A 26-year-old Illinois man has been sentenced to 76 months in prison and three years of supervised release after orchestrating a massive social engineering campaign that compromised over 750 Snapchat accounts. According to court documents released via CourtListener, Kyle Svara targeted women to steal and sell intimate photographs. He pleaded guilty in February following his formal indictment late last year.
The attacker's methodology relied entirely on psychological manipulation rather than brute-force software exploits. Between May 2020 and February 2021, Svara impersonated official Snap Inc. representatives, using anonymized phone numbers to contact his targets. Through highly targeted phishing campaigns, he successfully extracted Snapchat access codes from thousands of individuals.
The scale of the operation was extensive, with investigators revealing that Svara targeted over 4,500 victims and successfully breached the profiles of approximately 517 women. Once inside an account, the hacker did not just download private images; he actively weaponized security features by enabling two-factor authentication to permanently lock the legitimate owners out of their profiles.
During the investigation, the U.S. Department of Justice discovered that Svara was also in possession of child sexual abuse material (CSAM). Authorities found approximately 530 images and 600 videos of illegal content stored on his Mega cloud account. Despite initially lying to investigators and denying any involvement in the Snapchat breaches or CSAM collection, evidence proved he actively gathered and distributed the material.
Svara also monetized his illicit skills by advertising "hacking for hire" services online, directing potential clients to the encrypted messaging app Kik. One confirmed client was Steve Waithe, a former track coach at Northeastern University, who paid Svara to hack the accounts of female student-athletes. Waithe's involvement in the scheme victimized at least 128 women and resulted in the theft of explicit photos from over 100 victims. For his role, Waithe was sentenced to five years in prison in March 2024.
Svara's independent targets included neighbors, classmates, and students at Colby College in Maine.
How to Protect Your Snapchat Account
This case highlights how attackers use social engineering to bypass standard security measures. To secure your profile against similar phishing attempts, follow these steps:
- Never share your login codes: Snap Inc. support will never contact you via text message or phone call to ask for your password or two-factor authentication code.
- Enable 2FA immediately: Set up two-factor authentication on your account before an attacker can do it for you. Use an authenticator app rather than SMS-based codes for stronger security.
- Verify official communications: Treat any unsolicited message claiming your account is compromised as highly suspicious. Always check your account status directly through the official Snapchat app.
The Weaponization of Security Features
The most alarming aspect of Svara's campaign is not the phishing itself, but how he weaponized two-factor authentication against his victims. By hijacking an account and immediately enabling 2FA, he effectively built a digital fortress around stolen data, locking the actual owners out while he harvested their private lives. This flips the traditional narrative of cybersecurity on its head; a tool designed to protect users became the very mechanism that sealed their loss of control.
This case also exposes the growing threat of "hacking as a service" in local communities. Svara wasn't just an isolated threat actor; he was a vendor for people like Steve Waithe, turning localized stalking into a scalable, outsourced operation. As social platforms continue to harden their backend infrastructure, attackers will increasingly target the human element, proving that the most vulnerable point in any network is the person holding the phone.