The OTP Deception on Snapchat: Anatomy of an Attack That Compromised Over 750 Accounts
Data Breaches

Illustrative image generated with AI

The OTP Deception on Snapchat: Anatomy of an Attack That Compromised Over 750 Accounts

Learn how a massive Snapchat phishing attack compromised 750+ accounts by bypassing OTP 2FA via vishing, and discover how to protect your account from hackers.

Text generated by artificial intelligence, published without human review. AI transparency

Introduction

A 26-year-old from Illinois has been sentenced to six years and four months in prison for orchestrating a massive intrusion campaign on Snapchat between 2020 and 2021. The attacker targeted more than 4,500 potential victims, successfully breaching the accounts of around 750 women and stealing intimate images, often to resell them or on commission. This case highlights how social engineering techniques can render even the most common security mechanisms, such as one-time passwords (OTPs), completely ineffective.

Technical Analysis

The attack relied on a chain of psychological phishing (vishing and smishing). The hacker gathered phone numbers or usernames of women active on Snapchat through social media and public channels. Then, using anonymized numbers or messaging apps, he contacted each victim posing as an official Snap Inc. representative. Using emergency pretexts – suspicious logins, security verifications – he convinced them to read out the OTP code that the platform sent to their phone, triggered by the attacker’s login attempt from a new device.

Once he obtained the code, the hacker would complete authentication and take full control of the account. He immediately downloaded all private images (including stories and messages) and activated a new two-factor authentication (2FA) method under his control (e.g., an authenticator app), thereby locking out the legitimate owner.

The attacker did not merely hoard his loot: on Kik Messenger – an encrypted platform – he advertised his “hacking-for-hire” service and traded the stolen material. In addition to images of adults, he stored and distributed child sexual abuse material (CSAM) via Mega accounts, where he amassed more than 1,100 files. In at least one case, he breached the accounts of university students at the request of a former coach, who was later also convicted.

From a technical standpoint, the most insidious element is the manipulation of the human factor. OTP-based 2FA loses all effectiveness if the victim voluntarily hands over the code, and the subsequent activation of a hostile 2FA method makes account recovery very difficult, since the legitimate owner can no longer pass the verification.

Impact

The impact on the victims has been profound: beyond the theft of personal data and the non-consensual dissemination of intimate images, many suffered psychological and reputational harm. Being forcibly locked out of their accounts amplified their sense of helplessness. From a criminal perspective, the case has shone a spotlight on CSAM trafficking, cyberstalking, and sextortion. For Snap Inc., the incident represents reputational damage and a wake-up call to strengthen defenses against targeted phishing and to educate users more effectively.

Mitigation

For users:

  • Never share OTP codes, passwords, or PINs with anyone over the phone or via message, even if the requester claims to be from technical support.
  • Where possible, replace SMS-based 2FA with authenticator apps (TOTP) or hardware keys, which are harder to intercept via social means.
  • Always verify the identity of anyone contacting you by using official channels (verified emails, in-app notifications) and immediately report suspicious attempts.
  • Monitor login and security settings change notifications; if you notice unauthorized changes, contact legitimate support immediately.

For platforms:

  • Enhance anomaly detection engines, such as spotting logins from unusual devices or geographic areas, or the activation of a new 2FA immediately after a login.
  • Send clear push notifications and emails for every critical change (e.g., password change, new 2FA), including a link to undo the operation within a few minutes.
  • Invest in ongoing awareness campaigns that make it unequivocally clear that official personnel will never ask for OTP codes.
  • Expedite the blocking and removal of accounts that impersonate the company.

FAQ

1. How did the hacker obtain OTP codes without physically having the victim's phone?
The attacker used social engineering: he contacted the victim posing as Snapchat and persuaded them to read out the code the app was generating at that moment. Since the victim themselves gave away the code, all cryptographic protections were bypassed.

2. Why didn't two-factor authentication protect the victims?
OTP-based 2FA only works if the code remains secret. Believing they were talking to a security representative, the victim voluntarily shared the code, nullifying the protection factor. Afterwards, the hacker set up his own 2FA, taking exclusive control of the account.

3. What lessons should a platform like Snapchat learn?
It must make the message unequivocal that no staff member will ever ask for an OTP or password. Moreover, it is crucial to implement automated systems that detect suspicious behavior – for example, a new 2FA activation immediately after a login – and provide users with quick recovery tools and dedicated anti-fraud support.

Read next

Sources

This article is an original reworking based on the sources below.

Related topicsSnapchat OTP attackphishingOTP bypasssocial engineeringaccount securityvishing2FA protection
Back to home