Fake Google Support Bait Led to $245M Crypto Theft

Graham Cluley · High sophistication
Last updated September 10, 2026

A Singaporean man, Malone Lam (aliases including “Anne Hathaway”), pleaded guilty to leading a group that stole over $245 million in cryptocurrency from U.S. victims. The group used social engineering, such as posing as Google Support and using spoofed phone numbers, to trick victims into handing over access, including via screen-sharing and 2FA codes.

Key findings

  • Malone Lam pleaded guilty to leading a group that stole over $245 million in cryptocurrency from victims across the United States.
  • The group allegedly used fake tech support-style social engineering, including posing as Google Support, to trick at least one victim into transferring $230 million in Bitcoin.
  • The operation recruited accomplices via online gaming platforms and used specialized roles (callers, money launderers, and even burglars) to steal and move funds.
  • The article highlights common victim hooks: requests to screen-share during a “support” call and requests for 2FA codes.

Who’s being targeted

  • Commonly targeted roles: Executives, Finance/Accounting, IT/Helpdesk, Customer support teams, Employees with access to cryptocurrency accounts or wallets.
  • Affected industries: Cryptocurrency holders / personal finance, Financial services.
  • Attack channels: vishing.
  • Impersonated: Google Support.

Awareness takeaways

  • Treat unexpected “tech support” calls as suspicious, hang up and call back using an official number you find yourself.
  • Never share your screen with an unsolicited caller; screen-sharing can expose sensitive information and enable account takeover.
  • Never read out or forward 2FA codes to anyone, real support teams don’t need them.
  • For organizations or individuals holding crypto, use stronger storage practices (e.g., cold/hardware wallets) and extra verification for transfers.

Red flags to watch for

  • Unsolicited support call (you didn’t open a ticket)
  • Requests to share your screen during a support call
  • Requests for a 2FA code
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Someone lost two hundred and thirty million dollars in Bitcoin… from one fake Google Support call. The caller opened with, "Hi, this is Google Support calling about a security issue on your account." Then they asked the victim to share their screen and read out a 2FA code so they could "verify" it. That’s all it took for Malone Lam’s crew to drain accounts, spoofed caller ID, fake tech support script, and you doing the work by sharing your screen and your 2FA. If you ever get an unexpected "Google Support" call, hang up, then call back using the official support number you look up yourself.

Similar attacks

Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026
Crypto Scammers Posed as Apple/Google Support

Crypto Scammers Posed as Apple/Google Support

U.S. prosecutors say a group led by Malone Lam ran social engineering scams that stole over $245 million in cryptocurrency. The scammers allegedly called crypto holders while pretending to be customer support from Apple or Google, talked victims into handing over key account details, and in at…

September 8, 2026
Fake IT Helpdesk Tricks Users Into Remote Access

Fake IT Helpdesk Tricks Users Into Remote Access

This bulletin describes multiple real-world social engineering campaigns where attackers impersonate IT support or use trusted-looking sharing and “Allow” prompts to gain access. Several campaigns abuse Microsoft Teams and document-sharing lures to trick employees into installing remote tools or…

September 3, 2026
Tesla ‘Crypto Presale’ Kit Fuels New Scam Wave

Tesla ‘Crypto Presale’ Kit Fuels New Scam Wave

The article describes real-world social engineering aimed at both consumers and financial firms, including phone-based attacks on hedge funds and a turnkey scam kit that impersonates Tesla to steal cryptocurrency. The kit uses a professional-looking fake presale website with urgency tactics…

August 12, 2026
Deepfake Job Interviews and Vishing Hit Enterprises

Deepfake Job Interviews and Vishing Hit Enterprises

CrowdStrike warns that attackers are using AI to make social engineering faster and more convincing, including AI-generated resumes and deepfake job interviews to infiltrate companies. The report also describes vishing campaigns that quickly pivot from stealing accounts to stealing data from SaaS…

August 3, 2026
OpenAI: ChatGPT Aided Cambodia Scam Network

OpenAI: ChatGPT Aided Cambodia Scam Network

OpenAI says it shut down a coordinated network of ChatGPT accounts linked to Cambodia that supported multiple real-world scams, including investment, romance, gambling, and law-enforcement impersonation. The group used AI to create fake personas, translate and generate persuasive messages on…

August 3, 2026