Illinois Man Pleads Guilty in Snapchat Smishing Attack That Compromised 59 User Accounts
An Illinois man has pleaded guilty to multiple federal criminal charges after orchestrating a sophisticated social engineering campaign that targeted thousands of Snapchat users through SMS phishing attacks.
The case highlights the continued effectiveness of account takeover (ATO) techniques that exploit human trust rather than software vulnerabilities.
According to the U.S. Department of Justice, 27-year-old Kyle Svara of Oswego, Illinois, admitted to charges including aggravated identity theft, wire fraud, computer fraud, and conspiracy for operating a large-scale phishing scheme between May 2020 and February 2021.
Illinois Man Pleads Guilty in Snapchat
The investigation underscores how cybercriminals increasingly rely on social engineering to bypass authentication safeguards and monetize stolen digital accounts.
Federal investigators determined that Svara collected personally identifiable information (PII), including victims’ phone numbers, email addresses, and Snapchat usernames, to launch highly targeted phishing campaigns.
Rather than exploiting technical weaknesses in Snapchat’s infrastructure, the attacker leveraged legitimate authentication processes by impersonating Snap Inc. customer support representatives.
Using anonymized phone numbers and carefully crafted SMS messages, Svara instructed victims to provide one-time verification codes supposedly required to secure or verify their accounts.
This approach exploited users’ trust in official-looking communications while avoiding the need to steal passwords directly.
The campaign targeted more than 4,500 Snapchat users through SMS phishing, commonly known as smishing. Investigators found that approximately 570 victims disclosed their one-time authentication codes after receiving fraudulent messages.
Those verification codes enabled Svara to successfully compromise at least 59 Snapchat accounts by completing legitimate login authentication requests.
Because the authentication codes were genuine and generated by Snapchat’s own security system, the attack effectively bypassed traditional password protections without exploiting software vulnerabilities or malware.
This technique demonstrates how attackers can weaponize legitimate security mechanisms when users are manipulated into revealing authentication credentials.
Following successful account compromise, investigators said Svara accessed victims’ private content, including personal photographs and sensitive media stored within Snapchat accounts.
The stolen information was reportedly sold or traded on underground cybercrime forums where compromised accounts and private data are treated as valuable commodities.
Authorities further revealed that Svara offered account compromise services to other cybercriminals, effectively operating as an attacker-for-hire.
Evidence presented during the investigation showed that he advertised his capabilities on platforms such as Reddit, openly promoting his ability to “get into” Snapchat accounts for paying clients. This business model reflects the growing commercialization of cybercrime services within underground marketplaces.
The investigation also uncovered disturbing evidence that some of the stolen material included child sexual abuse material (CSAM), significantly increasing the severity of the criminal case and associated federal charges.
Additionally, prosecutors identified a conspiracy involving Steve Waithe, a former Northeastern University track and field coach, who allegedly hired Svara to target specific individuals, including student-athletes with whom he had direct professional relationships.
The involvement of a trusted insider illustrates how personal knowledge and contextual intelligence can substantially improve the effectiveness of targeted phishing operations, blurring the lines between insider threats and external cybercriminal activity.
From a cybersecurity perspective, the case serves as a reminder that one-time passcodes delivered via SMS remain vulnerable to social engineering attacks despite providing stronger protection than passwords alone.
Security experts continue to recommend phishing-resistant authentication methods such as hardware security keys based on the FIDO2/WebAuthn standard or app-based authenticators that generate time-based one-time passwords (TOTP).
Organizations should also implement continuous security awareness training that teaches users to recognize impersonation attempts, verify unsolicited communications through official channels, and never disclose authentication codes to anyone claiming to represent technical support.
Combined with behavioral monitoring, anomaly detection, and adaptive authentication, these measures significantly reduce the risk of account takeover attacks driven by social engineering.
Svara is scheduled to be sentenced on May 18, 2026. The federal charges carry severe penalties, including up to 20 years in prison for wire fraud, a mandatory minimum two-year sentence for aggravated identity theft, and additional prison terms for computer fraud and conspiracy offenses.
The investigation was led by the FBI with assistance from law enforcement agencies in Chicago and the Oswego Police Department. Authorities continue encouraging potential victims to report related incidents through official FBI reporting channels as investigations into associated cybercriminal activity remain ongoing.
No Comment! Be the first one.