records by impersonating account holders or otherwise deceiving carrier customer-service representatives into believing they were speaking with someone entitled to the information. This article isn't going to walk through how that was done — the goal of documenting it historically is to explain why regulators eventually banned it outright, not to describe a replicable method.

Unauthorized Account Access as a General Mechanism

Pretexting phone calls weren't the only method investigators identified. In general terms, some brokers were also reported to have exploited weaknesses in carriers' early online account portals, and in isolated cases to have obtained records through insiders. None of that detail is operational — the point is simply that multiple paths existed for extracting protected data without a customer's knowledge, which is exactly why the eventual legal and technical fixes had to address more than just phone-based deception.

Mobility Today's November 2005 Report

On Monday, November 28, 2005, Mobility Today writer David Ciccone published a post titled "Web Sites Offer Private Cell Phone Information." It pointed to a Florida television investigation, credited to Local 6 News, which had found that websites would sell the last 100 numbers dialed from a target's cell phone for about $100. Ciccone noted that the sites did not appear to be operating illegally under the law as it stood at the time, and advised readers who suspected their own records had been exposed to contact the Florida Attorney General's Office. He also declined to link directly to the sites involved, framing the post as a warning rather than a review — there's no indication in the surviving post that Mobility Today tested the service itself.

What the post did include was a short rundown of the kind of menu these sites were advertising at the time, similar to what the underlying television investigation had described:

Advertised ServiceApprox. PriceWhat It Claimed to Deliver
Reverse cell-phone number lookup$65 (higher for Canadian or international numbers)Name and address matched to a phone number
Find a current cell-phone number$95A working number matched to a name and identifying details
Cell-phone call record$110A log of calls made from a specified cell number

That last item — a full call log sold for a fee, with no indication the requester needed any authorization from the account holder — is the core of why this became a national scandal rather than a footnote about disreputable websites.

LocateCell.com and the Companies Behind the Headlines

Mobility Today's post referenced "Locate Cell" as one of the sites the Florida television report had highlighted, without going into more detail. That reference lines up with the broader public record of the scandal: LocateCell.com, operated by a company called 1st Source Information Specialists, became one of the most frequently cited data brokers in the lawsuits and investigations that followed. Sprint Nextel later sued 1st Source Information Specialists and won a court injunction covering its operation of LocateCell.com and related sites. The overlap between what a small mobile-tech blog flagged in late 2005 and what a major national carrier was suing over within months is a useful reminder of just how visible this practice already was, well before it became a mainstream news story.

EPIC's Early Warnings to Regulators

The Electronic Privacy Information Center, known as EPIC, had been tracking this market before most mainstream outlets caught up. In July 2005, EPIC filed a complaint with the FTC identifying at least 40 websites openly advertising the sale of consumers' calling records. The following month, EPIC separately petitioned the FCC to require carriers to adopt stronger safeguards around calling records, and it followed up with the FTC again in November 2005 — the same month Mobility Today's post ran.

FTC Enforcement Against Data Brokers

The FTC's response escalated through 2006. In May of that year, the agency filed federal court complaints against five web-based operations it accused of obtaining and selling consumers' confidential phone records through pretexting. That October, one of those companies, Integrity Security & Investigation Services, became the first to settle, agreeing to forfeit the roughly $2,700 it had earned from selling phone and credit-card records and accepting a permanent ban on the practice. Additional settlements followed over the next two years, including a case in May 2008 that permanently barred another operation from obtaining or selling consumers' phone records.

Carrier Lawsuits: Cingular, Verizon, Sprint, and T-Mobile

The major wireless carriers didn't wait on regulators. Sprint Nextel, Verizon Wireless, Cingular Wireless, and T-Mobile each filed civil suits against data brokers during 2006, arguing that brokers had posed as customers or otherwise defrauded carrier systems to extract calling records that were then advertised and resold online. Cingular won an injunction barring one broker, eFindOutTheTruth.com, from posing as a Cingular customer or employee for any purpose. Sprint Nextel's suit against 1st Source Information Specialists produced one of the more significant injunctions of the period, directly targeting the operation behind LocateCell.com.

Congressional Concern and Hearings

The scandal reached Capitol Hill through 2006, with House and Senate committees holding hearings on the sale of confidential phone records and on internet data brokers more broadly, including a House Energy and Commerce Committee hearing examining who had access to consumers' private records. Lawmakers from both parties raised concern that domestic-violence survivors, law-enforcement personnel, and ordinary consumers alike could have their calling patterns exposed to anyone willing to pay a fee, without notice and with little existing legal recourse.

Why Call Records Are Considered Sensitive

A list of numbers dialed and received can reveal far more about someone's life than it first appears to. It can show who a person's doctor is, whether they've been calling a divorce attorney, which shelter or hotline they've contacted, who they're seeing romantically, and broadly where they spend their time. Unlike a name and address, which can often be pieced together from ordinary public records, a call log reflects real-time relationships and behavior as they're actually happening. That's why telecommunications carriers are legally required to protect what regulators formally call customer proprietary network information, and why the 2005-2006 scandal was treated as a serious regulatory matter rather than a minor consumer complaint once it came fully into view.

The Telephone Records and Privacy Protection Act of 2006

Congress responded with the Telephone Records and Privacy Protection Act of 2006 (H.R. 4709), which passed in December 2006 and was signed into law by President George W. Bush on January 3, 2007. The law made pretexting to buy, sell, or obtain personal phone records a federal crime for the first time, carrying penalties of up to ten years in prison, with exceptions for authorized law-enforcement and intelligence activity. Before the law passed, California stood alone as the only state with specific statutory protection against phone-record pretexting; afterward, obtaining someone's phone records through deception became a federal offense nationwide.

A Related Scandal: HP's Boardroom Pretexting Case

The same year the phone-records legislation moved through Congress, a separate but related scandal broke: Hewlett-Packard's board had hired investigators who used pretexting to obtain the phone records of board members and journalists while trying to trace the source of leaks to the press. The HP case wasn't part of the consumer-facing data-broker market that Mobility Today, EPIC, and the carriers had been documenting, but the overlapping technique and the timing meant it added considerable political pressure behind the push for a federal pretexting ban.

Lessons for Modern Privacy

The 2005-2006 scandal is worth remembering because the underlying vulnerability — a customer-service process that can be talked into disclosing account data — hasn't disappeared, it has just moved. Modern account-takeover attempts still frequently rely on social engineering rather than purely technical hacking: convincing a support representative, or exploiting a weak identity-verification step, remains one of the more common ways sensitive account data leaks today, across telecom, banking, and other industries. The specific loophole that let 2005-era brokers thrive was largely closed by federal law and stronger carrier verification procedures, but the broader lesson — that human processes are frequently the weakest link in data security — outlived the original scandal by a wide margin.

How to Protect Your Telecom Account Today

Most major carriers now offer account-level protections that didn't widely exist in 2005, and it's worth actually using them. A dedicated account PIN or passcode, required before any changes can be made or information disclosed over the phone, is one of the most effective safeguards available. Carriers also generally offer specific protections against unauthorized SIM swaps and number ports, which are worth enabling proactively rather than after a problem occurs. Beyond that, it's worth treating any unexpected call claiming to be from your carrier's "verification" or "security" team with skepticism, since deception aimed at customer-service systems is still, more than fifteen years later, one of the more common ways account data gets exposed.

It's worth closing on a distinction that's easy to blur, especially for anyone who has also read Mobility Today's guide to a tool like ZabaSearch. Public people-search services compile information that is, by design, drawn from public or semi-public sources — voter registrations, property records, and phone-directory listings people have, at some point, made available in some public context. That's a legally and factually different category of information from a carrier's call-detail records, which document a private relationship between a customer and their telecom provider and are protected by federal law and carrier contract, not simply left to social norms. Nothing about the 2005 scandal means public people-search tools are somehow the same thing as a stolen phone bill, and treating them as equivalent badly understates just how protected call-detail records actually are — and how seriously the law now treats anyone who tries to obtain them through deception.

FAQ

Could websites really sell cell-phone records?

Yes. Through the mid-2000s, multiple websites openly advertised the sale of cell-phone call logs, typically for roughly $100 or more, until FTC enforcement, carrier lawsuits, and the 2006 federal pretexting law shut the practice down.

What was pretexting?

Pretexting was a form of social engineering in which someone used a false cover story to convince a company, or its representatives, to hand over information they wouldn't normally disclose to a stranger. It was one of the methods reportedly used to obtain phone records during this period.

Were call-detail records public?

No. Call-detail records are protected account information generated by a customer's relationship with their carrier, legally distinct from public records like property or voter data.

Why did carriers sue data brokers?

Cingular, Verizon, Sprint Nextel, and T-Mobile each argued that brokers had defrauded their own customer-service systems, often by posing as account holders, in order to extract and resell calling records.

What laws changed afterward?

Congress passed the Telephone Records and Privacy Protection Act of 2006, signed into law in January 2007, making pretexting to obtain phone records a federal crime punishable by up to ten years in prison.

Are private phone records legal to buy today?

No. Obtaining someone else's phone records through deception or unauthorized account access is a federal crime, and no legitimate service today offers to sell another person's private call records.

How can consumers protect their telecom accounts?

Set up a dedicated account PIN, enable any SIM-swap or port-out protection your carrier offers, and treat unexpected calls asking to "verify" account details with skepticism.

The 2005 cell-phone records scandal is a reminder of how quickly a privacy gap can turn into a genuine market, and how much regulatory and legal effort it can take to close it once it does. What started as a handful of websites and a local Florida news investigation — small enough that a mobile-tech blog like Mobility Today could cover it in a single short post — ended up reshaping federal privacy law within about a year. The specific loophole is closed now, but the underlying lesson about human trust being the weakest link in any data system hasn't gone anywhere.

About the Author

Priya Nair

Priya edits buying guides and comparison reviews, translating spec sheets into plain-English recommendations for first-time e-bike and scooter buyers.