One does not even need to bribe or defraud telecom employees, the biggest gaping hole is the fact that roaming requests are insecure, and SMSes are plaintexted.
On "certain Russian forums" the talk is that was the way how British MPs were deprived of their email mailboxes in 2016. Somebody dug up their IMSIs from leaks and public dbs, and sent roaming requests through Megafon - Russia's biggest telco