Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

SIM Swapper Who Stole $20 Million Sentenced to Prison

Nicholas Truglia, of Florida, was sentenced to 18 months in prison last week for stealing more than $20 million in a SIM swapping scheme.

According to the indictment, in January 2018, Truglia, now aged 25, participated in a scheme to hack into online accounts in an effort to steal cryptocurrency. He pleaded guilty in late 2021.

Nicholas Truglia, of Florida, was sentenced to 18 months in prison last week for stealing more than $20 million in a SIM swapping scheme.

According to the indictment, in January 2018, Truglia, now aged 25, participated in a scheme to hack into online accounts in an effort to steal cryptocurrency. He pleaded guilty in late 2021.

The defendant and other participants to the scheme used SIM swapping to gain unauthorized access to a victim’s accounts, the US Department of Justice announced.

The attackers tricked the victim’s mobile carrier into transferring the victim’s phone number to a SIM in the attackers’ control, which allowed them to reset the passwords for the targeted online accounts.

According to the indictment, one of the compromised accounts contained over $20 million worth of cryptocurrency, which the attackers transferred to accounts owned by Truglia, where the amount was converted to Bitcoin.

The funds were then transferred to other accounts owned by the scheme participants. The defendant kept roughly $673,000 worth of the stolen funds.

The victim is cryptocurrency investor Michael Terpin, who filed a complaint claiming that three million tokens worth $23.8 million had been stolen from his phone in 2018. Terpin won a $75 million civil case against Truglia in 2019. After the incident, Terpin also sued AT&T for failing to prevent the hack, but a court threw out a $200 million damages claim in 2020.

Truglia has now been sentenced to 18 months in prison and three years of supervised release, and was ordered the restitution of more than $20 million. He was also ordered to forfeit nearly $1 million.

Advertisement. Scroll to continue reading.

The DoJ announced Truglia’s sentencing on Thursday, the same day that the Spanish police announced the dismantling of a SIM swapping gang and the arrest of 55 individuals suspected of stealing over $263,000 from more than 100 victims.

Working in four interconnected action cells, the suspects engaged in social engineering, phishing, vishing, carding, and call forwarding techniques to conduct scams. For SIM swapping, the gang relied mainly on vishing, the Spanish police says.

Related: Spanish Authorities Dismantle SIM Swapping Gang

Related: FBI Received 1,600 SIM Swapping Complaints in 2021

Related: Hacker Pleads Guilty to SIM Swapping Attacks, Cryptocurrency Theft

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Mike Dube has joined cloud security company Aqua Security as CRO.

Cody Barrow has been appointed as CEO of threat intelligence company EclecticIQ.

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

More People On The Move

Expert Insights

Related Content

Cybercrime

A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...

Cybercrime

The changing nature of what we still generally call ransomware will continue through 2023, driven by three primary conditions.

Cybercrime

As it evolves, web3 will contain and increase all the security issues of web2 – and perhaps add a few more.

Cybercrime

Luxury retailer Neiman Marcus Group informed some customers last week that their online accounts had been breached by hackers.

Cybercrime

Zendesk is informing customers about a data breach that started with an SMS phishing campaign targeting the company’s employees.

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Artificial Intelligence

The release of OpenAI’s ChatGPT in late 2022 has demonstrated the potential of AI for both good and bad.

Cybercrime

Satellite TV giant Dish Network confirmed that a recent outage was the result of a cyberattack and admitted that data was stolen.