‘Anne Hathaway’ crypto theft gang siphons $245 million, flaunts luxury spending
What Happened — Between October 2023 and May 2025, a Singapore‑based criminal group led by 22‑year‑old Malone Lam (aliases “Anne Hathaway”, “$$$”, “King Greavy”) stole more than $245 million in cryptocurrency from victims across the United States. The operation used social‑engineering tactics such as fake Google support calls, recruited accomplices on gaming platforms, and even employed physical burglary to seize hardware wallets.
Why It Matters for Trust & Control Assurance
- The scheme illustrates how weak identity verification and lack of user awareness enable credential compromise and large‑scale asset loss.
- Continuous control‑assurance programs that enforce strong authentication, monitor anomalous support‑channel activity, and require regular security‑awareness training can detect and deter these tactics.
- Evidence of such controls (e.g., MFA logs, phishing‑simulation results) provides a defensible audit trail for regulators and insurers.
Who Is Affected
- Individual cryptocurrency holders and investors.
- Crypto exchanges, custodial wallets, and fintech platforms that manage digital assets.
Recommended Actions
- Enforce multi‑factor authentication and privileged‑access reviews for all support‑related accounts.
- Deploy a security‑awareness program focused on social‑engineering, including simulated phishing and “tech‑support” call drills.
- Implement continuous monitoring of support‑channel communications and anomalous transaction patterns.
- Document the controls and evidence in a Trust Center to streamline audit readiness.
Source: Bitdefender Blog – Anne Hathaway crypto theft gang
Technical Notes
- Attack vector: Social engineering (fake tech‑support calls), recruitment via online gaming platforms, physical theft of hardware wallets.
- Tactics: Credential compromise, impersonation, money‑laundering through cash‑in‑plush‑toys, lavish spending to attract law‑enforcement attention.
- Impact: Direct theft of cryptocurrency assets; no disclosed data breach of personal information.
Source: same as above