Social Engineering: How 10 minute phone calls are causing millions in damages

Social Engineering: How 10 minute phone calls are causing millions in damages

A spoofed number, a confident voice, and ten minutes can move eight figures. The Johnston case shows how the vishing economy works, and Scattered Spider shows what it does to companies.

SOCIAL ENGINEERING / 2026-09-09

In March 2026, a California investor answered two phone calls. The first caller said they were from Google support. The second claimed to be from Trezor, a cryptocurrency security firm. Both told the same story: the accounts were compromised and needed immediate action. By the end of the day, roughly 185 bitcoin, about $13 million, had left the investor's wallets. No malware, no stolen password, no exploited software. Two phone calls, both placed by a 19-year-old in Miami.

That case ended in a June 2026 guilty plea from Trenton Johnston, and it is the purest recent example of vishing: voice phishing built on impersonation. It is the same playbook that cost MGM Resorts an estimated $100 million in September 2023, when a single ten-minute call to the IT help desk started a chain that encrypted more than 100 of the company's servers and shut its systems down for days. The phone has become the most reliable way around the controls built to stop phishing, because none of those controls answer calls.

A 19-year-old called someone on the phone, said he was from Google, and stole $13 MILLION. Police found him in a Rolls-Royce with drugs in a Hermès bag. – Trenton Johnston started the scheme in January 2024. – He and his crew impersonated employees of Google, Trezor and other crypto firms by phone and email, convincing victims their accounts were compromised. – The first victim lost $41,000 in Ether after Johnston convinced them their Google and Coinbase accounts were under attack. – Less than a month later they went bigger. – They posed as Google and Trezor representatives and social-engineered a single California victim into transferring $13 MILLION in Bitcoin from their wallet in one transaction. – No exchange was hacked. No code was exploited. Just a phone call and a convincing voice. – Within two months $1.2 MILLION was already gone. A Lamborghini Aventador SVJ. Two BMWs. A rented mansion in North Miami. A private jet. Plane tickets flown in for two women from New York. – After the transfer Johnston texted his accomplice: "bro we rlly actually did some crazy a-- s---." – The ruse ended at a traffic stop. Police found him in the back seat of a Rolls-Royce Cullinan with suspected amphetamine tablets sitting inside a Hermès bag. – He was 19 years old. – He pleaded guilty yesterday in Miami federal court. – Prosecutors are recommending 51 to 63 months in prison. He has agreed to be deported back to Canada. – The victim has not recovered a single dollar. – No code, no exploit, no technical skill. – Just a teenager with a phone pretending to be Google. That was enough to take $13 MILLION from someone who had it. The most expensive hack in crypto is still the one that targets the human, not the wallet. @aisarcore

The anatomy of the call

Vishing works because caller ID is not identity. The number on the screen can be spoofed. The STIR/SHAKEN framework carriers are adopting makes spoofing harder, but it has not ended it, and it does nothing about the stronger trick: when the story is good enough, the caller does not need a real number at all.

The callers arrive prepared. In the Johnston case, the scripts named real companies and real security procedures, and the actors escalated from a $41,000 Ether theft in February 2026 to the $13 million Bitcoin heist a few weeks later, refining the script between attempts. The Scattered Spider group researches employees on LinkedIn before calling, and analysis of its call recordings shows it already holding personal details such as dates of birth and manager names when it reaches a help desk, so standard verification questions fail clean.

Then comes the ask, and the ask is always the same shape: a fraud alert, a compromise, a reset. Move funds to a safe account. Read back this code. Confirm these numbers. The request is urgent, it sounds reversible, and it is always something a real institution would never request over an unsolicited call.

Who runs these calls

  • Scattered Spider, also tracked as Octo Tempest and UNC3944, is a native English-speaking group that impersonates employees to help desks, resets MFA tokens, and SIM-swaps victims. Its MGM intrusion ran on a single ten-minute pretext call, and Microsoft incident responders document it masquerading as CISOs and incident response firms mid-attack
  • Support impersonators like the Johnston ring pose as Google, Trezor, Coinbase, and similar brands. The March 13, 2026 take of 185 bitcoin from one victim was coordinated over two calls, and prosecutors say none of the funds had been recovered as of the criminal complaint
  • A laundering layer sits under both: in a separate Western District of Washington indictment, five defendants are accused of moving more than $7.4 million in proceeds from impersonation scams through 21 shell companies and roughly 44 bank accounts before wiring funds abroad

Why the totals keep climbing

The scale is now visible in government data. The FBI's 2025 Internet Crime Report logged 1,008,597 complaints with reported losses above $20 billion, including more than 181,000 cryptocurrency complaints totaling over $11 billion. Call-center fraud alone, the tech-support and government-impersonation categories that run on these calls, drew more than 80,000 complaints with losses exceeding $2.9 billion in 2025.

Bank impersonation is the highest-loss impersonation category on record with the FTC, and the FCC moved in April 2026 to fine a phone provider $4.5 million for carrying tens of thousands of fake bank calls. The enforcement is real and the economics still favor the caller: a stolen wallet moves in minutes, a plea deal takes years, and the money is usually gone before either arrives.

The rules that end the call

  • Never authenticate into an inbound call. Hang up and call the number on your card, in your app, or on the institution's verified site. A real fraud team will wait on hold like everyone else
  • No legitimate bank or exchange will ask you to move funds to a safe account, read back a code, or confirm a password over the phone. The request is the attack
  • Treat urgency as the tell. Real security incidents are handled with process, not panic, and never with secrecy
  • Keep recovery material out of reach of a phone call: hardware keys, recovery seeds, and backup codes stored offline
  • Shrink the ammunition. Vishing pretexts are assembled from breach data and public records. Broker removal, account retirement, and monitored exposure are raw material denial, and they make the next call fail before it starts
  • If your household or your office moves money, agree on a codeword or callback rule now. The ten-minute call cannot survive a sixty-second callback to a known number
FIELD NOTE No bank, exchange, or platform will ever call you and ask you to move money to a safe account or read a code back. When the call demands urgency and secrecy, the call is the attack.