CSIDB logo
Threat actor

Muhammad Fahd

Attribution profile

Type
Crime Syndicate
Location
Pakistan
Known incidents
1 incident
First seen
2012-04-01
Last seen
2012-04-01
Updated
2026-07-31 07:52
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Muhammad Fahd, also known by the alias Muhammad Fahd, is a Pakistani national who came to public attention through a Department of Justice case involving bribery of AT&T employees. The scheme centered on the telecommunications sector in the United States, specifically targeting AT&T’s Mobility Customer Care call center in Bothell, Washington. Fahd and his co‑conspirator paid more than one million dollars in bribes to facilitate the unauthorized unlocking of mobile devices and the deployment of malware on the carrier’s network. The primary objective of the activity, as evidenced by the bribes paid and the reported financial losses exceeding five million dollars annually for AT&T, was financial gain through the illicit resale of unlocked phones.

The operation unfolded in distinct phases that illustrate Fahd’s tactics, techniques, and procedures. Initially, bribed employees were used to unlock high‑value iPhones so they could operate outside AT&T’s network, a process that lasted roughly a year until staff changes disrupted it. In the second phase, Fahd funded the installation of a keylogger malware on AT&T’s internal systems between April and October 2013 to harvest infrastructure data, followed by a second malware strain that automated phone unlocking without further employee interaction. Persistence was later achieved through bribes that led to the deployment of rogue wireless access points in 2014, which provided continued network access. Fahd also operated front companies such as Endless Trading FZE and maintained a website called SwiftUnlocks to monetize the unlocked devices, demonstrating a tooling style that combined illicit service platforms with insider‑enabled malware deployment.

Attribution to Fahd is based on publicly available court documents and law‑enforcement statements; no state sponsorship or affiliation with a larger criminal consortium has been established in the source material. His known associate in the scheme, Ghulam Jiwani, is reported to be deceased. Fahd was apprehended in Hong Kong in February 2018 and subsequently extradited to the United States, where he faces charges that could result in up to twenty years of imprisonment. AT&T has confirmed that customer data was not compromised during the incident, underscoring that the impact was primarily financial and operational rather than a breach of personal information. This case remains the principal publicly reported operation linked to Muhammad Fahd.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB