Skip to main content
CybersecurityHacking

Illinois Hacker Sentenced for Exploiting Snapchat Accounts

Smartphone on a plain surface with a blurred background and a hint of a computer screen.

76 months in prison and three years of supervised release — the penalty an Illinois man received after admitting to an extensive campaign of hacking Snapchat accounts and trading stolen images online.

Sentence and admissions by Kyle Svara

On Tuesday, 26-year-old defendant Kyle Svara was sentenced to 76 months in prison and three years of supervised release after pleading guilty to charges tied to a months-long campaign of account takeovers, image theft and distribution. According to the Justice Department, Svara admitted in February that he used a range of social engineering tactics to phish Snapchat access codes from more than 750 women. He had been charged in December prior to that admission.

Scope of the intrusions and victim set

The Justice Department’s account lays out the reach of Svara’s activity between May 2020 and February 2021. During that period he targeted more than 4,500 victims while posing as a representative of Snap Inc and using anonymized phone numbers. Investigators determined Svara accessed approximately 517 women’s Snapchat accounts without permission and downloaded nude or semi-nude photos from those accounts. The source says he targeted local residents in Plainfield, Illinois — including neighbors, family friends, classmates and his own personal friends — as well as students at Colby College in Waterville, Maine.

Tactics: social engineering, anonymized numbers, two‑factor lockouts and encrypted messaging

Svara’s methods, as described in court documents and the Justice Department statement, centered on social engineering. He phished Snapchat access codes by posing as a Snap Inc. representative and used anonymized phone numbers to mask his identity. After stealing victims’ credentials, he commonly activated two‑factor authentication on compromised accounts, locking rightful owners out. The documents also show Svara advertised his services online, offering to “get into girls snap accounts,” trading stolen images and asking potential clients to contact him via Kik, an encrypted messaging app.

CSAM found, distributed and solicited

Investigators found evidence that extended beyond adult victims. According to the Justice Department, Svara distributed child sexual abuse material (CSAM); approximately 530 images and 600 videos depicting CSAM were discovered in his Mega account. The Justice Department also reported that, when interviewed, Svara falsely denied knowledge of hacking Snapchat and falsely stated he had no interest in child pornography and had never actively sought or accessed CSAM. The official statement said those denials were contrary to the evidence, which showed the defendant had collected, distributed and solicited CSAM.

Clients, paid hacking and related prosecutions

The court record ties Svara’s activity to a paid market for account takeovers. He advertised and sold access to stolen images and services to third parties. One client named in the source is Steve Waithe, a former Northeastern University track and field coach, who hired Svara to hack Snapchat accounts of students and members of Northeastern’s women’s track and field and soccer teams. Waithe was later found guilty of targeting at least 128 women and stealing thousands of explicit photos from more than 100 women; he was sentenced in March 2024 to five years in prison for cyber fraud, cyberstalking and sextortion.

What this means for security teams, colleges, and end users

  • Security teams: The case illustrates how social engineering plus anonymized telecom tools and encrypted messaging can bypass protections and be used to monetize stolen data. Detection and response efforts should account for abuse of account-recovery channels and secondary controls like two‑factor authentication being manipulated to lock victims out.
  • Colleges and campus communities: Students and athletic programs were specific targets in the record — both as victims and as a market for paid intrusions. Institutions that house or support young users will want to consider how account-recovery fraud and targeted phishing might be identified and mitigated among students and staff.
  • End users and victims: The case underscores that criminals may not only obtain images but also weaponize account settings (activating two‑factor authentication) to deny victims access. The record also shows illicit markets for images where stolen material is traded or sold to third parties.

The sentencing of Kyle Svara closes one chapter of a multi‑faceted abuse pattern laid out in court documents: a widely distributed campaign of phishing and account takeover, a commercial market for stolen images, and the presence of CSAM among the materials traded. The record raises concrete enforcement and detection questions — about how account‑recovery flows are vetted, how anonymized communications are traced, and how institutions that serve young people can spot and respond to targeted harassment and exploitation.

Original story