Verizon Identity Theft Lawsuit: SIM Swaps and FCC Penalties

The Verizon identity theft lawsuit landscape covers several distinct kinds of cases: customers who sued after Verizon allegedly mishandled reports that imposters opened accounts in their names, federal prosecutions of Verizon store employees who used stolen personal data to create fraudulent accounts, civil suits over SIM swap attacks enabled by insiders, a class action by employees whose own information was exposed in a 2023 breach, and FCC enforcement actions penalizing Verizon for failing to protect customer data. Together they show how identity theft claims against the carrier have played out in court and before regulators.

Class Actions by Customers Whose Identity Theft Claims Were Mishandled

In 2019, California resident Jesse Kaufman filed a proposed class action in the U.S. District Court for the Northern District of California alleging Verizon botched his identity theft claim. According to the complaint in Kaufman v. Verizon Communications Inc. (Case No. 4:19-cv-03888-DMR), an imposter used Kaufman’s personal information to purchase $2,562 worth of equipment from Verizon. Even after Kaufman provided written notice and a police report, Verizon allegedly kept reporting the fraudulent debt to credit bureaus. The suit also alleged that Verizon sent Kaufman a W-9 form and then filed a 1099-C with the IRS listing him as the debtor for a $2,280 “equipment write-off.” Kaufman sought civil penalties, damages, and injunctive relief for a proposed class of California consumers who received similar treatment after reporting identity theft.1Top Class Actions. Verizon Class Action Says Identity Theft Mishandled

A separate case, Sidney v. Verizon Communications, was filed in New York. The plaintiff alleged that in October 2016, an imposter ordered a phone and service at a Best Buy in Wesley Chapel, Florida using his identity, and Verizon then charged his account through autopay without his knowledge or consent. The complaint accused Verizon of maintaining a policy of staying silent about fraud on customer accounts until the customer noticed and complained, and it alleged fraud, breach of contract, and unjust enrichment. It sought damages and injunctive relief on behalf of a nationwide class of consumers similarly charged through autopay without authorization.2ClassAction.org. Identity Theft Attempt Sparks Class Action Over Verizon Fraud Services

Verizon Employees Criminally Charged for Opening Fake Accounts

Some identity theft cases have targeted Verizon employees themselves. In August 2019, a federal grand jury in the Northern District of Georgia indicted seven people, five of them former Verizon store employees, on charges of conspiracy, access device fraud, and aggravated identity theft. Prosecutors alleged that between November 2018 and May 2019, the employees used stolen names, Social Security numbers, and dates of birth to open fraudulent Verizon accounts at stores in Newnan, Buckhead, and Smyrna, Georgia, then used those accounts to buy “tens of thousands of dollars’ worth” of phones and accessories that were left in default. Two other defendants, described as “runners,” supplied the stolen personal data.3U.S. Department of Justice. Five Former Verizon Employees Indicted for Opening Bogus Accounts With Stolen Identity

The case, United States v. Bolden (1:19-cr-00334), was largely resolved through guilty pleas. Edward Bolden Jr., the former general manager of the Newnan store, received 27 months. Roland C. Newell, a former solutions specialist, was sentenced to 24 months plus three years of supervised release, and Eric Gamboa also received 24 months. Marchel D. Robinson and Robert A. Woods each received 18 months. The defendants were ordered to pay restitution to Verizon Wireless ranging from about $78,700 to $130,000, depending on the defendant. The case was terminated in February 2021. Court records list no final disposition for one defendant, Christian R. James.4CourtListener. United States v. Bolden – Parties5CourtListener. United States v. Bolden

SIM Swap Lawsuits Involving Verizon Insiders

Verizon has also been sued over SIM swap attacks, a form of identity theft in which a criminal persuades or bribes a carrier employee to move a victim’s phone number to a new SIM card. That gives the attacker the victim’s calls, texts, and two-factor authentication codes, often opening the door to theft from cryptocurrency or bank accounts.

In Krumdieck v. Coinbase, Inc. et al. (1:23-cv-09556, S.D.N.Y.), plaintiff Raymond Krumdieck alleged that in December 2021, Darryl Jenkins, an assistant manager at a Verizon store in Minnetonka, Minnesota, performed an unauthorized SIM swap that let a hacker steal about $300,000 in cryptocurrency from Krumdieck’s Coinbase account. The complaint alleged Jenkins confessed to participating in SIM swaps for money. Krumdieck sued Verizon and Coinbase for negligence, breach of contract, deceptive business practices, and violations of several federal and state statutes, seeking more than $16 million in combined compensatory, emotional distress, and punitive damages.6Communications Daily. Verizon, Coinbase Negligent in $300K Crypto Hack, Says SIM Swap Victim The case was stayed pending arbitration in April 2024 and voluntarily dismissed with prejudice in September 2025, suggesting a private resolution.7PACER Monitor. Krumdieck v. Coinbase, Inc. et al

Insider involvement in SIM swaps has surfaced in criminal court as well. In May 2019, Verizon employee Fendley Joseph was charged in a federal complaint filed in Michigan with wire fraud for allegedly taking a $3,500 bribe from a SIM-swapping group known as “The Community” in exchange for handing over customers’ personal information. That activity allegedly enabled the theft of $100,000 from a victim.8Fox 5 Atlanta. Fox 11 Tracks Down Verizon Employee Accused of Taking Bribes From SIM Swap Hackers

The 2024 Employee Data Breach Class Action

Identity theft exposure has come from inside the company in another way. In February 2024, former Verizon employee Carlos Malacon filed a class action in the Central District of California (Malacon v. Verizon Communications, Inc., 2:24-cv-01431) after Verizon disclosed that an employee had gained unauthorized access to a file with sensitive information on 63,206 employees. The breach occurred on September 21, 2023, but Verizon didn’t discover it until December 12, 2023, and didn’t notify affected people until February 7, 2024. The exposed data included Social Security numbers, dates of birth, physical addresses, gender, union affiliation, and compensation information. Malacon alleged negligence, breach of fiduciary duties, breach of implied contract, and invasion of privacy, arguing that Verizon’s offer of two years of credit monitoring was “woefully inadequate” given the scope of the exposure. The suit sought actual, statutory, and punitive damages along with court-ordered improvements to Verizon’s data security.9ClassAction.org. Malacon v. Verizon Communications, Inc.

FCC Penalties Over Customer Data

The largest regulatory penalty Verizon has faced in this area came from the Federal Communications Commission. In April 2024, the FCC finalized a $46.9 million forfeiture against Verizon for failing to protect customers’ real-time location data. The action, which began with a Notice of Apparent Liability in February 2020, found that Verizon had sold access to customer location information to data aggregators who resold it to third-party providers, including bail-bond companies and bounty hunters, without valid customer consent.10FCC. FCC Fines Verizon $46M for Location Data Violations11CNBC. U.S. Court Upholds Verizon $46.9 Million Fine Over Location Data The investigation was triggered by reports that a Missouri sheriff had used a location-finding service run by a company called Securus to track people without legal authorization.12FCC. FCC Forfeiture Order – Verizon Location Data

Verizon paid the fine and then challenged it in the Second Circuit, arguing among other things that the data at issue didn’t qualify as Customer Proprietary Network Information under the Communications Act. In September 2025, a three-judge panel rejected every one of Verizon’s arguments, holding that device-location data is CPNI because it is provided “solely by virtue of the carrier-customer relationship,” and that the FCC properly treated Verizon’s conduct as 63 separate continuing violations.13Midpage. Verizon Commc’ns Inc. v. FCC, 156 F.4th 86 (2d Cir. 2025) Verizon then petitioned the U.S. Supreme Court (No. 25-567), and certiorari was granted on January 9, 2026. On June 4, 2026, the Court held that the FCC’s issuance of forfeiture orders without a jury does not violate the Seventh Amendment, reasoning that the orders “do not definitively resolve the parties’ legal obligations” and that the agency’s factual findings “are not conclusive in an enforcement action.”14U.S. Chamber of Commerce. Verizon Communications Inc. v. FCC

Verizon’s fine was part of a broader FCC action. The agency assessed nearly $200 million in total penalties against the four major wireless carriers for the same location-data practices, with T-Mobile fined $80 million, AT&T $57 million, and Sprint (by then acquired by T-Mobile) $12 million.11CNBC. U.S. Court Upholds Verizon $46.9 Million Fine Over Location Data

The location-data penalty wasn’t Verizon’s first FCC action over customer privacy. In September 2014, the company agreed to pay $7.4 million to resolve an investigation into its use of CPNI for marketing. The FCC’s Enforcement Bureau found that beginning in 2006, Verizon had failed to generate required opt-out consent notices for approximately two million customers, effectively using their personal data for marketing before giving them the chance to refuse. Verizon also allegedly waited 126 days to tell the FCC after discovering the problem. The settlement required Verizon to include opt-out notices on every customer bill, put compliance monitoring in place, and report any future CPNI issues to the FCC within five business days. At the time, it was the largest FCC settlement for alleged CPNI misuse.12FCC. FCC Forfeiture Order – Verizon Location Data