Case file · FAKE SUPPORT 2024

How a fake Google support call stole 4,100 bitcoin from one person

Published 2026-09-29 · 5 min read · Missing control: Call back on a known number

One phone call from someone claiming to be Google support ended with a single person in Washington, D.C. losing more than 4,100 bitcoin, worth over $230 million at the time.[1][2] This case file covers how the fake support call worked, how the thieves' spending helped bring them down, and the one habit that would have stopped it.

What happened

On August 18, 2024, a Washington, D.C. resident who held a large amount of bitcoin got a call from a number that appeared to belong to Google. The caller said the person's account had been compromised. A second caller then posed as support staff for Gemini, a cryptocurrency exchange, continuing the same story.[1][4]

Believing they were getting help, the victim was talked into resetting two-factor protections and sharing their computer screen. What the callers saw on that screen let them take the private keys, the secret codes that control a bitcoin wallet. With those keys they moved more than 4,100 bitcoin to wallets they controlled.[1][3]

Federal prosecutors later said the theft was part of a larger criminal group that ran from October 2023 to May 2025. Its members met through online gaming platforms and were spread across California, Connecticut, New York, Florida and abroad.[2]

How it worked

This was not a technical break-in. It was a performance. Prosecutors described a group with assigned jobs: people who pulled personal details from leaked databases, people who picked targets, callers who played the support agents, launderers who turned crypto into cash, and in some cases burglars who went after hardware wallets in people's homes.[3]

The call itself relied on three tricks. First, a spoofed caller ID, so the number on the screen looked like it came from a real company. Second, urgency: the victim was told their account was already under attack, which pushes people to act before thinking. Third, a request that feels routine to anyone who has ever had tech help, which is to share your screen so the agent can see the problem.[1][4] Once a stranger can see or control your screen, anything displayed there, including passwords and wallet keys, belongs to them too.

Real support teams at large tech companies generally do not call customers out of the blue to report a hacked account. The warning itself was the scam.

How it was caught

The spending was hard to miss. Prosecutors say proceeds went on nightclub evenings costing up to $500,000, luxury watches, designer handbags handed out at parties, rental homes in Los Angeles, the Hamptons and Miami, private jets, a private security team, and a fleet of at least 28 exotic cars worth from $100,000 to $3.8 million each.[2][3] An independent crypto investigator publicly traced the stolen funds and highlighted the group's flashy lifestyle within weeks.[4]

In September 2024, about a month after the theft, the FBI arrested 2 men in Miami and Los Angeles and seized luxury cars in a raid on a Miami property.[4] In May 2025 prosecutors charged 12 more people, and said the stolen coins had been swapped into harder-to-trace currency and moved through mixers and pass-through wallets to hide their origin.[1]

What it cost

On September 8, 2026, Malone Lam, a 22-year-old Singaporean citizen living in Miami, pleaded guilty to a racketeering conspiracy in federal court in Washington, D.C. Prosecutors described him as the leader who coordinated the thefts and picked targets, and put the group's total take at more than $245 million.[2] The charge carries up to 20 years in prison. No sentencing date had been set; a status hearing was scheduled for December 8, 2026.[5]

By then, 11 of 18 defendants charged in the investigation had pleaded guilty, according to press coverage of the plea.[5] Earlier, in December 2025, a 22-year-old California man, Evan Tangeman, pleaded guilty for his role laundering proceeds.[3]

The missing control

The missing control: hang up and call back on a number you already know.

A call-back rule breaks this kind of scam at its first step. If the victim had ended the call and dialed Google or Gemini using a number from the company's own website or account page, the real company would have said there was no problem. Spoofed caller ID only works while the scammer controls the line. A second rule, never share your screen with anyone who contacted you first, would have closed the door even if the call-back was skipped.

What to do in your business

Watch the case
The fake Google support call that cost 4,100 bitcoinDrops 2026-11-09
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More payments and fraud cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. BleepingComputer: US charges 12 more suspects linked to $230 million crypto theft
  2. U.S. Attorney's Office, District of Columbia: Singaporean ringleader of $245 million cryptocurrency racketeering enterprise pleads guilty
  3. U.S. Attorney's Office, District of Columbia: Guilty plea and superseding indictment announced in social engineering scheme that stole $263 million
  4. Bitdefender: Two men arrested one month after $230 million of cryptocurrency stolen from a single victim
  5. NBC 6 Miami: Malone Lam pleads guilty as ringleader of international crypto scheme