# Former US Executives Plead Guilty to Operating International Tech Support Fraud Infrastructure
Two former technology executives have admitted to knowingly operating a call-tracking and analytics platform that served as the backbone for a years-long tech support scam operation victimizing vulnerable individuals worldwide. Adam Young, former CEO of C.A. Cloud Attribution, Ltd., and Harrison Gevirtz, former Chief Security Officer, pleaded guilty to misprision of felony charges on May 22, 2026, marking a significant law enforcement victory against the infrastructure providers who profited from fraud rather than perpetrating it directly.
## The Charges and Guilty Pleas
Adam Young, 54, of Miami, Florida, and Harrison Gevirtz, 48, of Las Vegas, Nevada, each face sentences of up to three years in federal prison, fines reaching $250,000, or both when they appear for sentencing on June 16, 2026. The misprision of felony charge—essentially knowingly concealing a federal crime and failing to report it—represents a rare prosecution of enablers rather than the scammers themselves.
According to court filings, Young and Gevirtz operated their company's core services—telephone number provisioning, call recording, call forwarding, and call-tracking analytics—while maintaining explicit knowledge that many of their customers were engaged in telemarketing and tech support fraud. Rather than report these illegal activities to law enforcement, prosecutors allege the executives took deliberate steps to facilitate and conceal the fraudulent operations.
"What the CEO and CSO of this well-known call tracking and analytics company did was downright despicable," said Ted E. Docks, Special Agent in Charge of the FBI's Boston Division. "By their own admission, they willfully profited from telemarketing and tech support scammers, here and abroad, who preyed on the elderly, exploited the vulnerable, and drained victims of their life savings and peace of mind."
## The Infrastructure of Deception
C.A. Cloud Attribution, Ltd. operated from early 2017 through April 2022, providing the technical backbone that enabled scammers to reach victims with unprecedented scale and anonymity. The company's services were not inherently fraudulent—call-tracking platforms have legitimate business uses—but Young and Gevirtz weaponized these tools by deliberately marketing to known fraudsters and helping them evade law enforcement detection.
### How Scammers Used the Platform
The typical victim experience began with a deceptive pop-up advertisement appearing on a personal computer, falsely claiming the system was infected with dangerous malware. The pop-up included phone numbers provided by C.A. Cloud Attribution and directed panicked users to contact "technical support." When victims called, they reached call center agents who:
The scheme operated across borders, with Young and Gevirtz also owning and operating a call center in Tunisia from 2016 through April 2022, where employees directly engaged in tech support fraud, including fraudulently accessing computers via compromised links and sending false invoices.
## Deliberate Obstruction and Facilitation
Rather than cooperate with law enforcement, the executives took deliberate steps to perpetuate the fraud network:
| Action | Purpose |
|--------|---------|
| Advised customers to use rotating telephone numbers | Reduce complaints and prevent account terminations |
| Directed sales staff to target fraud-engaged businesses | Expand the fraudster customer base |
| Introduced fraudsters to one another | Facilitate call buying and selling between scam operations |
| Maintained telecommunications infrastructure | Enable large-scale, coordinated fraud campaigns |
This pattern of assistance suggests Young and Gevirtz understood precisely what they were enabling and chose profit over legal obligation.
## The Scale of Tech Support Fraud
The guilty pleas provide context for a fraud epidemic affecting millions globally. According to the FBI's 2025 Internet Crime Report, Americans alone lost at least $2.1 billion to tech support fraud in 2025, based on data from nearly 48,000 complaints submitted to the FBI's Internet Crime Complaint Center (IC3). The actual losses are likely significantly higher, as many elderly victims never report victimization due to shame, confusion, or lack of awareness.
In August 2024, a single tech support scammer was sentenced to seven years in prison after collecting more than $6 million from at least 6,500 elderly victims across the United States and Canada. That one operator—with C.A. Cloud Attribution's infrastructure supporting thousands of similar schemes—illustrates the epidemic scale of this fraud category.
## Background and Context
Tech support fraud has evolved into one of the most prolific and profitable fraud schemes targeting vulnerable populations, particularly elderly Americans. The scheme's effectiveness stems from several factors:
Technical exploitation: Fraudsters use legitimate remote access software (TeamViewer, AnyDesk) to convince victims they are receiving real technical support, creating a false sense of legitimacy.
Social engineering: Scammers exploit fear—claiming system infections or security breaches—to bypass victim skepticism and induce immediate action.
Infrastructure anonymity: Call-tracking services like C.A. Cloud Attribution enable fraudsters to mask their origin and identity through call forwarding and number spoofing, making law enforcement attribution difficult.
Cross-border operations: By operating call centers in countries with weak regulatory oversight, scammers gain distance from US law enforcement while targeting US victims.
The guilty pleas of Young and Gevirtz represent law enforcement's growing focus on the infrastructure providers enabling fraud at scale, rather than exclusively pursuing individual scammers.
## HackWire Analysis
This case exposes a critical gap in fraud prevention: infrastructure providers occupy a legal and ethical middle ground that too often becomes a zone of profitable plausible deniability. Young and Gevirtz could not claim ignorance—prosecutors demonstrated they deliberately advised customers to rotate phone numbers to avoid detection, a clear indicator of knowing facilitation. Yet infrastructure providers have historically faced less scrutiny than the fraudsters themselves, creating a perverse incentive structure where providing tools to criminals is less risky than using them directly.
The $2.1 billion in annual US losses represents a dramatic undercount of true impact. Elderly victims suffer compounded harm: not only financial loss, but psychological trauma from violated trust and fear of future technology use. Many never recover financially from these thefts, and some die within months of victimization.
More troubling: this case addresses only one call-tracking company. Dozens of similar platforms operate globally, and it remains unknown how many other executives are knowingly facilitating fraud while maintaining plausible deniability. The guilty pleas of Young and Gevirtz should serve as a warning to other infrastructure providers that the "we didn't pull the trigger" defense is no longer viable—knowing facilitation is prosecutable.
For defenders, this case underscores why organizations must implement employee security awareness focused on identifying fraud infrastructure. Users remain the first line of defense against tech support scams, and security training emphasizing skepticism toward unsolicited technical support offers remains the most reliable countermeasure.
— HackWire Editorial
## Implications and Recommendations
For Individuals:
For Organizations:
For Technology Companies:
---
## Related Coverage