An Illinois man has pleaded guilty to multiple federal charges after orchestrating a large-scale social engineering campaign targeting Snapchat users, exposing persistent risks tied to account takeover (ATO) attacks and SMS-based phishing.
According to the U.S. Attorney’s Office for the District of Massachusetts, 27-year-old Kyle Svara of Oswego, Illinois, admitted to aggravated identity theft, wire fraud, computer fraud, and conspiracy offenses stemming from a coordinated phishing operation conducted between May 2020 and February 2021.
Investigators revealed that Svara harvested victim data, including phone numbers, email addresses, and Snapchat usernames, to facilitate account compromise attempts.
Illinois Man Pleads Guilty to Phishing Snapchat Codes
He then impersonated Snap Inc. support personnel using anonymized phone numbers to send fraudulent messages requesting account verification codes.
More than 4,500 individuals were targeted through SMS phishing, commonly known as smishing. Approximately 570 victims disclosed one-time access codes, enabling Svara to successfully compromise at least 59 Snapchat accounts.
This tactic exploited Snapchat’s legitimate authentication workflow, where security codes are sent to users during login attempts. By convincing victims to share these codes, Svara bypassed account protections without needing passwords.
According to the DOJ, once access was obtained, Svara extracted private content, including sensitive images, which he then sold or traded across underground forums.
The stolen material was also exchanged with other threat actors who had hired him to compromise accounts. Investigators found that Svara actively advertised his services on platforms such as Reddit, promoting his ability to “get into” Snapchat accounts.
Authorities also confirmed that some of the material involved child sexual abuse content (CSAM), significantly increasing the severity of the case and associated charges.
The operation highlights how financially motivated cybercriminals increasingly combine social engineering with commoditized access services, effectively operating within a broader cybercrime marketplace.
The case also uncovered a conspiracy involving Steve Waithe, a former Northeastern University track and field coach, who hired Svara to target specific individuals, including student-athletes with whom he had direct relationships.
This aspect underscores the growing intersection between insider threats and external cybercriminal services, where attackers-for-hire leverage personal familiarity and contextual intelligence to improve phishing success rates.
Svara is scheduled for sentencing on May 18, 2026. The charges carry significant penalties, including up to 20 years in prison for wire fraud, a mandatory minimum sentence of two years for aggravated identity theft, and up to five years each for computer fraud and conspiracy offenses.
The investigation was led by the FBI, with support from law enforcement agencies in Chicago and the Oswego Police Department. Authorities have urged potential victims to report incidents through an official FBI portal to assist ongoing efforts.
This case reinforces several critical cybersecurity lessons. One-time passcodes remain highly susceptible to social engineering attacks, particularly when users are deceived by impersonation tactics.
Organizations and individuals should prioritize phishing-resistant authentication methods, such as app-based authenticators or hardware security keys, and invest in ongoing user awareness training to mitigate the risk of similar attacks.
Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN.