Wednesday, September 16, 2026

Hacker Arrested for Taking Over SEC Social Media to Spread False Bitcoin News

Alabama man has been sentenced to 14 months in prison for orchestrating a sophisticated SIM swap attack that allowed him to hijack the U.S. Securities and Exchange Commission’s (SEC) social media account on X, formerly known as Twitter.

The unauthorized access was used to post false information about Bitcoin ETF approvals, causing significant market volatility in cryptocurrency prices.

Eric Council Jr., a 26-year-old Huntsville resident, received a 14-month prison sentence followed by three years of supervised release after pleading guilty to conspiracy to commit aggravated identity theft and access device fraud.

The sentencing, announced on May 19, 2025, concludes a case that highlighted vulnerabilities in high-profile social media accounts.

Court documents revealed that Council and his co-conspirators specifically targeted the SEC’s X account to publish a fabricated announcement claiming the SEC had approved Bitcoin Exchange Traded Funds (ETFs), information that investors and market participants had been eagerly awaiting.

The false announcement temporarily drove Bitcoin prices up by more than $1,000 per BTC before corrections sent the value plummeting by over $2,000 per BTC once the fraud was discovered.

SIM Swap Operation

The technical sophistication of Council’s operation centered on a Subscriber Identity Module (SIM) swap attack, a method increasingly used in high-stakes cyber fraud.

According to prosecutors, Council employed specialized hardware to create counterfeit identification cards containing a victim’s personal information that had been obtained through his co-conspirators.

Using this fraudulent ID, Council successfully impersonated the victim at a cellular service provider, convincing them to transfer the victim’s phone number to a SIM card under his control.

This critical step allowed the conspirators to bypass two-factor authentication protections on the SEC’s social media account, as account recovery and verification codes were redirected to the compromised phone number.

Once access was secured, Council’s co-conspirators posted the false announcement under the name of the SEC Chairman. For his technical role in the scheme, Council received payment in Bitcoin from his associates.

Market Manipulation and Law Enforcement

The attack represented a convergence of identity theft, telecommunications fraud, and targeted market manipulation that briefly disrupted cryptocurrency markets.

The FBI and SEC Office of Inspector General collaborated on the investigation that led to Council’s prosecution.

“The deliberate takeover of a federal agency’s official communications platform was a calculated criminal act meant to deceive the public and manipulate financial markets,” said FBI Criminal Investigative Division Acting Assistant Director Darren Cox.

According to the Report, “By spreading false information to influence the markets, Council attempted to erode public trust and exploit the financial system.”

Matthew R. Galeotti, Head of the Justice Department’s Criminal Division, emphasized the case’s significance: “Prosecuting those who seek to enrich themselves by threatening the integrity of digital assets through fraud is critical to protecting U.S. interests.”

U.S. Attorney Jeanine Pirro for the District of Columbia warned potential cybercriminals: “Don’t fool yourself into thinking you can’t be caught. You will be caught, prosecuted, and will pay the price for the damage your actions create.”

Find this News Interesting! Follow us on Google NewsLinkedIn, & X to Get Instant Updates!

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Google Search Makes It Harder to See Where a Link Really Goes Before You Click

Google has begun routing some organic Search result links...

Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters

Phishing operators are increasingly shifting away from malware-laden attachments...

Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors

Threat actors are actively exploiting a critical vulnerability in...

Weekly Cybersecurity Newsletter – Top 50 Biggest Cybersecurity Stories of the Week

Microsoft Patches 973 CVEs, Claude Agents Automate Attacks, China...

WordPress Events Calendar Vulnerabilities Let Hackers Take Over 600,000 Websites

Two critical unauthenticated vulnerability chains in the widely used...

Telegram Desktop XSS Vulnerability Lets Attackers Steal Entire Chat Histories

A stored cross-site scripting (XSS) vulnerability in Telegram Desktop...

Marimo RCE Flaw Lets Hackers Steal AWS Credentials and Pivot to Bastion Host in 8 Seconds

A threat actor exploited a critical pre-authentication remote code...

Related Articles

Recent News