{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:13:59.400Z","total":10,"returned":10,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"Manhattan indicts SIM-swap ring that used AT&T and T-Mobile store insiders","date":"2025-11-20","date_precision":"day","victim_org":"AT&T and T-Mobile customers, including four Manhattan residents","sector":"Telecom","country":"United States","primary_vector":"Insider Recruitment","secondary_vectors":["SIM Swap"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported.","outcomes":["Wire Fraud / Financial Loss","Identity Theft","Insider Access"],"loss_usd":435000,"loss_note":"$435,000 stolen from four Manhattan residents, with additional victims identified in other jurisdictions. The indictment covers conduct from October 2021 through July 2022.","records_affected":null,"threat_actor":"Eleven indicted defendants, including AT&T and T-Mobile retail employees Jadakiss Bonilla, Kendrah Vasquez, Amanda Rodado and Jared Moreland","summary":"Manhattan District Attorney Alvin Bragg announced an eleven-defendant indictment on November 20, 2025 against a SIM-swapping and identity theft ring that included four AT&T and T-Mobile retail employees. Between October 2021 and July 2022 the ring stole $435,000 from four Manhattan residents, with further victims elsewhere. The insiders used their employee access to perform the swaps in exchange for payment, and in some cases logged in with coworkers' credentials to obscure their involvement.","how_it_worked":"Ringleaders identified targets and passed their account details to retail store employees on the inside. Rather than talk a rep into a fraudulent swap, the crew paid the reps directly: the store workers used their own authorised access to customer account information to execute the SIM swaps, and in some cases signed in under a coworker's credentials so the audit trail pointed at the wrong person. Once a victim's number was ported to a device the ring controlled, incoming SMS one-time passcodes and password-reset links let them take over bank and payment accounts and move money out through wire transfers and peer-to-peer payment apps before the victim understood why their handset had lost service.","lessons":"Carriers need per-employee SIM-change rate monitoring, mandatory customer confirmation on a second channel, and credential controls that make shared or borrowed logins impossible, since insider swaps look identical to legitimate ones.","confidence":"Alleged","sources":[{"title":"D.A. Bragg Announces Indictment Of SIM-Swapping ID Theft Ring, Including AT&T And T-Mobile Employees","url":"https://manhattanda.org/d-a-bragg-announces-indictment-of-sim-swapping-id-theft-ring-including-att-and-t-mobile-employees/","publisher":"Manhattan District Attorney's Office"}],"entry_type":"campaign","slug":"2025-manhattan-indicts-sim-swap-ring-that-used-at-t-and-t-mobile-store-inside","year":2025,"loss_kind":"aggregate","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-manhattan-indicts-sim-swap-ring-that-used-at-t-and-t-mobile-store-inside"},{"slug":"2025-scattered-spider-member-sentenced-to-10-years-over-sim-swap-and-phishing","title":"Scattered Spider member sentenced to 10 years over SIM swap and phishing thefts","date":"2025-08","date_precision":"month","year":2025,"victim_org":"Cryptocurrency holders and companies targeted by the group","sector":"Cryptocurrency","country":"United States","primary_vector":"SIM Swap","secondary_vectors":["Smishing (SMS)","Credential Phishing Portal","Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Cryptocurrency Theft","Credential Theft","Identity Theft"],"loss_usd":13000000,"loss_kind":"direct_loss","loss_note":"About $13 million in restitution ordered to 59 victims; the figure covers cryptocurrency stolen from individuals.","records_affected":null,"threat_actor":"Scattered Spider","summary":"A Florida federal court sentenced Noah Michael Urban, a member of the Scattered Spider cybercrime group, to 10 years in prison in August 2025 and ordered $13 million in restitution to 59 victims. Urban pleaded guilty to conspiracy, wire fraud and aggravated identity theft over SIM swapping and corporate phishing campaigns that drained cryptocurrency wallets and gave the group access to corporate accounts.","how_it_worked":"The group ran two complementary human-centred plays. For individuals, they gathered personal details, then persuaded mobile carrier staff or used compromised carrier tooling to move a victim's phone number to a SIM they controlled, which handed them the SMS one-time codes protecting exchange and email accounts. For companies, they sent employees text messages claiming an urgent single sign-on or Okta password expiry, pointing at a lookalike portal that captured credentials and MFA codes in real time, and followed up with phone calls impersonating IT to talk hesitant staff through it. Both approaches turned on convincing a person, not breaking software.","lessons":"Carriers need strong port-out and SIM-change protections including account locks; enterprises should replace SMS and push MFA with phishing-resistant authenticators.","confidence":"Confirmed","sources":[{"title":"SIM-Swapper, Scattered Spider Hacker Gets 10 Years","url":"https://krebsonsecurity.com/2025/08/sim-swapper-scattered-spider-hacker-gets-10-years/","publisher":"Krebs on Security"},{"title":"Scattered Spider affiliate given 10 year sentence, ordered to pay $13 million in restitution","url":"https://therecord.media/scattered-spider-affiliate-sentenced-10-years","publisher":"The Record"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-scattered-spider-member-sentenced-to-10-years-over-sim-swap-and-phishing"},{"title":"SIM swap of the SEC's X account posted a fake Bitcoin ETF approval","date":"2024-01-09","date_precision":"day","victim_org":"U.S. Securities and Exchange Commission","sector":"Government","country":"United States","primary_vector":"SIM Swap","secondary_vectors":["Physical Pretexting"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported; the impersonation used a physically printed counterfeit ID card.","outcomes":["Identity Theft","Service Disruption","Wire Fraud / Financial Loss"],"loss_usd":null,"loss_note":"No direct loss to the SEC was published. The fake post moved bitcoin roughly $1,000 higher, then more than $2,000 lower once the SEC disclosed the compromise. Council was paid about $50,000 in bitcoin for performing SIM swaps and was ordered to forfeit that amount.","records_affected":null,"threat_actor":"Eric Council Jr. and co-conspirators","summary":"On January 9, 2024, attackers took over the SEC's @SECgov account on X and posted a false announcement that the agency had approved spot Bitcoin ETFs. Eric Council Jr., 26, of Athens, Alabama, executed the SIM swap that made it possible; he pleaded guilty on February 10, 2025 to conspiracy to commit aggravated identity theft and access device fraud, and was sentenced to 14 months in prison plus forfeiture of $50,000.","how_it_worked":"Council printed a counterfeit identification card on a portable card printer using personal details supplied by co-conspirators, then walked into an AT&T store in Huntsville, Alabama and asked for a replacement SIM for the number tied to the @SECgov account. Store staff issued it against the fake document. He activated the SIM in a newly purchased iPhone, received the password-reset code for the X account, and passed it to the conspirators, who posted the fabricated ETF approval. Bitcoin moved over $1,000 within minutes. The FBI later found fake-ID templates and searches about FBI investigations at his residence.","lessons":"High-consequence institutional social accounts should be secured with hardware security keys rather than SMS-based recovery, and carrier retail ID checks need document-authentication technology rather than visual inspection.","confidence":"Confirmed","sources":[{"title":"Alabama Man Sentenced in Hack of SEC X Account that Spiked the Value of Bitcoin","url":"https://www.justice.gov/usao-dc/pr/alabama-man-sentenced-hack-sec-x-account-spiked-value-bitcoin","publisher":"U.S. Department of Justice"},{"title":"Hacker pleads guilty to SIM swap attack on US SEC X account","url":"https://www.bleepingcomputer.com/news/security/hacker-pleads-guilty-to-sim-swap-attack-on-us-sec-x-account/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2024-sim-swap-of-the-sec-s-x-account-posted-a-fake-bitcoin-etf-approval","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-sim-swap-of-the-sec-s-x-account-posted-a-fake-bitcoin-etf-approval"},{"slug":"2023-sim-swap-of-a-kroll-employee-exposes-ftx-blockfi-and-genesis-claimant-da","title":"SIM swap of a Kroll employee exposes FTX, BlockFi and Genesis claimant data","date":"2023-08-19","date_precision":"day","year":2023,"victim_org":"Kroll","sector":"Professional Services","country":"United States","primary_vector":"SIM Swap","secondary_vectors":["Help Desk Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Credential Theft","Identity Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"Risk advisory firm Kroll disclosed that on 19 August 2023 an attacker transferred a Kroll employee's T-Mobile phone number to a device under their control without Kroll's or the employee's authorisation. Using that number the attacker accessed files containing personal information of bankruptcy claimants of FTX, BlockFi and Genesis, for which Kroll acted as claims agent. Affected claimants were notified and warned about follow-on phishing.","how_it_worked":"The attacker convinced T-Mobile to port a Kroll employee's number to a SIM they controlled, a transfer carried out by a mobile carrier representative acting on a fraudulent request. Once the number was theirs, SMS-based authentication codes for the employee's accounts arrived on the attacker's device, letting them reset access and reach the claimant files Kroll held as bankruptcy administrator. The victims were bankrupt crypto platforms' creditors, a population whose names and contact details are immediately monetisable through targeted phishing about their claims, and several such phishing waves followed the breach.","lessons":"Remove SMS from the authentication path entirely for staff handling sensitive data, and place carrier-level port-out locks on corporate mobile numbers.","confidence":"Confirmed","sources":[{"title":"Kroll Employee SIM-Swapped for Crypto Investor Data","url":"https://krebsonsecurity.com/2023/08/kroll-employee-sim-swapped-for-crypto-investor-data/","publisher":"Krebs on Security"},{"title":"T-Mobile SIM-swapping attack on Kroll employee caused crypto platform data breach","url":"https://therecord.media/sim-swap-attack-caused-crypto-breach","publisher":"The Record"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-sim-swap-of-a-kroll-employee-exposes-ftx-blockfi-and-genesis-claimant-da"},{"title":"Blockchain Capital co-founder loses $6.3M in SIM swap; $14M attempt blocked","date":"2023-05","date_precision":"month","victim_org":"Bart Stephens, co-founder of Blockchain Capital","sector":"Cryptocurrency","country":"United States","primary_vector":"SIM Swap","secondary_vectors":["Help Desk Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported.","outcomes":["Cryptocurrency Theft","Identity Theft","Attempt Blocked"],"loss_usd":6300000,"loss_note":"$6.3 million in bitcoin, ether and other tokens per the civil complaint. A further attempted theft of about $14 million from a cold storage wallet was stopped. Roughly half the stolen funds were routed through mixers.","records_affected":null,"threat_actor":"Unidentified attacker sued as 'Jane Doe'","summary":"Blockchain Capital co-founder Bart Stephens lost $6.3 million in cryptocurrency to a SIM-swap attack in May 2023 and sued the unidentified attacker in the Northern District of California on August 16, 2023. A separate attempt to move about $14 million out of a cold storage wallet was blocked when a Blockchain Capital employee saw the withdrawal notification and intervened. The attacker taunted Stephens, claiming the ability to remotely hijack any phone number in the mainland US.","how_it_worked":"The attacker assembled Stephens's personal details from public sources and dark web data, then used them to pass the identity checks at his mobile carrier, change the account password, order a new handset and port his private cell number to a SIM in that device. Holding the number, the attacker triggered password resets across Stephens's digital wallets and satisfied the SMS second factor on each one, then systematically moved assets out. The one transfer that failed was the cold storage withdrawal, which generated a notification seen by a colleague at the firm who acted before it settled.","lessons":"Removing SMS as a recovery or second factor for any wallet, and routing large withdrawals through a mandatory second-person approval with a time delay, are the two controls that separated the $6.3 million loss from the $14 million save.","confidence":"Reported","sources":[{"title":"Blockchain Capital's Bart Stephens Lost $6.3 Million In SIM-Swap Crypto Hack","url":"https://www.forbes.com/sites/iainmartin/2023/08/21/blockchain-capitals-bart-stephens-lost-63-million-in-sim-swap-crypto-hack/","publisher":"Forbes"}],"entry_type":"incident","slug":"2023-blockchain-capital-co-founder-loses-6-3m-in-sim-swap-14m-attempt-blocked","year":2023,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-blockchain-capital-co-founder-loses-6-3m-in-sim-swap-14m-attempt-blocked"},{"title":"SIM swap at an AT&T store enabled the $400M FTX drain on bankruptcy night","date":"2022-11-11","date_precision":"day","victim_org":"FTX (referred to as 'Victim 1' in the indictment)","sector":"Cryptocurrency","country":"United States","primary_vector":"SIM Swap","secondary_vectors":["Physical Pretexting"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported; the impersonation used a physical fake ID at a retail store.","outcomes":["Cryptocurrency Theft","Identity Theft","Wire Fraud / Financial Loss"],"loss_usd":400000000,"loss_note":"The DOJ indictment concerns a theft of roughly $400 million. FTX administrators reported $413 million in unauthorised transfers, and Elliptic valued the outflow at $477 million. Prosecutors have not officially named FTX as the victim.","records_affected":null,"threat_actor":"Robert Powell ('ElSwapo1', the 'Powell SIM Swapping Crew'), Emily Hernandez, Carter Rohn","summary":"On the night FTX filed for bankruptcy, roughly $400 million in cryptocurrency left its wallets. In February 2024 the DOJ indicted three people over a SIM-swapping conspiracy running from March 2021 to April 2023, including a November 2022 swap against an unnamed 'Victim 1'. Investigators and blockchain analysts concluded from the date, amount and transaction pattern that the victim was FTX.","how_it_worked":"A member of the crew walked into an AT&T retail location carrying a counterfeit ID in the target's name and asked staff to move the number to a new device. The store employee, following normal identity-check procedure against a document that looked genuine, completed the port. From that point every SMS one-time code and password-reset link for the target's accounts arrived on the attackers' handset. The crew used those codes to reach account credentials and then initiated the transfers out of FTX wallets, timed to a night when the company was in bankruptcy chaos and unusual outflows were least likely to be challenged.","lessons":"Enterprise-controlled authentication that never touches a consumer mobile number, combined with number-lock and in-person ID escalation at carrier retail, closes the pathway a physical fake ID otherwise opens.","confidence":"Reported","sources":[{"title":"Arrests in $400M SIM-Swap Tied to Heist at FTX?","url":"https://krebsonsecurity.com/2024/02/arrests-in-400m-sim-swap-tied-to-heist-at-ftx/","publisher":"Krebs on Security"}],"entry_type":"incident","slug":"2022-sim-swap-at-an-at-t-store-enabled-the-400m-ftx-drain-on-bankruptcy-night","year":2022,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-sim-swap-at-an-at-t-store-enabled-the-400m-ftx-drain-on-bankruptcy-night"},{"slug":"2022-lapsus-repeatedly-targeted-t-mobile-staff-to-reach-internal-tools-and-so","title":"LAPSUS$ repeatedly targeted T-Mobile staff to reach internal tools and source code","date":"2022-03","date_precision":"month","year":2022,"victim_org":"T-Mobile US","sector":"Telecom","country":"United States","primary_vector":"SIM Swap","secondary_vectors":["Credential Phishing Portal","Insider Recruitment","MFA Fatigue / Push Bombing"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Insider Access","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"LAPSUS$ (DEV-0537)","summary":"Leaked internal chat logs published by Krebs on Security in April 2022 showed that the LAPSUS$ extortion group repeatedly compromised T-Mobile employee accounts in March 2022. On 19 March the group reached Atlas, an internal T-Mobile tool for managing customer accounts, and used Slack and Bitbucket access to download more than 30,000 source code repositories in about twelve hours. T-Mobile confirmed the intrusion and said no customer or government information was obtained.","how_it_worked":"LAPSUS$ bought T-Mobile VPN credentials from criminal marketplaces and then had to get an attacker-controlled device enrolled in the company's mobile device management, which meant persuading a T-Mobile employee to approve the enrolment. The chats show the group working the human layer persistently: when one employee blocked them, they simply bought another set of credentials and tried the next person. Their sustained interest in T-Mobile staff was that internal tools such as Atlas enable hassle-free SIM swaps, the group's core money-maker. T-Mobile detected the activity and revoked the access tokens.","lessons":"Device enrolment must require a verified, ticketed request rather than a single employee approval, and access to customer-account tooling should be tightly scoped and continuously monitored.","confidence":"Confirmed","sources":[{"title":"Leaked Chats Show LAPSUS$ Stole T-Mobile Source Code","url":"https://krebsonsecurity.com/2022/04/leaked-chats-show-lapsus-stole-t-mobile-source-code/","publisher":"Krebs on Security"},{"title":"T-Mobile Admits Lapsus$ Hackers Gained Access to its Internal Tools and Source Code","url":"https://thehackernews.com/2022/04/t-mobile-admits-lapsus-hackers-gained.html","publisher":"The Hacker News"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-lapsus-repeatedly-targeted-t-mobile-staff-to-reach-internal-tools-and-so"},{"title":"Mobile carrier employee took $500-a-day bribes to perform SIM swaps","date":"2018-10","date_precision":"month","victim_org":"Unnamed US mobile carrier ('Phone Company A') and at least 19 of its customers","sector":"Telecom","country":"United States","primary_vector":"Insider Recruitment","secondary_vectors":["SIM Swap"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported.","outcomes":["Insider Access","Identity Theft","Cryptocurrency Theft"],"loss_usd":null,"loss_note":"DOJ did not state aggregate victim losses in the charging announcement. Defiore received approximately $2,325 across twelve bribe payments, at roughly $500 per day of swaps.","records_affected":19,"threat_actor":"Stephen Daniel Defiore and unnamed co-conspirators","summary":"A US Attorney's Office charged a former mobile phone company employee with accepting bribes to perform unauthorized SIM swaps on customer accounts. Between October 20 and November 9, 2018, a co-conspirator sent him customer phone numbers, four-digit PINs and destination SIM numbers, and he executed the swaps from inside the carrier's systems. At least 19 customers were targeted in the wider conspiracy, including a New Orleans physician.","how_it_worked":"The deceived party here was the carrier itself, not a customer. Rather than talk a retail rep into a fraudulent swap, the conspiracy simply put one on payroll. A co-conspirator messaged Defiore a target's phone number, account PIN and the SIM identifier to swap the line to; Defiore, who worked at the carrier from August 2017 to November 2018, used his legitimate employee access to execute the change and was paid roughly $500 per day. Because the change was made by an authorized account with a valid business reason on its face, none of the carrier's customer-facing verification controls applied. The hijacked numbers then received the victims' SMS authentication codes.","lessons":"SIM-change transactions need behavioral monitoring on the employee side, including per-rep swap-rate baselining and out-of-band customer confirmation, since insider abuse looks identical to authorized work in the logs.","confidence":"Confirmed","sources":[{"title":"Former Phone Company Employee Charged for Role in SIM Swap Scam That Targeted at Least 19 Customers","url":"https://www.justice.gov/usao-edla/pr/former-phone-company-employee-charged-rolein-sim-swap-scam-targeted-least-19-customers","publisher":"U.S. Department of Justice"}],"entry_type":"incident","slug":"2018-mobile-carrier-employee-took-500-a-day-bribes-to-perform-sim-swaps","year":2018,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2018-mobile-carrier-employee-took-500-a-day-bribes-to-perform-sim-swaps"},{"title":"AT&T SIM swap drains $24M in crypto from investor Michael Terpin","date":"2018-01","date_precision":"month","victim_org":"Michael Terpin (individual investor; Transform Group)","sector":"Cryptocurrency","country":"United States","primary_vector":"SIM Swap","secondary_vectors":["Insider Recruitment","Help Desk Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media was reported in this case; the attack relied on carrier account takeover and insider assistance.","outcomes":["Cryptocurrency Theft","Identity Theft"],"loss_usd":24000000,"loss_note":"Approximately $24 million in cryptocurrency at the values cited in Terpin's litigation and contemporaneous reporting. A Los Angeles Superior Court default judgment against Nicholas Truglia totaled $75.8 million including treble RICO damages and prejudgment interest.","records_affected":null,"threat_actor":"Nicholas Truglia and associates; Ellis Pinsky, then 15, later named as a participant","summary":"Cryptocurrency investor Michael Terpin lost roughly $24 million in tokens after attackers took over the mobile phone number tied to his accounts. Terpin sued AT&T, alleging the carrier failed to protect his subscriber information under Section 222 of the Federal Communications Act. He separately won a $75.8 million civil judgment against Nicholas Truglia in what his counsel described as the first SIM-swap racketeering case.","how_it_worked":"Attackers targeted the mobile carrier rather than Terpin directly. According to reporting on the litigation, a then-15-year-old and an accomplice bribed an AT&T employee to move Terpin's SIM information onto a blank SIM card in a phone they controlled. Once the number was theirs, inbound SMS one-time codes and password-reset links flowed to the attackers, letting them reset credentials on Terpin's email and exchange accounts and sweep his holdings. Terpin had reportedly already asked AT&T to place additional protections on the account, which the complaint alleged were not effective against an employee acting from inside the carrier's own systems.","lessons":"Removing SMS from the authentication path for high-value crypto accounts, and enforcing dual-control plus supervisory approval on carrier-side SIM changes, would have broken this chain.","confidence":"Confirmed","sources":[{"title":"Cryptocurrency Investor Michael Terpin Wins $75.8 Million Judgment in First-Ever SIM Swap Racketeering Case","url":"https://www.greenbergglusker.com/news/cryptocurrency-investor-michael-terpin-wins-75-8-million-judgment-in-first-ever-sim-swap-racketeering-case","publisher":"Greenberg Glusker"},{"title":"Court revives 2020 AT&T case over $24M crypto theft via SIM swap","url":"https://cointelegraph.com/news/att-court-sim-swap-crypto-theft","publisher":"Cointelegraph"}],"entry_type":"incident","slug":"2018-at-t-sim-swap-drains-24m-in-crypto-from-investor-michael-terpin","year":2018,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2018-at-t-sim-swap-drains-24m-in-crypto-from-investor-michael-terpin"},{"title":"Joel Ortiz gets 10 years for $7.5M SIM-swap crypto theft spree","date":"2018","date_precision":"year","victim_org":"Approximately 40 individual cryptocurrency holders","sector":"Cryptocurrency","country":"United States","primary_vector":"SIM Swap","secondary_vectors":["Help Desk Impersonation","Insider Recruitment"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported.","outcomes":["Cryptocurrency Theft","Identity Theft"],"loss_usd":7500000,"loss_note":"CoinDesk reported thefts exceeding $7.5 million across roughly 40 victims, including a single May 2018 theft of more than $5.2 million from a Cupertino entrepreneur. Vice reported the aggregate as 'over $5 million'. About $400,000 was recovered at arrest.","records_affected":null,"threat_actor":"Joel Ortiz","summary":"Joel Ortiz, a 21-year-old college student, pleaded no contest to ten felony theft counts after hijacking the phone numbers of roughly 40 cryptocurrency holders and draining their wallets. He was sentenced to ten years in prison by a Santa Clara County judge, in what is widely described as the first US conviction for crypto theft by SIM swapping. The REACT (Regional Enforcement Allied Computer Team) task force investigated.","how_it_worked":"Ortiz and associates identified crypto holders from conference attendance and social media, then attacked their mobile carrier accounts rather than their wallets. Using victim personal data and, in the wider SIM-swap ecosystem the task force mapped, cooperative or deceived retail carrier staff, they had target numbers ported onto SIM cards they controlled. Possession of the number let them intercept SMS one-time passcodes and password-reset links, take over email and exchange accounts, and transfer funds out. One May 2018 swap moved more than $5.2 million within minutes. Proceeds went to club spending, a helicopter rental and designer goods.","lessons":"Carrier port-out PINs and number-lock features, plus app- or hardware-based MFA instead of SMS on exchange accounts, remove the single point of failure this scheme depended on.","confidence":"Confirmed","sources":[{"title":"Student Gets 10-Year Jail Term for SIM-Swap Crypto Thefts Worth $7.5 Million","url":"https://www.coindesk.com/markets/2019/04/23/student-gets-10-year-jail-term-for-sim-swap-crypto-thefts-worth-75-million","publisher":"CoinDesk"},{"title":"Hacker Who Stole $5 Million By SIM Swapping Gets 10 Years in Prison","url":"https://www.vice.com/en/article/hacker-joel-ortiz-sim-swapping-10-years-in-prison/","publisher":"Vice / Motherboard"}],"entry_type":"incident","slug":"2018-joel-ortiz-gets-10-years-for-7-5m-sim-swap-crypto-theft-spree","year":2018,"loss_kind":"aggregate","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2018-joel-ortiz-gets-10-years-for-7-5m-sim-swap-crypto-theft-spree"}]}