{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2018-joel-ortiz-gets-10-years-for-7-5m-sim-swap-crypto-theft-spree"},"incident":{"title":"Joel Ortiz gets 10 years for $7.5M SIM-swap crypto theft spree","date":"2018","date_precision":"year","victim_org":"Approximately 40 individual cryptocurrency holders","sector":"Cryptocurrency","country":"United States","primary_vector":"SIM Swap","secondary_vectors":["Help Desk Impersonation","Insider Recruitment"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported.","outcomes":["Cryptocurrency Theft","Identity Theft"],"loss_usd":7500000,"loss_note":"CoinDesk reported thefts exceeding $7.5 million across roughly 40 victims, including a single May 2018 theft of more than $5.2 million from a Cupertino entrepreneur. Vice reported the aggregate as 'over $5 million'. About $400,000 was recovered at arrest.","records_affected":null,"threat_actor":"Joel Ortiz","summary":"Joel Ortiz, a 21-year-old college student, pleaded no contest to ten felony theft counts after hijacking the phone numbers of roughly 40 cryptocurrency holders and draining their wallets. He was sentenced to ten years in prison by a Santa Clara County judge, in what is widely described as the first US conviction for crypto theft by SIM swapping. The REACT (Regional Enforcement Allied Computer Team) task force investigated.","how_it_worked":"Ortiz and associates identified crypto holders from conference attendance and social media, then attacked their mobile carrier accounts rather than their wallets. Using victim personal data and, in the wider SIM-swap ecosystem the task force mapped, cooperative or deceived retail carrier staff, they had target numbers ported onto SIM cards they controlled. Possession of the number let them intercept SMS one-time passcodes and password-reset links, take over email and exchange accounts, and transfer funds out. One May 2018 swap moved more than $5.2 million within minutes. Proceeds went to club spending, a helicopter rental and designer goods.","lessons":"Carrier port-out PINs and number-lock features, plus app- or hardware-based MFA instead of SMS on exchange accounts, remove the single point of failure this scheme depended on.","confidence":"Confirmed","sources":[{"title":"Student Gets 10-Year Jail Term for SIM-Swap Crypto Thefts Worth $7.5 Million","url":"https://www.coindesk.com/markets/2019/04/23/student-gets-10-year-jail-term-for-sim-swap-crypto-thefts-worth-75-million","publisher":"CoinDesk"},{"title":"Hacker Who Stole $5 Million By SIM Swapping Gets 10 Years in Prison","url":"https://www.vice.com/en/article/hacker-joel-ortiz-sim-swapping-10-years-in-prison/","publisher":"Vice / Motherboard"}],"entry_type":"incident","slug":"2018-joel-ortiz-gets-10-years-for-7-5m-sim-swap-crypto-theft-spree","year":2018,"loss_kind":"aggregate","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2018-joel-ortiz-gets-10-years-for-7-5m-sim-swap-crypto-theft-spree"}}