Mobile Firm Employee Charged With Aiding Crypto SIM-Swap Attacks Targeting 19

Stephen Defiore was allegedly paid to transfer cellphone accounts to ones owned by a co-conspirator.

AccessTimeIconFeb 9, 2021 at 11:09 a.m. UTC
Updated Sep 14, 2021 at 12:08 p.m. UTC
10 Years of Decentralizing the Future
May 29-31, 2024 - Austin, TexasThe biggest and most established global hub for everything crypto, blockchain and Web3.Register Now

A 36-year-old Florida-based telco employee was charged Monday over a SIM-swapping scam that stole one victim’s cryptocurrency.

Stephen Defiore, 36, received a one-count Bill of Information – a waiver of indictment and agreement to prosecution in court – with conspiracy to commit wire fraud, according to a U.S. Department of Justice press release.

Defiore is the second person charged in connection with a scheme that hit 19 victims in SIM-swap attacks, and stole a “significant portion” of cryptocurrency held by a doctor in New Orleans.

According to the report, Defiore worked as a sales representative between August 2017 and November 2018 for an unnamed phone company. Having access to the company's customer accounts, he allegedly performed SIM swaps – reassigning a SIM card to another user – as part of a $500 per day arrangement with a co-conspirator.

For each SIM-swap, which netted Defiore over $2,300 in total via 12 payments, co-conspirator Ricard Li sent him a customer’s cellphone number, a four-digit PIN and a new SIM-card number for the swap. Li was charged for his alleged involvement in June 2020.

A SIM-swap hack occurs when an attacker gains access to a victim's cellphone account, allowing incoming calls and text messages to be routed to a different device. The attacker is then able to change passwords on a victim's various accounts including emails and cryptocurrency exchange and bank accounts via SMS verification.

If convicted of the charge, Defiore faces a maximum of five years in prison and a fine of up to $250,000, as well as up to three years of supervised release after imprisonment and a mandatory $100 special assessment per count.

Disclosure

Please note that our privacy policy, terms of use, cookies, and do not sell my personal information has been updated.

CoinDesk is an award-winning media outlet that covers the cryptocurrency industry. Its journalists abide by a strict set of editorial policies. In November 2023, CoinDesk was acquired by the Bullish group, owner of Bullish, a regulated, digital assets exchange. The Bullish group is majority-owned by Block.one; both companies have interests in a variety of blockchain and digital asset businesses and significant holdings of digital assets, including bitcoin. CoinDesk operates as an independent subsidiary with an editorial committee to protect journalistic independence. CoinDesk employees, including journalists, may receive options in the Bullish group as part of their compensation.


Learn more about Consensus 2024, CoinDesk's longest-running and most influential event that brings together all sides of crypto, blockchain and Web3. Head to consensus.coindesk.com to register and buy your pass now.