The SIM-Swap Attack That Hijacked the SEC’s X Account

United States v. Eric Council Jr. revealed how cellular identity theft, fraudulent identification, weak account-recovery controls, and carefully timed disinformation enabled conspirators to publish a false Bitcoin ETF approval announcement through the securities regulator’s official social-media account.

WASHINGTON — A SIM-swap conspiracy seized control of the United States Securities and Exchange Commission’s official X account during one of the cryptocurrency industry’s most sensitive regulatory moments, allowing criminals to distribute a fraudulent Bitcoin exchange-traded fund approval announcement capable of moving global markets immediately.

The January 9, 2024, takeover briefly pushed Bitcoin’s value more than $1,000 higher before the SEC publicly denied the announcement, after which the cryptocurrency fell by more than $2,000 as traders rapidly reconsidered positions created during the confusion.

Federal investigators ultimately identified Eric Council Jr., an Alabama resident who used fraudulent identification to transfer a telephone number associated with the SEC account onto a device controlled by the conspirators, enabling accomplices to obtain account-recovery credentials and publish the unauthorized message.

Although the proposed title identifies United States v. Robert Powell, the publicly documented federal prosecution concerning the SEC account takeover was United States v. Eric Council Jr., while Robert Powell was charged and convicted in a separate SIM-swapping conspiracy involving numerous individual victims.

That distinction matters because both prosecutions demonstrate the extraordinary power available through cellular identity theft, but only Council’s admitted conduct was directly connected with the fraudulent SEC announcement, the compromised regulatory account, and the resulting Bitcoin price volatility.

The Case Name Requires an Important Correction

Robert Powell, sometimes known online as “R,” led a separate criminal SIM-swapping group that stole cryptocurrency and personal information from victims by transferring their telephone numbers to devices controlled by members of the conspiracy.

Powell pleaded guilty to conspiracy to commit wire fraud, aggravated identity theft, and access-device fraud, but publicly available federal records do not identify him as the defendant responsible for obtaining control of the SEC’s telephone number or X account.

Eric Council Jr. instead admitted participating in the January 2024 SEC takeover, making his prosecution the correct federal case through which to examine the fake Bitcoin ETF announcement, cellular transfer, identity impersonation, and immediate market consequences.

Confusing the defendants would improperly combine two distinct prosecutions, separate victim groups, different operational networks, and unrelated charging documents merely because both criminal cases involved SIM swapping as a method for defeating account protections.

The corrected case nevertheless supports the intended warning because SIM-swap services frequently operate through loosely connected specialists who obtain personal information, manufacture identification, visit cellular stores, recover accounts, publish messages, steal cryptocurrency, and distribute criminal proceeds.

A Criminal Opportunity Appeared Before the ETF Decision

During early January 2024, cryptocurrency markets were waiting intensely for the SEC’s decision concerning applications seeking authorization for exchange-traded products holding spot Bitcoin, creating an unusually sensitive environment in which one apparently official announcement could trigger immediate global trading.

Investors, financial institutions, journalists, analysts, automated trading systems, and cryptocurrency enthusiasts monitored the regulator’s official communications continuously because an approval could expand conventional investment access, increase institutional participation, and mark an important development within United States financial regulation.

The conspirators exploited that expectation by targeting an authoritative account whose statements carried exceptional credibility, recognizing that fraudulent information delivered through the SEC’s verified profile would appear considerably more persuasive than comparable rumors distributed through anonymous cryptocurrency channels.

Their operation did not require changing Bitcoin’s blockchain, compromising an exchange, stealing institutional cryptocurrency reserves, or penetrating the SEC’s internal regulatory systems because control of one public communication channel supplied enough credibility to influence market expectations.

The attack therefore demonstrated that financial infrastructure includes trusted information sources alongside payment networks and trading venues, since unauthorized access to a regulator’s public voice can create economic consequences before institutions determine that its message was fraudulent.

The Telephone Number Became the Entry Point

Council’s conspirators first obtained personal identifying information belonging to an individual who possessed authorized access to the SEC’s X account, giving the group enough information to impersonate that person during a cellular service interaction.

Council created a fraudulent identification document containing the victim’s personal information but displaying Council’s photograph, allowing him to present himself physically as the authorized subscriber while requesting control over the telephone number associated with the victim.

He traveled to a cellular retail location in Huntsville, Alabama, presented the counterfeit identification, purchased a new iPhone, and successfully arranged for the targeted telephone number to be connected to a SIM card under the conspirators’ control.

Once the transfer succeeded, incoming calls and text messages intended for the legitimate subscriber could reach the newly activated device, giving the attackers a pathway to recovery codes used to regain access to protected online accounts.

This technique transformed information collected about one person into operational control over a government agency’s communication channel, illustrating why telephone numbers should never function as unquestioned proof that the person receiving a message remains the legitimate subscriber.

How SIM Swapping Defeats Account Protection

A subscriber identity module allows a cellular network to associate one device with a customer’s telephone service, enabling calls, messages, and authentication codes to follow the subscriber when a legitimate replacement device becomes necessary.

SIM swapping weaponizes that routine customer-service process by convincing a carrier to transfer the victim’s number onto hardware controlled by an attacker, often through stolen personal information, fraudulent identification, bribed employees, compromised retail credentials, or manipulated support personnel.

The victim’s original phone may unexpectedly lose network service while the attacker’s device begins receiving calls and text messages, although that warning can arrive after criminals have already initiated password resets or account-recovery procedures.

When an online service delivers authentication codes through ordinary text messages, possession of the transferred number can allow an attacker to satisfy a security challenge even though the criminal never possessed the victim’s original phone, password, or authorized device.

The Federal Communications Commission’s consumer guidance concerning SIM-swap and port-out fraud explains why criminals seek control over telephone numbers that can unlock financial, email, social-media, cryptocurrency, and other sensitive accounts through recovery procedures.

A Fraudulent Identification Enabled the Transfer

Council’s role demonstrated how convincing physical identification can become a bridge between stolen personal information and digital account access, particularly when frontline employees must process legitimate device replacements quickly for large numbers of customers.

A counterfeit document does not need to withstand every form of forensic examination when an attacker encounters a hurried employee, inconsistent verification procedures, limited training, unreliable document-scanning technology, or customer-service pressure favoring rapid completion.

Criminal groups can prepare prospective “walkers” with a target’s name, address, account information, security answers, telephone number, and identification document before directing them toward a particular cellular store offering favorable conditions for successful impersonation.

The person conducting the in-store transfer may receive only a fraction of the eventual proceeds while understanding little about the ultimate objective, allowing organizers to separate the visible impersonation from account takeover, market manipulation, theft, and laundering.

Council received Bitcoin compensation for completing the fraudulent transfer, connecting his apparently local retail interaction with a broader conspiracy designed to exploit one of the most closely watched financial regulatory decisions of the year.

The SEC Account Lacked Multifactor Protection

Following the incident, the SEC explained that multifactor authentication had previously been enabled for its X account, but platform support had disabled that protection months earlier after the agency encountered difficulty accessing the profile.

The additional protection remained disabled when the SIM swap occurred, making control of the associated telephone number significantly more valuable because the conspirators could use account-recovery functions without satisfying a stronger, separately protected authentication requirement.

An official account carrying market-moving authority should use hardware security keys, phishing-resistant authentication, restricted administrative access, documented recovery procedures, independent approval requirements, and continuous monitoring capable of detecting unexpected changes to credentials or telephone numbers.

Text-message authentication remains preferable to using only a password under some circumstances, but it creates dependence on cellular account controls designed primarily for convenient customer service rather than protecting systemically important communications.

The SEC compromise showed that security can deteriorate quietly after a temporary operational workaround, especially when nobody assumes responsibility for restoring the disabled protection, reviewing the exception, and testing account recovery before an adversary discovers the weakness.

The Fraudulent Post Imitated Official Authority

After obtaining recovery credentials through the transferred telephone number, Council delivered the necessary access information to his co-conspirators, who entered the SEC account and prepared a message resembling an authentic regulatory announcement.

The fraudulent post falsely stated that the SEC had approved Bitcoin exchange-traded funds for listing upon all registered national securities exchanges, while an accompanying image and fabricated quotation attributed the momentous decision to the agency’s chairman.

Because the statement appeared through the verified @SECGov profile, market participants initially encountered all the visible signals ordinarily associated with trustworthy government information, including familiar branding, official account history, and the expectation of an imminent decision.

The attackers therefore borrowed institutional credibility rather than constructing it themselves, turning years of public trust accumulated by a federal regulator into a temporary instrument for distributing disinformation toward investors worldwide.

The SEC’s official account-compromise statement confirmed that the January 9 announcement was unauthorized and had not been issued by the agency or its staff, correcting the market before the authentic ETF decision arrived.

Bitcoin Reacted Within Minutes

Bitcoin’s price increased by more than $1,000 after the false message appeared because traders interpreted the announcement as confirmation that regulated spot products would soon expand access toward the world’s largest cryptocurrency.

When the SEC and its chairman explained that the account had been compromised and no approval had yet occurred, the price reversed direction and declined by more than $2,000 as participants reconsidered trades entered under false assumptions.

A contemporaneous news report examining the SEC account takeover described how cellular identity theft enabled the compromise while intensifying questions concerning cybersecurity practices at an agency responsible for protecting investors and supervising important markets.

The rapid movement did not prove that every purchase or sale resulted exclusively from the fraudulent post because cryptocurrency prices respond continuously to liquidity, leverage, expectations, automated strategies, and unrelated market information.

However, the immediate spike and reversal illustrated how authoritative disinformation can influence prices, trigger automated orders, liquidate leveraged positions, create arbitrage opportunities, and redistribute wealth before human analysts have enough time to independently verify a breaking announcement.

The Authentic Approval Arrived One Day Later

The false announcement became particularly disruptive because the SEC genuinely approved multiple spot Bitcoin exchange-traded products on January 10, 2024, only one day after criminals prematurely published a fabricated version of the anticipated decision.

That extraordinary timing gave the fraudulent message enough plausibility to influence experienced market participants, since the underlying regulatory development was expected soon and therefore did not resemble an obviously impossible claim.

The authentic decision did not excuse the conspiracy because criminals knowingly seized an official account and distributed unauthorized information before the regulator completed its lawful communication process, exposing traders to volatility generated through deliberate deception.

Even accurate information can become manipulative when obtained, altered, timed, or presented unlawfully, while an attacker who correctly anticipates tomorrow’s announcement does not gain permission to impersonate the government today.

The episode consequently revealed that misinformation risk becomes greatest when fabricated content closely resembles a probable event, arrives through a trusted channel, and reaches markets during a period of unusually concentrated expectation.

Council Returned the Device and Collected Bitcoin

After completing the SIM swap, Council traveled toward Birmingham, delivered the iPhone containing the transferred number to a co-conspirator, and received approximately $50,000 in Bitcoin as compensation for his participation.

The payment demonstrated that his role carried substantial value within the conspiracy because gaining control over the associated telephone number created the essential access pathway enabling other participants to compromise the regulator’s social-media profile.

Council later returned to the cellular store and exchanged the device for cash, behavior prosecutors presented as part of the sequence surrounding the impersonation, transfer, handoff, and concealment of evidence.

Criminal organizers frequently divide operations into specialized assignments so that one participant acquires identity information, another manufactures identification, a walker completes the cellular transfer, and technically experienced accomplices recover accounts or move stolen assets.

That structure can complicate attribution initially, but communications, location histories, store surveillance, device records, cryptocurrency payments, internet searches, identification files, and cooperating witnesses can eventually reconstruct how apparently isolated actions supported one coordinated offense.

Investigators Reconstructed the Conspiracy

Federal investigators followed records connecting Council with the cellular store, fraudulent identification, a transferred telephone number, a purchased device, Bitcoin payments, communications, and online activity occurring before and after the account compromise.

Searches attributed to Council included questions concerning signs that law enforcement or the Federal Bureau of Investigation might be investigating someone, revealing anxiety after the operation attracted international attention.

Internet searches alone do not establish criminal guilt because innocent users research investigations for numerous reasons, but those inquiries can become corroborating evidence when combined with physical movements, false documents, communications, payments, devices, and account records.

Council’s arrest during October 2024 demonstrated that investigators could reconstruct a technically mediated offense months afterward, even when conspirators used cryptocurrency compensation and divided operational responsibilities among several participants.

The prosecution also emphasized why organizations should preserve authentication logs, customer-service records, account changes, recovery attempts, IP information, device identifiers, and administrator activity because those records can transform a confusing breach into an attributable criminal sequence.

Council Admitted His Role

During February 2025, Council pleaded guilty to conspiring to commit aggravated identity theft and access-device fraud, accepting criminal responsibility for obtaining the telephone number used during the takeover and supplying access to his co-conspirators.

A guilty plea carries greater evidentiary significance than an accusation because the defendant formally acknowledges essential criminal conduct before a federal judge, who must determine whether the admission remains voluntary, informed, and supported by an adequate factual basis.

The plea resolved Council’s individual prosecution without publicly identifying every participant responsible for selecting the target, acquiring personal information, directing the SIM swap, accessing the X account, composing the message, or trading around the resulting volatility.

That incomplete public attribution illustrates how criminal investigations can establish one participant’s guilt while leaving unanswered questions concerning additional conspirators, financial beneficiaries, market positions, operational leadership, and the complete distribution of proceeds.

Responsible reporting should therefore describe Council’s proven conduct carefully without presenting him as the only conceivable participant or inventing identities for accomplices who were not publicly charged within the documented proceeding.

The Court Imposed a Fourteen-Month Sentence

During May 2025, a federal judge sentenced Council to fourteen months of imprisonment, followed by three years of supervised release, while ordering forfeiture reflecting the Bitcoin compensation connected with his participation.

The Justice Department’s sentencing announcement explained that the conspirators intended to manipulate Bitcoin’s price by publishing fraudulent information through the SEC’s official account during the highly anticipated ETF decision period.

Sentencing accountability extended beyond the few minutes during which the unauthorized message remained visible because the operation stole an identity, compromised a federal regulator’s public communications, destabilized market expectations, and undermined confidence in official online information.

The sentence should not be interpreted as a universal penalty for SIM swapping because future outcomes depend upon charging decisions, criminal histories, financial losses, victim numbers, leadership roles, stolen assets, cooperation, obstruction, and applicable statutory provisions.

Council’s conviction nevertheless established that a retail cellular transfer performed through fraudulent identification can support serious federal punishment when the resulting access enables identity theft, account compromise, disinformation, and attempted financial-market manipulation.

Robert Powell’s Separate SIM-Swap Conspiracy

Robert Powell’s prosecution remains relevant because his criminal organization demonstrated how SIM swapping can become a specialized commercial service used repeatedly against victims holding valuable cryptocurrency and sensitive online accounts.

Powell admitted leading a group that targeted numerous people, transferred telephone numbers, accessed protected accounts, stole information and digital assets, and caused substantial financial losses through coordinated identity theft and telecommunications manipulation.

His case illustrated the broader criminal ecosystem surrounding SIM swaps, where organizers can purchase personal information, recruit impersonators, direct porting attempts, receive stolen cryptocurrency, and distribute proceeds across participants who may never meet physically.

However, none of those similarities authorizes merging Powell’s prosecution with Council’s SEC account takeover, since factual accuracy requires separating a broad cryptocurrency theft conspiracy from the specific operation targeting the federal regulator’s public profile.

The comparison instead shows that one technical method can support dramatically different objectives, including emptying individual cryptocurrency wallets, taking over email accounts, impersonating public institutions, publishing market-moving disinformation, or defeating financial authentication controls.

Multifactor Authentication Must Resist Telephone Theft

Organizations controlling high-impact accounts should replace ordinary text-message verification with phishing-resistant authentication such as hardware security keys, cryptographic passkeys, or independently managed authenticators that remain unaffected when a telephone number moves between SIM cards.

Every account should maintain at least two secured recovery methods, although backup credentials must receive the same protection as primary authentication because criminals naturally target whichever pathway imposes the weakest identity checks.

High-risk changes should require approval from multiple authorized employees, documented verification through previously established channels, and automatic notifications sent toward security teams when recovery settings, telephone numbers, administrators, devices, or authentication methods change unexpectedly.

Administrative access should remain limited according to operational necessity, while employees leaving a role should lose privileges promptly so that forgotten credentials and inactive recovery paths do not remain available indefinitely.

Regular exercises should test account takeover scenarios involving lost devices, unavailable employees, compromised email, fraudulent carrier transfers, platform-support mistakes, and malicious insiders before a genuine emergency forces improvised decisions under intense public pressure.

Cellular Carriers Remain Critical Security Gatekeepers

Telecommunications providers occupy an important position within digital identity infrastructure because banks, email services, government agencies, cryptocurrency platforms, and social networks continue using telephone numbers for authentication, alerts, password recovery, and customer verification.

Carriers should require strong identity verification for SIM changes, impose transfer locks, alert customers through multiple channels, maintain cooling-off periods for sensitive modifications, and escalate suspicious requests involving high-risk or institutionally important accounts.

Employees need training to identify counterfeit documents, scripted answers, unusual urgency, repeated failed attempts, distant store visits, account inconsistencies, and customers who appear unfamiliar with basic information about the service they claim to own.

Technical controls should prevent one frontline employee from overriding significant protections without additional review, particularly when an account carries heightened risk because of public authority, substantial cryptocurrency holdings, financial access, or previous takeover attempts.

Customers can reduce exposure by establishing carrier PINs, number locks, port-out restrictions, separate recovery addresses, and immediate alerts, although those measures remain only as dependable as the provider’s enforcement procedures.

Official Social-Media Accounts Are Financial Infrastructure

A verified government profile can influence securities, commodities, currencies, cryptocurrency, interest-rate expectations, corporate valuations, and public confidence, making its protection comparable with other systems distributing sensitive market information.

Attackers do not need to alter regulatory databases when they can impersonate the regulator successfully, since traders reacting to apparently official information may move billions of dollars before the institution restores control.

Agencies should consequently inventory every public account, classify potential economic impact, assign named security owners, require hardened authentication, review platform dependencies, and maintain emergency procedures for publishing corrections through independent channels.

Journalists and financial institutions should also verify extraordinary announcements through agency websites, formal filings, press-release systems, and multiple authorized representatives instead of relying exclusively upon one social-media post, even when the profile displays verification.

Automated trading systems require particular caution because algorithms responding within milliseconds can amplify fabricated information long before human analysts evaluate language, timing, source integrity, or contradictions appearing across official communications.

Investors Need Independent Verification Habits

Investors should treat unexpected announcements concerning ETF approvals, enforcement decisions, exchange failures, asset freezes, resignations, sanctions, token listings, or regulatory changes as unconfirmed until authoritative information appears through several independent channels.

A verified badge does not prove that the authorized account holder created the current message because passwords, recovery methods, administrator credentials, platform personnel, connected applications, and telephone numbers can all become compromised.

Screenshots provide even weaker evidence because they can be fabricated or removed from context easily, requiring users to locate the original statement and compare it with information displayed upon the responsible institution’s official website.

Traders using leverage should recognize that false announcements can trigger liquidation before verification becomes possible, making risk limits, position sizing, stop policies, and reduced dependence upon breaking social-media information essential protections.

The SEC incident supplied an unusually visible warning that market manipulation can begin with identity infrastructure rather than fraudulent trading, because one hijacked telephone number became the gateway toward a global financial misinformation event.

Lawful Privacy Requires Consistent Identity Records

Individuals seeking privacy, international diversification, secure communications, and protection from identity theft should minimize unnecessary exposure while maintaining accurate documentation concerning every lawful identity, account, asset, telephone number, and authorized representative.

Responsible cross-border asset protection and international planning should preserve truthful beneficial ownership, dependable source-of-funds records, lawful taxation, and identity information capable of surviving review by banks, courts, regulators, immigration authorities, and telecommunications providers.

Using fabricated identification to transfer another person’s telephone service constitutes criminal impersonation rather than legitimate privacy, while cryptocurrency compensation and cross-border communications cannot transform account takeover into acceptable anonymity planning.

Organizations serving internationally mobile clients should establish secure recovery procedures that remain effective after telephone changes, foreign travel, residence transitions, lost devices, unavailable numbers, and replacement identity documents issued through lawful governmental processes.

Clients should retain records demonstrating why contact information changed, who possessed administrative authority, when devices were replaced, and how important accounts were recovered, reducing the likelihood that legitimate transitions resemble unexplained takeover activity.

Privacy Differs from Impersonation

Privacy limits unnecessary disclosure of accurate personal information, whereas impersonation presents false information or stolen credentials to obtain access, services, property, authority, or trust belonging legally to someone else.

Lawful privacy and international risk-management services should establish coherent records and defensible controls rather than counterfeit identification, stolen telephone numbers, fabricated credentials, deceptive account recovery, or undisclosed access toward another person’s financial assets.

Encrypted communications, private accounts, aliases used transparently, trusts, companies, authentication devices, and international telephone services can support lawful security objectives when ownership and authority remain accurately documented toward institutions entitled to verify them.

A SIM-swap conspirator seeks the opposite outcome by convincing a carrier that the attacker is the subscriber, converting deliberately false identity information into operational access over communications and authentication codes belonging to the victim.

The strongest lawful privacy arrangement therefore reduces public exposure while strengthening private verification, ensuring that authorized institutions can distinguish the legitimate owner from anyone presenting stolen data, fabricated documents, or manipulated recovery requests.

The Enduring Warning from the SEC Takeover

The SEC account compromise demonstrated that sophisticated financial disruption can begin with an ordinary cellular-store interaction, counterfeit identification, a replacement device, and an account-recovery code rather than an advanced intrusion into protected government networks.

Council’s admitted conduct supplied the physical identity impersonation required for transferring the number, while his co-conspirators transformed that access into an authoritative false announcement capable of changing Bitcoin prices within minutes.

The event exposed weaknesses across several interconnected systems, including cellular verification, platform recovery, disabled multifactor authentication, institutional account governance, investor reliance upon social media, and automated market reactions toward breaking information.

It also proved that rapid correction cannot eliminate every consequence because traders can suffer liquidation, missed opportunities, reputational damage, or irreversible transactions during the narrow interval between a fraudulent announcement and authoritative denial.

Robert Powell’s separate conviction reinforces the wider warning about organized SIM-swapping services, but Eric Council Jr. remains the correct defendant for reporting the cellular takeover that directly enabled criminals to hijack the SEC’s official X account.

For government agencies and financial institutions, the essential safeguards remain hardware-based authentication, strict transfer controls, limited administrative privileges, independent recovery channels, continuous monitoring, rehearsed incident response, and immediate publication through multiple trusted systems.

For investors, the strongest protection involves verifying consequential announcements independently, controlling leverage carefully, questioning sudden messages even from verified accounts, and understanding that possession of a telephone number does not reliably establish legitimate identity.

The final lesson remains unmistakable: when a mobile number functions as the master key for an institution’s public voice, one successful act of cellular impersonation can become a worldwide market event before anyone notices that the telephone has changed hands.