Skip to content
feed: live
>_ 0dayNews
threat intel

76 Months for Hacking 750 Women's Snapchat Accounts

An Illinois man received a 76-month federal sentence for compromising over 750 Snapchat accounts to steal intimate photos — one of the larger account-hacking prosecutions in recent memory.

76 Months for Hacking 750 Women's Snapchat Accounts
Image: 0dayNews / 0dayNews Editorial · All rights reserved
fuse Marisol "Fuse" Delgado · Published · 1 min read

An Illinois man was sentenced Tuesday to 76 months in federal prison and three years of supervised release for hacking the Snapchat accounts of more than 750 women to steal their intimate photos, BleepingComputer reports.

That’s 6 years, 4 months. Over 750 victims. Non-consensual intimate image theft at a scale that required systematic account access, not one-off opportunism.

What the sentence reflects

Six-plus years is a meaningful federal outcome for account compromise. Courts have been stacking charges in cases that combine unauthorized access with intimate image theft — the underlying computer fraud counts compound with content-related charges, and victim count affects sentencing under federal guidelines. This is in line with how the DOJ has been treating cases where the harms are individual but the methods are industrial.

None of that makes the sentence a deterrent by itself. The attacker compromised over 750 accounts before anyone caught up. That timeline tells you how long systematic account access can go undetected when the harm to any single person isn’t immediately visible.

The honest picture for defenders

750+ accounts at scale almost always means one of two attack methods: credential stuffing against accounts reusing passwords from prior breach dumps, or targeted phishing against individuals without MFA. Neither method requires custom tooling. Neither requires technical sophistication. Both are defeated by things users and platforms can actually do.

What reduces exposure:

  • Unique passwords per platform — a reused password from a 2022 breach is still live data in credential stuffing lists
  • MFA on any account that holds private content
  • Knowing what you’ve stored and where

The 750 victims did nothing wrong. The liability is the attacker’s. But the attack surface was real and largely preventable with controls that exist today.

Enforcement outcomes like this one matter. They don’t substitute for platform-level account security improvements or for basic user hygiene that should have been table stakes for years.


Related: Chick-fil-A Credential Stuffing Breach Hits 13,000 Accounts · Hotel Wi-Fi DNS Hijack Steals Microsoft 365 Credentials

Found this useful? Share it.