# A Social Engineering Scheme That Targeted 4,500 Women — and Had Paying Clients


Kyle Svara did not need zero-days. He needed a phone number he couldn't be traced to, a script claiming to be from Snap Inc., and the patience to send that same message a few thousand times.


On Tuesday, a federal judge in Illinois sentenced the 26-year-old to 76 months in prison — just over six years — plus three years of supervised release for hacking the Snapchat accounts of more than 750 women, stealing explicit photos, and then selling access to other men who wanted him to do the same thing to their targets.


The sentence closes one chapter of a case that is, at its core, a study in how account takeover becomes industrialized — and how the tools platforms built to protect users can be turned against them almost immediately.


## The Mechanics: Impersonation, Scale, Lockout


Between May 2020 and February 2021, Svara contacted more than 4,500 women using anonymized phone numbers while posing as a Snap Inc. representative. The pitch was some variation of account verification — a social engineering lure old enough to have mold on it, but effective against people who have no reason to suspect the person texting them about their account isn't who they claim to be.


When a victim handed over her Snapchat login code, Svara moved immediately. He accessed approximately 517 accounts, downloaded nude or semi-nude photos, and then — and this is the part that made recovery especially difficult — activated two-factor authentication on the compromised accounts before the real owner could get back in.


Think about that sequence. He used the absence of 2FA to get in. Then he used 2FA to keep victims out. A security feature designed to protect users became the padlock on a door he'd just broken through.


That's not an accidental insight. It's a deliberate operational step, the kind that takes someone who has thought through the victim's likely response and designed around it. When investigators caught up with Svara, he told them he knew nothing about Snapchat hacking and had no interest in child sexual abuse material. Both statements were provably false — his Mega.nz account contained approximately 530 images and 600 videos of CSAM.


## The Market He Was Running


What makes this case notable beyond its scale is the commercial layer.


Svara wasn't just collecting for himself. He advertised his services openly, posting offers to "get into girls snap accounts" and directing potential clients to reach him through Kik — the encrypted messaging app that has featured in enough criminal cases to earn its own uncomfortable reputation. He traded stolen images. He accepted payment for access.


One of his documented clients was Steve Waithe, a former track and field coach at Northeastern University. Waithe hired Svara to compromise accounts belonging to Northeastern students — specifically members of the women's track and field and soccer teams. The relationship between a coach with access to athletes and a hacker-for-hire willing to target them on request reveals something grim about how these markets function: the demand side often has existing trust relationships with targets that the technical actor doesn't.


Waithe was convicted separately and sentenced in March 2024 to five years for cyber fraud, cyberstalking, and sextortion after being found guilty of targeting at least 128 women and stealing explicit photos from more than 100 of them.


Two separate prosecutions, two prison sentences, one shared client-contractor relationship. The accountability is real, even if it took years.


## What "Social Engineering at Scale" Actually Looks Like


Coverage of cases like this often centers the sentence and the victim count, which are genuinely important. But the technical pattern deserves more attention, because it does not require sophistication.


Svara's toolkit was: fake phone numbers, a plausible impersonation, and volume. He messaged thousands of people. A fraction responded. That fraction was enough to generate hundreds of compromised accounts and a criminal enterprise.


This is sometimes called a "spray and pray" approach, but that framing undersells the targeting. Svara did not message randomly — he went after women in specific geographic areas, including his own Plainfield, Illinois neighborhood, and students at Colby College in Maine. There was local knowledge layered onto the volume play. He knew who he was going after. The scale just reduced the friction of making contact.


For platforms and users, the lesson is uncomfortable: 2FA codes delivered via SMS or in-app notification are a credential vector, not just a protection mechanism. Snapchat's account recovery flows — like those of every major consumer platform — depend on the assumption that the person requesting a code is the account owner. When that assumption is broken through impersonation, the security feature ships directly to the attacker.


---


## HackWire Analysis


The 76-month sentence will be read by some as appropriate accountability and by others as inadequate given the number of victims — over 750 accounts accessed, more than 4,500 people targeted, CSAM distributed at volume. Both reactions have merit. What the sentence doesn't change is the structural problem the case illustrates.


Account-takeover-as-a-service is not new. What this case shows clearly is the demand-side: people with access to targets — a coach, a neighbor, a classmate — are willing to pay someone else to do the technical work. The hacker provides the capability; the client provides the context. Together they accomplish what neither could as efficiently alone. This is the same logic that powers ransomware-as-a-service ecosystems, just applied to a much more intimate form of harm.


The 2FA weaponization deserves attention from platform security teams specifically. Once an attacker controls an account and enables MFA, account recovery for the legitimate owner becomes a customer service problem — slow, friction-heavy, and often opaque. Platforms with large user bases and high rates of account compromise need account recovery flows that don't assume the current 2FA configuration was set by the legitimate owner. Detecting rapid post-login MFA changes from new devices or locations should trigger holds, not just log entries.


The CSAM dimension here also pushes this beyond a cybercrime story into one that should concern child safety advocates, platform trust teams, and prosecutors in parallel. Mega.nz appeared again as the storage layer — a recurring venue in CSAM distribution cases. The pattern of using legitimate cloud storage to stage illegal content is old enough that platforms should be applying more aggressive automated detection, not waiting for investigators to surface it through criminal prosecutions.


For defenders working in consumer-facing security: phishing for one-time codes is not a sophisticated threat, but it is a scalable one. User education campaigns that specifically address "a company representative will never ask for your login code" remain underutilized relative to their effectiveness.


— HackWire Editorial


---


## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)