Hackers flip 6.3 million verizon files for pocket change while victims wait
Sixty-one gigabytes of Russell Cellular’s customer and employee data—names, phone numbers, account PINs, even internal job roles—are circulating on a criminal forum for the price of a mid-range Android phone. The listing went live last weekend; Verizon confirmed an investigation on Monday. Three days later, the carrier’s 750-store partner still has not forced a single password reset.
Why a $1,200 sticker price matters
Low cost, high velocity. Breach brokers know that telecom caches age fast: customers port out, employees quit, secrets stale. At $1,200 the dump is priced to move before counter-measures kick in. Samples inspected by Cybernews pass the smell test—real headers, real Verizon account formats, real employee LDAP strings. One file alone maps 63,000 SIM swap authorizations to unencrypted email addresses. That is not noise; that is a fraudster’s grocery list.
Russell Cellular, based in Bartlesville, Oklahoma, is no roadside kiosk. It is Verizon’s largest indirect agent, processing roughly 12 percent of the carrier’s national activations. A compromise here gives attackers lateral lines into Verizon’s core provisioning systems, including the OSS portal used to flag devices as “retail demo” or “employee test”—a backdoor that bypasses standard fraud alerts.

Inside the silence
Retailers hate admitting leaks; carriers hate admitting they cannot police partners. The result is a vacuum where Reddit threads replace official advisories. One store manager posted that corporate told staff to “keep selling and wait for HR to reach out.” No outreach has arrived. Meanwhile, dark-web buyers are already cross-referencing the employee table with LinkedIn, hunting for high-level Russell admins whose reused passwords might unlock deeper portals.
Verizon’s public statement pledges “active cooperation,” yet the company’s own security notifications page carries no mention of the incident. That omission breaks a pattern: when a corporate store in Tampa was skimmed last year, the carrier blasted SMS warnings within 36 hours. The discrepancy fuels suspicion that indirect breaches are deliberately downplayed to protect the myth that only “corporate” locations carry risk.

What actually works right now
If you activated a line, upgraded a phone, or paid a bill through Russell Cellular since 2019, treat every text or call as hostile. Swap your My Verizon passphrase, disable security questions (they are in the dump), and switch to app-based 2FA—SMS codes are worthless once a SIM swap is queued. Employees should assume corporate email is compromised; personal phones used for work Duo prompts are now pivot points. Freeze your credit not because the leak includes SSNs—it does not—but because account rerouting often precedes new-line fraud that surfaces on bureau reports.
Corporate stores are not immune—Verizon’s own infrastructure was pierced in 2022—but they operate under a single SOC umbrella with mandatory 24-hour password rotations. Indirect dealers follow looser guidelines, and the FCC does not audit them. Until that gap closes, the cheapest fix is customer vigilance: check your line daily, log out of every Verizon app after use, and never trust a carrier text that starts with “Dear valued subscriber.”
The last time a Verizon partner got popped, the data surfaced six months later in a tax-refund scam that cost Americans $68 million. This dump is fresher, cheaper, and already in circulation. Speed beats scale in today’s fraud economy; the clock started three days ago.
