A Singaporean man, Malone Lam (aliases including “Anne Hathaway”), pleaded guilty to leading a group that stole over $245 million in cryptocurrency from U.S. victims. The group used social engineering, such as posing as Google Support and using spoofed phone numbers, to trick victims into handing over access, including via screen-sharing and 2FA codes.
Key findings
- Malone Lam pleaded guilty to leading a group that stole over $245 million in cryptocurrency from victims across the United States.
- The group allegedly used fake tech support-style social engineering, including posing as Google Support, to trick at least one victim into transferring $230 million in Bitcoin.
- The operation recruited accomplices via online gaming platforms and used specialized roles (callers, money launderers, and even burglars) to steal and move funds.
- The article highlights common victim hooks: requests to screen-share during a “support” call and requests for 2FA codes.
Who’s being targeted
- Commonly targeted roles: Executives, Finance/Accounting, IT/Helpdesk, Customer support teams, Employees with access to cryptocurrency accounts or wallets.
- Affected industries: Cryptocurrency holders / personal finance, Financial services.
- Attack channels: vishing.
- Impersonated: Google Support.
Awareness takeaways
- Treat unexpected “tech support” calls as suspicious, hang up and call back using an official number you find yourself.
- Never share your screen with an unsolicited caller; screen-sharing can expose sensitive information and enable account takeover.
- Never read out or forward 2FA codes to anyone, real support teams don’t need them.
- For organizations or individuals holding crypto, use stronger storage practices (e.g., cold/hardware wallets) and extra verification for transfers.
Red flags to watch for
- Unsolicited support call (you didn’t open a ticket)
- Requests to share your screen during a support call
- Requests for a 2FA code
Read the video transcript
Someone lost two hundred and thirty million dollars in Bitcoin… from one fake Google Support call. The caller opened with, "Hi, this is Google Support calling about a security issue on your account." Then they asked the victim to share their screen and read out a 2FA code so they could "verify" it. That’s all it took for Malone Lam’s crew to drain accounts, spoofed caller ID, fake tech support script, and you doing the work by sharing your screen and your 2FA. If you ever get an unexpected "Google Support" call, hang up, then call back using the official support number you look up yourself.