Snapchat Hacker Receives Six-Year Term
An Illinois man was sentenced to 76 months in federal prison for orchestrating a campaign to compromise 750 social media accounts.
A federal court has handed down a 76-month prison sentence to an Illinois resident who systematically compromised hundreds of personal accounts to harvest explicit imagery. The case highlights a sophisticated exploitation of social engineering, where the perpetrator manipulated trust to bypass security measures and weaponize private data for financial gain and trade.
Methodology of the Breach
Between May 2020 and February 2021, the defendant, 26-year-old Kyle Svara, utilized anonymized phone numbers to impersonate representatives from Snap Inc. By deploying targeted phishing campaigns, he successfully acquired access codes from over 750 women. Once inside an account, the standard procedure involved locking the legitimate owner out by activating two-factor authentication, ensuring the perpetrator maintained exclusive control over the compromised assets.
Scope of the Exploitation
- Targeted more than 4,500 individuals.
- Compromised approximately 517 Snapchat accounts.
- Traded stolen images via the Kik messaging platform.
- Stored approximately 530 images and 600 videos of child sexual abuse material.
Connections to Broader Cyberstalking
The operation was not limited to independent harvesting. Evidence presented in court documents confirms that the perpetrator offered hacking services to third parties. One notable client was Steve Waithe, a former track and field coach who utilized these services to target student-athletes. Waithe was sentenced in March 2024 to five years for his role in the scheme, which involved the theft of photos from over 100 women.
When Svara was interviewed by investigators, he falsely stated that he did not know anything about hacking Snapchat.
— Justice Department
Implications for Account Security
The sentencing underscores the long-term legal consequences for individuals who leverage social engineering to facilitate identity theft and illicit distribution of private media. For users and organizations, this case demonstrates how easily standard account protections can be inverted against the user—specifically, how an attacker can use two-factor authentication as a locking mechanism rather than a security feature. The breadth of the victims, ranging from local neighbors to college students at Colby College, suggests that no demographic is immune to social engineering tactics that bypass technical defenses by targeting the human element of security.
Sources
- BleepingComputer Original source
- court documents Also reporting
- sentenced in March 2024 Also reporting
Continue Reading
ShinyHunters Brand Used in $2K Scams
Threat actors are repurposing publicly leaked data to launch targeted sextortion campaigns demanding Bitcoin payments from breach victims.
Cyber CrimeNewOrigin Energy Investigates Data Breach
Australian energy provider Origin confirms unauthorized access to customer records amid claims of a multi-million user data ransom.
University Ransomware Risks Escalate
Higher education institutions face a shifting threat landscape as specialized ransomware operations increasingly prioritize university targets.