Individual Who Compromised Over 1,000 Email Accounts At A New York City University Pleads Guilty
Jonathan Powell, a 30-year-old from Phoenix, Arizona, pled guilty to computer fraud for exploiting a university’s password reset system to compromise over 1,000 email accounts and access linked personal accounts to download sexually explicit content, facing up to five years in prison with sentencing set for December 1, 2017.
Jonathan Powell pled guilty to one count of fraud in connection with computers for hacking into more than 1,000 email accounts at a New York City university between October 2015 and September 2016. He made approximately 18,640 unauthorized attempts to reset passwords via the university’s system, successfully changing 1,378 passwords across 1,035 unique accounts, then used those compromised accounts to reset passwords for linked services like Gmail, iCloud, and Facebook to access private, sexually explicit photos and videos. He faces a maximum sentence of five years in prison, with sentencing scheduled for December 1, 2017; the FBI investigated the case, which was prosecuted by the Southern District of New York’s Complex Frauds and Cybercrime Unit.
Jonathan Powell, a 30-year-old resident of Phoenix, Arizona, pled guilty in Manhattan federal court to one count of fraud in connection with computers for orchestrating a months-long cyberattack on a New York City university’s email system. Between October 2015 and September 2016, he exploited the university’s password reset utility nearly 18,640 times, successfully changing passwords for 1,378 instances across 1,035 unique student and faculty accounts. Using these compromised accounts, Powell initiated password resets for linked personal accounts on platforms such as Apple iCloud, Google Gmail, Facebook, LinkedIn, and Yahoo!, gaining unauthorized access to private content including sexually explicit photographs and videos of college-aged women. Evidence showed he specifically searched for lewd terms within victims’ Gmail accounts to locate illicit material. The FBI’s investigation traced his activity to his Arizona residence and uncovered the full scope of his intrusions, including multiple re-compromises of the same accounts. Powell was arrested on November 2, 2016, and is scheduled to be sentenced on December 1, 2017, facing a statutory maximum of five years in prison. The case was prosecuted by the Southern District of New York’s Complex Frauds and Cybercrime Unit, which emphasized the broader threat such cybercrimes pose to educational institutions.
Extracted insights
- person jonathan powell ×2
- person alison j. nathan
- organization Department of Justice
- agency Federal Bureau of Investigation
- person Joon H. Kim
- organization United States Attorney's Office, Southern District Of New York
- organization University-1
- Jonathan Powell pled guilty to one count of fraud
- Jonathan Powell obtained unauthorized access to more than 1,000 email accounts
- Jonathan Powell downloaded sexually explicit photos and videos
- Jonathan Powell pled guilty before object
- FBI stopped Jonathan Powell
- Jonathan Powell accessed University-1 password reset utility approximately 18,640 times
- Jonathan Powell attempted approximately 18,600 password changes
Press Release Individual Who Compromised Over 1,000 Email Accounts At A New York City University Pleads Guilty Wednesday, August 9, 2017 Share FacebookLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. XLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. LinkedInLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. Email For Immediate Release U.S. Attorney's Office, Southern District of New York Joon H. Kim, the Acting United States Attorney for the Southern District of New York, announced that JONATHAN POWELL pled guilty today to one count of fraud in connection with his scheme to obtain unauthorized access to more than 1,000 email accounts maintained by a New York City area university in order to download sexually explicit photos and videos. POWELL pled guilty earlier today in Manhattan federal court before United States District Judge Alison J. Nathan. Acting U.S. Attorney Joon H. Kim said: “From a computer in Arizona, Jonathan Powell wreaked havoc on the email servers of a New York area university. To feed his perverse desire for personal photos and videos, Powell hacked into hundreds of student and faculty email accounts by surreptitiously changing their passwords. Cybercrime is a threat to organizations large and small, from big companies to local universities. Luckily, the FBI was able to stop Powell before he victimized others.” According to the allegations in the Information to which POWELL pled guilty, a criminal complaint filed against POWELL, as well as statements made during the plea and other proceedings in the case: From October 2015 up to September 2016, POWELL obtained unauthorized access to email accounts hosted by a U.S.-based university which has its primary campus in New York, New York (“University-1”). POWELL obtained unauthorized access to these accounts by accessing the password reset utility maintained by the email servers at Univeristy-1, which was designed to allow authorized users to reset forgotten passwords to accounts. POWELL utilized the password reset utility to change the email account passwords of students and others affiliated with University-1. Once POWELL gained access to the compromised email accounts (the “Compromised Accounts”), he obtained unauthorized access to other password-protected email, social media, and online accounts to which the Compromised Accounts were registered, including, but not limited to, Apple iCloud, Facebook, Google, LinkedIn, and Yahoo! accounts. Specifically, using the Compromised Accounts, POWELL requested password resets for linked accounts hosted by those websites (the “Linked Accounts”), resulting in password reset emails being sent to the Compromised Accounts, which allowed POWELL to change the passwords for the Linked Accounts. POWELL then logged into the Linked Accounts and searched within the Linked Accounts, gaining access to private and confidential content stored in the Linked Accounts. In one instance, POWELL searched a University-1 student’s linked Gmail account for digital photographs and for various lewd terms. The Government’s investigation ultimately revealed that POWELL accessed the Compromised and Linked Accounts at least in part to download sexually explicit photographs and videos of college-aged women. An analysis of University-1 password reset utility logs and other data revealed that POWELL accessed the University-1 password reset utility approximately 18,640 different times between October 2015 and September 2016. During that timeframe, POWELL attempted approximately 18,600 password changes in connection with approximately 2,054 unique University-1 email accounts, and succeeded in making 1,378 password changes in connection with approximately 1,035 unique University-1 email accounts, in some cases compromising the same email accounts multiple times. * * * POWELL, 30, of Phoenix, Arizona, was arrested on November 2, 2016. POWELL pled guilty today to one count of fraud in connection with computers, which carries a maximum sentence of five years in prison. The maximum potential sentence in this case is prescribed by Congress and is provided here for informational purposes only, as the defendant’s sentence will be determined by the judge. POWELL is scheduled to be sentenced on December 1, 2017, at 12 p.m. Mr. Kim praised the investigative work of the FBI. The case is being prosecuted by the Office’s Complex Frauds and Cybercrime Unit. Assistant United States Attorney Christopher J. DiMase is in charge of the prosecution. Updated August 10, 2017 Topic Cybercrime Component USAO - New York, Southern Press Release Number: 17-248
Press Release Individual Who Compromised Over 1,000 Email Accounts At A New York City University Pleads Guilty Wednesday, August 9, 2017 Share FacebookLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. XLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. LinkedInLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. Email For Immediate Release U.S. Attorney's Office, Southern District of New York Joon H. Kim, the Acting United States Attorney for the Southern District of New York, announced that JONATHAN POWELL pled guilty today to one count of fraud in connection with his scheme to obtain unauthorized access to more than 1,000 email accounts maintained by a New York City area university in order to download sexually explicit photos and videos. POWELL pled guilty earlier today in Manhattan federal court before United States District Judge Alison J. Nathan. Acting U.S. Attorney Joon H. Kim said: “From a computer in Arizona, Jonathan Powell wreaked havoc on the email servers of a New York area university. To feed his perverse desire for personal photos and videos, Powell hacked into hundreds of student and faculty email accounts by surreptitiously changing their passwords. Cybercrime is a threat to organizations large and small, from big companies to local universities. Luckily, the FBI was able to stop Powell before he victimized others.” According to the allegations in the Information to which POWELL pled guilty, a criminal complaint filed against POWELL, as well as statements made during the plea and other proceedings in the case: From October 2015 up to September 2016, POWELL obtained unauthorized access to email accounts hosted by a U.S.-based university which has its primary campus in New York, New York (“University-1”). POWELL obtained unauthorized access to these accounts by accessing the password reset utility maintained by the email servers at Univeristy-1, which was designed to allow authorized users to reset forgotten passwords to accounts. POWELL utilized the password reset utility to change the email account passwords of students and others affiliated with University-1. Once POWELL gained access to the compromised email accounts (the “Compromised Accounts”), he obtained unauthorized access to other password-protected email, social media, and online accounts to which the Compromised Accounts were registered, including, but not limited to, Apple iCloud, Facebook, Google, LinkedIn, and Yahoo! accounts. Specifically, using the Compromised Accounts, POWELL requested password resets for linked accounts hosted by those websites (the “Linked Accounts”), resulting in password reset emails being sent to the Compromised Accounts, which allowed POWELL to change the passwords for the Linked Accounts. POWELL then logged into the Linked Accounts and searched within the Linked Accounts, gaining access to private and confidential content stored in the Linked Accounts. In one instance, POWELL searched a University-1 student’s linked Gmail account for digital photographs and for various lewd terms. The Government’s investigation ultimately revealed that POWELL accessed the Compromised and Linked Accounts at least in part to download sexually explicit photographs and videos of college-aged women. An analysis of University-1 password reset utility logs and other data revealed that POWELL accessed the University-1 password reset utility approximately 18,640 different times between October 2015 and September 2016. During that timeframe, POWELL attempted approximately 18,600 password changes in connection with approximately 2,054 unique University-1 email accounts, and succeeded in making 1,378 password changes in connection with approximately 1,035 unique University-1 email accounts, in some cases compromising the same email accounts multiple times. * * * POWELL, 30, of Phoenix, Arizona, was arrested on November 2, 2016. POWELL pled guilty today to one count of fraud in connection with computers, which carries a maximum sentence of five years in prison. The maximum potential sentence in this case is prescribed by Congress and is provided here for informational purposes only, as the defendant’s sentence will be determined by the judge. POWELL is scheduled to be sentenced on December 1, 2017, at 12 p.m. Mr. Kim praised the investigative work of the FBI. The case is being prosecuted by the Office’s Complex Frauds and Cybercrime Unit. Assistant United States Attorney Christopher J. DiMase is in charge of the prosecution. Updated August 10, 2017 Topic Cybercrime Component USAO - New York, Southern Press Release Number: 17-248